Report #11153 check_circle

  • Creation Date: Sept. 8, 2020, 3:29 p.m.
  • Last Update: Sept. 8, 2020, 3:43 p.m.
  • File: 003_adv
  • Results:
Binary
DLL
False cancel
Size
129.00KB
trid
61.7% Win64 Executable
14.7% Win32 Dynamic Link Library
10.0% Win32 Executable
4.5% OS/2 Executable
4.4% Generic Win/DOS Executable
type
PE
wordsize
64
Subsystem
Windows CLI
Hashes
md5
5775a592ed670a6693c66c3aa2d83282
sha1
6025477114a546e4f946c7d506c53e9211beb1eb
crc32
0xc9e16f53
sha224
a78881fadc91064d880fdbf77d6a309b3e95e548b790bff8c8831706
sha256
2d6d522c78364dc29ab849fe45e77b703c574566ddc475c2f9df9b6ccfa6fed7
sha384
cee8d8f167175c0c2e7c1af3e52d321e1a5908923cf628e075b842f7d8217f2cba3d8ddf9036c6ea20f63c258feec6a7
sha512
0e3424cee19b18e95db590b886d25612f9c9062a24df405c868704287d119f8f2d1d4743ac516abd3667dd0216f2382354058db7ea8dc4b2ede49e98d01f7300
ssdeep
3072:2n/P7VvpXmjmYdJ4Z1RjnRdRkVGH7l87L:c/P7D2jJD4DRBuG
Community
Google
False cancel
HashLib
False cancel
YARA
Matches
win_registry, domain, anti_dbg, IsPE64, contentis_base64, HasDebugData, RijnDael_AES, IsConsole, maldoc_find_kernel32_base_method_1, CRC32_poly_Constant, Microsoft_Visual_Cpp_80_DLL, HasRichSignature

Suspicious
True check_circle

Strings
List
C:\Users\Win\Documents\Visual Studio 2012\Projects\Dropper\x64\Release\Dropper.pdb
COMCTL32.dll
MSVCR110.dll
WINMM.dll
UxTheme.dll
proc.exe
proc.exe
o%A0}
<requestedPrivileges>
__crt_debugger_hook
IsProcessorFeaturePresent
t1SSSh
CreateEventW
PSSh
IsDebuggerPresent
CreateProcessW
CoCreateInstance
RegOpenKeyExW
RegCreateKeyW
LoadResource
RegQueryValueExW
RegDeleteKeyW
RegGetValueW
QueryPerformanceCounter
RegSetValueExW
GetModuleHandleW
RegEnumKeyExW
fprintf
fopen
__crtCapturePreviousContext
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
BBBBhhhhAAAA
AAAAOOOOgggg
8-878A8K8[8e8o8
s@,E
__crtTerminateProcess
@X\uft3e
_commode
_initterm
__setusermatherr
__C_specific_handler
_initterm_e
Ti-b[Xv+S
_calloc_crt
__set_app_type
__dllonexit
_amsg_exit
__getmainargs
_XcptFilter
__initenv
?terminate@@YAXXZ
;22dV::tN
&&&&6666????
D$(9D$$s.HcD$$H
</assembly>
_unlock
}e#GEWF
It8]B4
MeOgU~M
O44h\
dV22tN::
2dV2:tN:
V22dN::t
Df""T~**;
`.rdata
`.rdata
_onexit
2Ht\l
f""D~**T
""Df**T~
;V#npGR2
LcA<E3
5,ANf
`3SbE
Gan;6
H3E H3E
ServicesActive
pCe-Rn)
N.}U(' PMs
p\lHtW
@.data
@.data
a44Do
R##Fe
WideCharToMultiByte
M H1E
QPeA~S
JNeME~
kIV,ge
P[bfie
_fmode
_cexit
Ur&ge
cl{au
_exit
?wreD
Rich?
R`ALy
-1HA
11#?*0

Foremost
Matches
24.exe, 115 KB
Suspicious
True check_circle
Heuristics
IPs
hasIPs: False cancel
Allowed
Suspicious
hasAllowed: False cancel
hasSuspicious: False cancel

URLs
Allowed
hasURLs: False cancel
Suspicious
hasAllowed: False cancel
hasSuspicious: False cancel

Files
Allowed: ADVAPI32.dll, MSVCR110.dll, ole32.dll, SHLWAPI.dll, USER32.dll, SHELL32.dll, COMCTL32.dll, RPCRT4.dll, UxTheme.dll, WINMM.dll, GDI32.dll, OLEAUT32.dll, KERNEL32.dll
hasFiles: True check_circle
Suspicious
hasAllowed: True check_circle
hasSuspicious: False cancel

Binary
Sizes
RVA
RVA: 16
Suspicious: False cancel
Code
Size: 127488
Suspicious: False cancel
Image
Address: 5368709120
Suspicious: False cancel
Stack
Stack: 4096
Suspicious: False cancel
Headers
Headers: 1024
Suspicious: False cancel
Suspicious: False cancel

Symbols
Number
Number: 0
Suspicious: True check_circle
Pointer
Pointer: 0
Suspicious: True check_circle
Directories
Number: 16
Suspicious: False cancel

Checksum
Value: 0
Suspicous: True check_circle

Sections
Allowed: .text, .rdata, .data, .pdata, .rsrc, .reloc
Suspicious
hasAllowed: True check_circle
hasSections: True check_circle
hasSuspicious: False cancel

Versions
OS
Version: 6
Suspicious: False cancel
Image
Version: True check_circle
Suspicious: 6
Linker
Version: 11.0
Suspicious: False cancel
Subsystem
Version: 6.0
Suspicious: False cancel
Suspicious: False cancel

EntryPoint
Address: 6772
Suspicious: False cancel

Anomalies
Anomalies: The header checksum and the calculated checksum do not match.
hasAnomalies: True check_circle

Libraries
Allowed: advapi32.dll, ole32.dll, shlwapi.dll, user32.dll, shell32.dll, comctl32.dll, rpcrt4.dll, uxtheme.dll, winmm.dll, gdi32.dll, oleaut32.dll, kernel32.dll
hasLibs: True check_circle
Suspicious: msvcr110.dll
hasAllowed: True check_circle
hasSuspicious: True check_circle

Timestamp
Past: False cancel
Valid: True check_circle
Value: 2020-09-03 16:23:37
Future: False cancel

Compilation
Packed: False cancel
Missing: False cancel
Packers
Compiled: True check_circle
Compilers: Microsoft Visual C++ 8.0 (DLL)

Obfuscation
XOR: True check_circle
Fuzzing: False cancel

PEDetector
Matches
12448
Suspicious
True check_circle
Disassembly
hasTricks
False cancel
Tricks
AVclass
sodinokibi
1
VirusTotal
md5
5775a592ed670a6693c66c3aa2d83282
sha1
6025477114a546e4f946c7d506c53e9211beb1eb
SCANS
AVG
result: Win32:Malware-gen
update: 20200908
version: 18.4.3895.0
detected: True check_circle

CMC
update: 20200908
version: 2.7.2019.1
detected: False cancel

MAX
result: malware (ai score=83)
update: 20200908
version: 2019.9.16.1
detected: True check_circle

APEX
update: 20200907
version: 6.68
detected: False cancel

Bkav
update: 20200908
version: 1.3.0.9899
detected: False cancel

K7GW
result: Trojan ( 0054d99c1 )
update: 20200908
version: 11.135.35196
detected: True check_circle

ALYac
result: Trojan.Ransom.Sodinokibi
update: 20200908
version: 1.1.1.5
detected: True check_circle

Avast
result: Win32:Malware-gen
update: 20200908
version: 18.4.3895.0
detected: True check_circle

Avira
result: TR/Crypt.XPACK.Gen
update: 20200908
version: 8.3.3.8
detected: True check_circle

Baidu
update: 20190318
version: 1.0.0.2
detected: False cancel

Cynet
update: 20200905
version: 4.0.0.24
detected: False cancel

Cyren
update: 20200908
version: 6.3.0.2
detected: False cancel

DrWeb
result: Trojan.Encoder.28004
update: 20200908
version: 7.0.48.8080
detected: True check_circle

GData
result: Win32.Trojan-Ransom.Sokinokibi.ECPW8C
update: 20200908
version: A:25.26931B:27.20096
detected: True check_circle

Panda
result: Trj/CI.A
update: 20200908
version: 4.6.4.2
detected: True check_circle

VBA32
update: 20200908
version: 4.4.1
detected: False cancel

VIPRE
result: Trojan.Win32.Generic!BT
update: 20200908
version: 86532
detected: True check_circle

Zoner
update: 20200908
version: 0.0.0.0
detected: False cancel

ClamAV
result: Win.Ransomware.Sodinokibi-7013612-0
update: 20200907
version: 0.102.4.0
detected: True check_circle

Comodo
result: .UnclassifiedMalware@0
update: 20200728
version: 32668
detected: True check_circle

Ikarus
result: Trojan-Ransom.Sodinokibi
update: 20200908
version: 0.1.5.2
detected: True check_circle

McAfee
result: Artemis!5775A592ED67
update: 20200908
version: 6.0.6.653
detected: True check_circle

Rising
result: Backdoor.Remcos!8.B89E (TFE:5:IBRWLZzTx1N)
update: 20200908
version: 25.0.0.26
detected: True check_circle

Sophos
result: Mal/Generic-S
update: 20200908
version: 4.98.0
detected: True check_circle

Yandex
update: 20200907
version: 5.5.2.24
detected: False cancel

Zillya
update: 20200908
version: 2.0.0.4171
detected: False cancel

Acronis
update: 20200806
version: 1.1.1.77
detected: False cancel

Alibaba
result: Trojan:Win32/GenKryptik.ebfbbef2
update: 20190527
version: 0.3.0.5
detected: True check_circle

Arcabit
update: 20200908
version: 1.0.0.881
detected: False cancel

Cylance
result: Unsafe
update: 20200908
version: 2.3.1.101
detected: True check_circle

Elastic
update: 20200831
version: 4.0.8
detected: False cancel

FireEye
result: DeepScan:Generic.Ransom.Sodinokibi.FE9FF902
update: 20200908
version: 32.36.1.0
detected: True check_circle

Sangfor
update: 20200814
version: 1.0
detected: False cancel

TACHYON
update: 20200908
version: 2020-09-08.02
detected: False cancel

Tencent
result: Malware.Win32.Gencirc.10cdd51f
update: 20200908
version: 1.0.0.1
detected: True check_circle

ViRobot
update: 20200908
version: 2014.3.20.0
detected: False cancel

Webroot
update: 20200908
version: 1.0.0.403
detected: False cancel

eGambit
update: 20200908
detected: False cancel

Ad-Aware
result: DeepScan:Generic.Ransom.Sodinokibi.FE9FF902
update: 20200908
version: 3.0.16.117
detected: True check_circle

AegisLab
result: Trojan.Win32.Gen.j!c
update: 20200908
version: 4.2
detected: True check_circle

F-Secure
result: Trojan.TR/Crypt.XPACK.Gen
update: 20200908
version: 12.0.86.52
detected: True check_circle

Fortinet
result: W32/Gen.B!tr
update: 20200908
version: 6.2.142.0
detected: True check_circle

Invincea
result: Mal/Generic-S
update: 20200908
version: 1.0.1.0
detected: True check_circle

Jiangmin
result: Trojan.MSIL.qkml
update: 20200908
version: 16.0.100
detected: True check_circle

Kingsoft
update: 20200908
version: 2013.8.14.323
detected: False cancel

Paloalto
update: 20200908
version: 1.0
detected: False cancel

Symantec
result: Downloader
update: 20200907
version: 1.12.0.0
detected: True check_circle

AhnLab-V3
update: 20200908
version: 3.18.1.10026
detected: False cancel

Antiy-AVL
result: Trojan[Ransom]/Win32.Gen
update: 20200908
version: 3.0.0.1
detected: True check_circle

Kaspersky
result: HEUR:Trojan-Ransom.Win32.Gen.gen
update: 20200908
version: 15.0.1.13
detected: True check_circle

MaxSecure
update: 20200908
version: 1.0.0.1
detected: False cancel

Microsoft
result: Trojan:Win32/Ymacco.AA2D
update: 20200908
version: 1.1.17400.5
detected: True check_circle

Qihoo-360
result: Win32/Trojan.Ransom.fb6
update: 20200908
version: 1.0.0.1120
detected: True check_circle

ZoneAlarm
result: HEUR:Trojan-Ransom.Win32.Gen.gen
update: 20200908
version: 1.0
detected: True check_circle

Cybereason
result: malicious.2ed670
update: 20190616
version: 1.2.449
detected: True check_circle

ESET-NOD32
result: a variant of Win64/GenKryptik.ERUI
update: 20200908
version: 21955
detected: True check_circle

TrendMicro
update: 20200908
version: 11.0.0.1006
detected: False cancel

BitDefender
result: DeepScan:Generic.Ransom.Sodinokibi.FE9FF902
update: 20200908
version: 7.2
detected: True check_circle

CrowdStrike
result: win/malicious_confidence_60% (W)
update: 20190702
version: 1.0
detected: True check_circle

K7AntiVirus
result: Trojan ( 0054d99c1 )
update: 20200908
version: 11.135.35194
detected: True check_circle

SentinelOne
update: 20200724
version: 4.4.0.0
detected: False cancel

Malwarebytes
update: 20200908
version: 3.6.4.335
detected: False cancel

TotalDefense
update: 20200908
version: 37.1.62.1
detected: False cancel

CAT-QuickHeal
result: Trojanransom.Gen
update: 20200908
version: 14.00
detected: True check_circle

NANO-Antivirus
result: Virus.Win32.Gen.ccmw
update: 20200908
version: 1.0.134.25140
detected: True check_circle

BitDefenderTheta
result: AI:Packer.59A870CF1E
update: 20200902
version: 7.2.37796.0
detected: True check_circle

MicroWorld-eScan
result: DeepScan:Generic.Ransom.Sodinokibi.FE9FF902
update: 20200908
version: 14.0.409.0
detected: True check_circle

SUPERAntiSpyware
update: 20200904
version: 5.6.0.1032
detected: False cancel

TrendMicro-HouseCall
update: 20200908
version: 10.0.0.1040
detected: False cancel

total
69
sha256
2d6d522c78364dc29ab849fe45e77b703c574566ddc475c2f9df9b6ccfa6fed7
scan_id
2d6d522c78364dc29ab849fe45e77b703c574566ddc475c2f9df9b6ccfa6fed7-1599568023
resource
5775a592ed670a6693c66c3aa2d83282
positives
41
scan_date
2020-09-08 12:27:03
verbose_msg
Scan finished, information embedded
response_code
1
File
Trace
8/9/2020 - 14:45:42.512Unknown1480C:\malware.exeC:\Monitor\proc.exe
8/9/2020 - 14:45:42.512Open1480C:\malware.exeC:\Windows\System32\apphelp.dll
8/9/2020 - 14:45:42.512Open1480C:\malware.exeC:\Windows\System32\apphelp.dll
8/9/2020 - 14:45:42.512Open1480C:\malware.exeC:\Windows\AppPatch\sysmain.sdb
8/9/2020 - 14:45:42.512Open1480C:\malware.exeC:\Monitor
8/9/2020 - 14:45:42.512Unknown1480C:\malware.exeC:\Monitor
8/9/2020 - 14:45:42.512Open1480C:\malware.exeC:\Monitor\proc.exe
8/9/2020 - 14:45:42.512Unknown1480C:\malware.exeC:\Monitor\proc.exe
8/9/2020 - 14:45:42.512Open1480C:\malware.exeC:\
8/9/2020 - 14:45:42.512Unknown1480C:\malware.exeC:\
8/9/2020 - 14:45:42.512Open1480C:\malware.exeC:\Monitor
8/9/2020 - 14:45:42.512Unknown1480C:\malware.exeC:\Monitor
8/9/2020 - 14:45:42.512Open1480C:\malware.exeC:\Monitor
8/9/2020 - 14:45:42.512Unknown1480C:\malware.exeC:\Monitor
8/9/2020 - 14:45:42.512Open1480C:\malware.exeC:\Monitor\proc.exe
8/9/2020 - 14:45:42.512Read1480C:\malware.exeC:\Monitor\proc.exe
8/9/2020 - 14:45:42.512Open1480C:\malware.exeC:\Monitor\ui\SwDRM.dll
8/9/2020 - 14:45:42.528Open1480C:\malware.exeC:\Monitor\proc.exe
8/9/2020 - 14:45:42.528Open1480C:\malware.exeC:\Monitor\proc.exe
8/9/2020 - 14:45:42.528Unknown1480C:\malware.exeC:\Monitor\proc.exe
8/9/2020 - 14:45:42.528Open1480C:\malware.exeC:\Monitor\proc.exe
8/9/2020 - 14:45:42.528Unknown1480C:\malware.exeC:\Monitor\proc.exe
8/9/2020 - 14:45:42.528Unknown1480C:\malware.exeC:\Monitor\proc.exe
8/9/2020 - 14:45:42.528Unknown1480C:\malware.exeC:\Monitor\proc.exe
8/9/2020 - 14:45:42.528Unknown1480C:\malware.exeC:\Monitor
8/9/2020 - 14:45:42.528Unknown1480C:\malware.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_a4d981ff711297b6
8/9/2020 - 14:45:42.543Open1488C:\Monitor\proc.exeC:\Windows\Prefetch\PROC.EXE-5509F567.pf
8/9/2020 - 14:45:42.543Open1488C:\Monitor\proc.exeC:\Windows
8/9/2020 - 14:45:42.543Open1488C:\Monitor\proc.exeC:\Windows\System32\wow64.dll
8/9/2020 - 14:45:42.543Open1488C:\Monitor\proc.exeC:\Windows\System32\wow64.dll
8/9/2020 - 14:45:42.543Open1488C:\Monitor\proc.exeC:\Windows\System32\wow64win.dll
8/9/2020 - 14:45:42.543Open1488C:\Monitor\proc.exeC:\Windows\System32\wow64win.dll
8/9/2020 - 14:45:42.543Open1488C:\Monitor\proc.exeC:\Windows\System32\wow64cpu.dll
8/9/2020 - 14:45:42.543Open1488C:\Monitor\proc.exeC:\Windows\System32\wow64cpu.dll
8/9/2020 - 14:45:42.543Open1488C:\Monitor\proc.exeC:\Windows\System32\wow64log.dll
8/9/2020 - 14:45:42.543Open1488C:\Monitor\proc.exeC:\Windows
8/9/2020 - 14:45:42.543Unknown1488C:\Monitor\proc.exeC:\Windows
8/9/2020 - 14:45:42.543Open1488C:\Monitor\proc.exeC:\Monitor
8/9/2020 - 14:45:42.543Open1488C:\Monitor\proc.exeC:\Monitor\rstrtmgr.dll
8/9/2020 - 14:45:42.543Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\RstrtMgr.dll
8/9/2020 - 14:45:42.543Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\RstrtMgr.dll
8/9/2020 - 14:45:42.575Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\sechost.dll
8/9/2020 - 14:45:42.575Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\sechost.dll
8/9/2020 - 14:45:42.590Open1488C:\Monitor\proc.exeC:\Monitor\ncrypt.dll
8/9/2020 - 14:45:42.590Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\ncrypt.dll
8/9/2020 - 14:45:42.590Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\ncrypt.dll
8/9/2020 - 14:45:42.590Open1488C:\Monitor\proc.exeC:\Monitor\bcrypt.dll
8/9/2020 - 14:45:42.590Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\bcrypt.dll
8/9/2020 - 14:45:42.590Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\bcrypt.dll
8/9/2020 - 14:45:42.590Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 14:45:42.590Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 14:45:42.590Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 14:45:42.590Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 14:45:42.590Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 14:45:42.590Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 14:45:42.590Open1488C:\Monitor\proc.exeC:\Monitor\winhttp.dll
8/9/2020 - 14:45:42.590Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\winhttp.dll
8/9/2020 - 14:45:42.590Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\winhttp.dll
8/9/2020 - 14:45:42.590Open1488C:\Monitor\proc.exeC:\Monitor\webio.dll
8/9/2020 - 14:45:42.590Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\webio.dll
8/9/2020 - 14:45:42.590Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\webio.dll
8/9/2020 - 14:45:42.606Open1488C:\Monitor\proc.exeC:\Monitor\winmm.dll
8/9/2020 - 14:45:42.606Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\winmm.dll
8/9/2020 - 14:45:42.606Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\winmm.dll
8/9/2020 - 14:45:42.606Open1488C:\Monitor\proc.exeC:\Monitor\mpr.dll
8/9/2020 - 14:45:42.606Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\mpr.dll
8/9/2020 - 14:45:42.606Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\mpr.dll
8/9/2020 - 14:45:45.685Open1488C:\Monitor\proc.exeC:\
8/9/2020 - 14:45:45.686Unknown1488C:\Monitor\proc.exeC:\
8/9/2020 - 14:45:45.692Open1488C:\Monitor\proc.exeC:\
8/9/2020 - 14:45:45.692Unknown1488C:\Monitor\proc.exeC:\
8/9/2020 - 14:45:45.735Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\rpcss.dll
8/9/2020 - 14:45:45.736Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\rpcss.dll
8/9/2020 - 14:45:45.858Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\wbem\wbemprox.dll
8/9/2020 - 14:45:45.861Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\wbem\wbemprox.dll
8/9/2020 - 14:45:45.868Open1488C:\Monitor\proc.exeC:\Monitor\powershell.exe
8/9/2020 - 14:45:45.869Open1488C:\Monitor\proc.exeC:\Monitor\powershell.exe
8/9/2020 - 14:45:45.869Open1488C:\Monitor\proc.exeC:\Windows\System32\powershell.exe
8/9/2020 - 14:45:45.870Open1488C:\Monitor\proc.exeC:\Windows\system\powershell.exe
8/9/2020 - 14:45:45.870Open1488C:\Monitor\proc.exeC:\Windows\powershell.exe
8/9/2020 - 14:45:45.870Open1488C:\Monitor\proc.exeC:\Windows\System32\powershell.exe
8/9/2020 - 14:45:45.870Open1488C:\Monitor\proc.exeC:\Windows\powershell.exe
8/9/2020 - 14:45:45.870Open1488C:\Monitor\proc.exeC:\Windows\System32\wbem\powershell.exe
8/9/2020 - 14:45:45.871Open1488C:\Monitor\proc.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
8/9/2020 - 14:45:45.871Unknown1488C:\Monitor\proc.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exepowershell.exe
8/9/2020 - 14:45:45.871Open1488C:\Monitor\proc.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
8/9/2020 - 14:45:45.871Unknown1488C:\Monitor\proc.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exepowershell.exe
8/9/2020 - 14:45:45.872Open1488C:\Monitor\proc.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
8/9/2020 - 14:45:45.875Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\wbem\wbemcomn.dll
8/9/2020 - 14:45:45.875Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\wbemcomn.dll
8/9/2020 - 14:45:45.876Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\wbemcomn.dll
8/9/2020 - 14:45:46.24Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\wbem\Logs
8/9/2020 - 14:45:46.59Unknown1488C:\Monitor\proc.exeC:\Windows\SysWOW64\wbem\Logs
8/9/2020 - 14:45:46.61Open1488C:\Monitor\proc.exeC:\Monitor\CRYPTSP.dll
8/9/2020 - 14:45:46.61Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\cryptsp.dll
8/9/2020 - 14:45:46.62Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\cryptsp.dll
8/9/2020 - 14:45:46.63Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 14:45:46.63Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 14:45:46.64Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 14:45:46.64Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 14:45:46.64Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 14:45:46.65Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 14:45:46.65Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 14:45:46.65Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 14:45:46.66Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 14:45:46.66Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 14:45:46.72Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 14:45:46.72Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 14:45:46.74Open1488C:\Monitor\proc.exeC:\Windows\Globalization\Sorting\SortDefault.nls
8/9/2020 - 14:45:46.74Unknown1488C:\Monitor\proc.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
8/9/2020 - 14:45:46.75Open1488C:\Monitor\proc.exeC:\Monitor\RpcRtRemote.dll
8/9/2020 - 14:45:46.75Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\RpcRtRemote.dll
8/9/2020 - 14:45:46.76Unknown1488C:\Monitor\proc.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
8/9/2020 - 14:45:46.76Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\RpcRtRemote.dll
8/9/2020 - 14:45:46.76Unknown1488C:\Monitor\proc.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
8/9/2020 - 14:45:46.77Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\apphelp.dll
8/9/2020 - 14:45:46.77Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\apphelp.dll
8/9/2020 - 14:45:46.78Open1488C:\Monitor\proc.exeC:\Windows\AppPatch\AppPatch64\sysmain.sdb
8/9/2020 - 14:45:46.79Open1488C:\Monitor\proc.exeC:\Windows\System32\WindowsPowerShell\v1.0
8/9/2020 - 14:45:46.79Unknown1488C:\Monitor\proc.exeC:\Windows\System32\WindowsPowerShell\v1.0
8/9/2020 - 14:45:46.79Open1488C:\Monitor\proc.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
8/9/2020 - 14:45:46.79Unknown1488C:\Monitor\proc.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exepowershell.exe
8/9/2020 - 14:45:46.80Open1488C:\Monitor\proc.exeC:\
8/9/2020 - 14:45:46.80Unknown1488C:\Monitor\proc.exeC:\
8/9/2020 - 14:45:46.80Open1488C:\Monitor\proc.exeC:\Windows
8/9/2020 - 14:45:46.80Unknown1488C:\Monitor\proc.exeC:\Windows
8/9/2020 - 14:45:46.80Open1488C:\Monitor\proc.exeC:\Windows\System32\WindowsPowerShell
8/9/2020 - 14:45:46.80Unknown1488C:\Monitor\proc.exeC:\Windows\System32\WindowsPowerShell
8/9/2020 - 14:45:46.83Unknown1488C:\Monitor\proc.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exepowershell.exe
8/9/2020 - 14:45:46.128Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Prefetch\POWERSHELL.EXE-920BBA2A.pf
8/9/2020 - 14:45:46.129Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
8/9/2020 - 14:45:46.351Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\wbem\wbemsvc.dll
8/9/2020 - 14:45:46.354Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\wbem\wbemsvc.dll
8/9/2020 - 14:45:46.402Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\sechost.dll
8/9/2020 - 14:45:46.402Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\sechost.dll
8/9/2020 - 14:45:46.411Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\ATL.DLL
8/9/2020 - 14:45:46.411Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\atl.dll
8/9/2020 - 14:45:46.411Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\atl.dll
8/9/2020 - 14:45:46.413Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\mscoree.dll
8/9/2020 - 14:45:46.413Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\mscoree.dll
8/9/2020 - 14:45:46.414Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\mscoree.dll
8/9/2020 - 14:45:46.418Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\imm32.dll
8/9/2020 - 14:45:46.419Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\imm32.dll
8/9/2020 - 14:45:46.420Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\imm32.dll
8/9/2020 - 14:45:46.420Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\imm32.dll
8/9/2020 - 14:45:46.421Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\imm32.dll
8/9/2020 - 14:45:46.421Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\imm32.dll
8/9/2020 - 14:45:46.423Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\pt-BR\powershell.exe.mui
8/9/2020 - 14:45:46.443Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rpcss.dll
8/9/2020 - 14:45:46.443Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rpcss.dll
8/9/2020 - 14:45:46.444Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rpcss.dll
8/9/2020 - 14:45:46.445Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rpcss.dll
8/9/2020 - 14:45:46.447Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\CRYPTBASE.dll
8/9/2020 - 14:45:46.448Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\cryptbase.dll
8/9/2020 - 14:45:46.448Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\cryptbase.dllcryptbase.dll
8/9/2020 - 14:45:46.448Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\cryptbase.dll
8/9/2020 - 14:45:46.448Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\cryptbase.dllcryptbase.dll
8/9/2020 - 14:45:46.449Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\uxtheme.dll
8/9/2020 - 14:45:46.449Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\uxtheme.dll
8/9/2020 - 14:45:46.506Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\shell32.dll
8/9/2020 - 14:45:46.506Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\shell32.dll
8/9/2020 - 14:45:46.510Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\shell32.dll
8/9/2020 - 14:45:46.511Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe.Local
8/9/2020 - 14:45:46.511Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
8/9/2020 - 14:45:46.511Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
8/9/2020 - 14:45:46.514Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
8/9/2020 - 14:45:46.515Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll
8/9/2020 - 14:45:46.515Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll
8/9/2020 - 14:45:46.515Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll
8/9/2020 - 14:45:46.515Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll
8/9/2020 - 14:45:46.516Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\WindowsShell.Manifest
8/9/2020 - 14:45:46.516Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\WindowsShell.ManifestWindowsShell.Manifest
8/9/2020 - 14:45:46.517Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Globalization\Sorting\SortDefault.nls
8/9/2020 - 14:45:46.518Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
8/9/2020 - 14:45:46.518Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
8/9/2020 - 14:45:46.518Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
8/9/2020 - 14:45:46.519Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
8/9/2020 - 14:45:46.519Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
8/9/2020 - 14:45:46.520Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
8/9/2020 - 14:45:46.520Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exepowershell.exe
8/9/2020 - 14:45:46.520Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.520Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.520Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
8/9/2020 - 14:45:46.520Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
8/9/2020 - 14:45:46.520Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell
8/9/2020 - 14:45:46.521Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell
8/9/2020 - 14:45:46.522Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
8/9/2020 - 14:45:46.522Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
8/9/2020 - 14:45:46.523Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.523Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.524Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\propsys.dll
8/9/2020 - 14:45:46.524Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\propsys.dll
8/9/2020 - 14:45:46.525Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches
8/9/2020 - 14:45:46.525Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
8/9/2020 - 14:45:46.525Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches
8/9/2020 - 14:45:46.526Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
8/9/2020 - 14:45:46.526Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000000.db
8/9/2020 - 14:45:46.526Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\desktop.ini
8/9/2020 - 14:45:46.526Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\desktop.ini
8/9/2020 - 14:45:46.528Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
8/9/2020 - 14:45:46.528Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
8/9/2020 - 14:45:46.528Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
8/9/2020 - 14:45:46.528Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
8/9/2020 - 14:45:46.528Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData
8/9/2020 - 14:45:46.528Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData
8/9/2020 - 14:45:46.529Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming
8/9/2020 - 14:45:46.529Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming
8/9/2020 - 14:45:46.529Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\desktop.ini
8/9/2020 - 14:45:46.529Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft
8/9/2020 - 14:45:46.529Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft
8/9/2020 - 14:45:46.529Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
8/9/2020 - 14:45:46.530Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
8/9/2020 - 14:45:46.530Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
8/9/2020 - 14:45:46.530Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
8/9/2020 - 14:45:46.530Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\Desktop\desktop.ini
8/9/2020 - 14:45:46.531Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\Desktop\desktop.ini
8/9/2020 - 14:45:46.534Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
8/9/2020 - 14:45:46.535Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
8/9/2020 - 14:45:46.535Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.535Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.535Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
8/9/2020 - 14:45:46.535Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
8/9/2020 - 14:45:46.535Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
8/9/2020 - 14:45:46.536Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
8/9/2020 - 14:45:46.536Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData
8/9/2020 - 14:45:46.536Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData
8/9/2020 - 14:45:46.536Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming
8/9/2020 - 14:45:46.536Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming
8/9/2020 - 14:45:46.536Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft
8/9/2020 - 14:45:46.536Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft
8/9/2020 - 14:45:46.537Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
8/9/2020 - 14:45:46.537Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
8/9/2020 - 14:45:46.537Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
8/9/2020 - 14:45:46.537Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
8/9/2020 - 14:45:46.537Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
8/9/2020 - 14:45:46.537Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
8/9/2020 - 14:45:46.538Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu
8/9/2020 - 14:45:46.538Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu
8/9/2020 - 14:45:46.538Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.538Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.539Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData
8/9/2020 - 14:45:46.539Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData
8/9/2020 - 14:45:46.539Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\desktop.ini
8/9/2020 - 14:45:46.539Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft
8/9/2020 - 14:45:46.539Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft
8/9/2020 - 14:45:46.539Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows
8/9/2020 - 14:45:46.540Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows
8/9/2020 - 14:45:46.540Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini
8/9/2020 - 14:45:46.540Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini
8/9/2020 - 14:45:46.541Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\wbem\fastprox.dll
8/9/2020 - 14:45:46.542Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\wbem\fastprox.dll
8/9/2020 - 14:45:46.558Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\wbem\NTDSAPI.dll
8/9/2020 - 14:45:46.559Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\ntdsapi.dll
8/9/2020 - 14:45:46.560Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\ntdsapi.dll
8/9/2020 - 14:45:46.614Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs
8/9/2020 - 14:45:46.614Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs
8/9/2020 - 14:45:46.614Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.614Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.615Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData
8/9/2020 - 14:45:46.615Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData
8/9/2020 - 14:45:46.615Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft
8/9/2020 - 14:45:46.615Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft
8/9/2020 - 14:45:46.615Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows
8/9/2020 - 14:45:46.615Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows
8/9/2020 - 14:45:46.616Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu
8/9/2020 - 14:45:46.617Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu
8/9/2020 - 14:45:46.617Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini
8/9/2020 - 14:45:46.618Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini
8/9/2020 - 14:45:46.619Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\Desktop
8/9/2020 - 14:45:46.619Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\Desktop
8/9/2020 - 14:45:46.619Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.619Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.620Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
8/9/2020 - 14:45:46.620Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
8/9/2020 - 14:45:46.620Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
8/9/2020 - 14:45:46.620Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
8/9/2020 - 14:45:46.620Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Public\Desktop
8/9/2020 - 14:45:46.621Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Public\Desktop
8/9/2020 - 14:45:46.621Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.621Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.621Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
8/9/2020 - 14:45:46.621Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
8/9/2020 - 14:45:46.621Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Public\desktop.ini
8/9/2020 - 14:45:46.622Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Public\desktop.ini
8/9/2020 - 14:45:46.622Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Public
8/9/2020 - 14:45:46.622Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Public
8/9/2020 - 14:45:46.622Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Public\Desktop\desktop.ini
8/9/2020 - 14:45:46.622Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Public\Desktop\desktop.ini
8/9/2020 - 14:45:46.623Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\apphelp.dll
8/9/2020 - 14:45:46.623Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\apphelp.dll
8/9/2020 - 14:45:46.624Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\apphelp.dll
8/9/2020 - 14:45:46.625Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\gameux.dll
8/9/2020 - 14:45:46.625Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\gameux.dll
8/9/2020 - 14:45:46.625Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\gameux.dll
8/9/2020 - 14:45:46.625Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\gameux.dll
8/9/2020 - 14:45:46.626Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe.Local
8/9/2020 - 14:45:46.626Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
8/9/2020 - 14:45:46.626Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
8/9/2020 - 14:45:46.626Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
8/9/2020 - 14:45:46.627Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe.Local
8/9/2020 - 14:45:46.627Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_14556c1e8b95d0b8
8/9/2020 - 14:45:46.627Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_14556c1e8b95d0b8
8/9/2020 - 14:45:46.627Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_14556c1e8b95d0b8
8/9/2020 - 14:45:46.627Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_14556c1e8b95d0b8\GdiPlus.dll
8/9/2020 - 14:45:46.628Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_14556c1e8b95d0b8\GdiPlus.dll
8/9/2020 - 14:45:46.628Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\xmllite.dll
8/9/2020 - 14:45:46.629Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\xmllite.dll
8/9/2020 - 14:45:46.630Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wer.dll
8/9/2020 - 14:45:46.630Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wer.dll
8/9/2020 - 14:45:46.688Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
8/9/2020 - 14:45:46.762Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
8/9/2020 - 14:45:46.763Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
8/9/2020 - 14:45:46.763Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
8/9/2020 - 14:45:46.764Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
8/9/2020 - 14:45:46.765Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
8/9/2020 - 14:45:46.765Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
8/9/2020 - 14:45:46.766Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
8/9/2020 - 14:45:46.766Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
8/9/2020 - 14:45:46.767Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
8/9/2020 - 14:45:46.768Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
8/9/2020 - 14:45:46.768Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\gameux.dll
8/9/2020 - 14:45:46.769Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
8/9/2020 - 14:45:46.769Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
8/9/2020 - 14:45:46.770Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.770Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.770Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
8/9/2020 - 14:45:46.770Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
8/9/2020 - 14:45:46.770Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
8/9/2020 - 14:45:46.770Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
8/9/2020 - 14:45:46.771Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData
8/9/2020 - 14:45:46.771Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData
8/9/2020 - 14:45:46.771Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming
8/9/2020 - 14:45:46.771Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming
8/9/2020 - 14:45:46.771Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft
8/9/2020 - 14:45:46.771Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft
8/9/2020 - 14:45:46.772Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer
8/9/2020 - 14:45:46.772Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer
8/9/2020 - 14:45:46.772Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
8/9/2020 - 14:45:46.772Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
8/9/2020 - 14:45:46.772Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch
8/9/2020 - 14:45:46.773Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch
8/9/2020 - 14:45:46.774Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\shdocvw.dll
8/9/2020 - 14:45:46.775Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\shdocvw.dll
8/9/2020 - 14:45:46.775Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\shdocvw.dll
8/9/2020 - 14:45:46.777Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.777Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.777Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
8/9/2020 - 14:45:46.778Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users
8/9/2020 - 14:45:46.778Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
8/9/2020 - 14:45:46.778Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
8/9/2020 - 14:45:46.778Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData
8/9/2020 - 14:45:46.778Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData
8/9/2020 - 14:45:46.778Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming
8/9/2020 - 14:45:46.778Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming
8/9/2020 - 14:45:46.779Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft
8/9/2020 - 14:45:46.779Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft
8/9/2020 - 14:45:46.779Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer
8/9/2020 - 14:45:46.779Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer
8/9/2020 - 14:45:46.779Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch
8/9/2020 - 14:45:46.779Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch
8/9/2020 - 14:45:46.836Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations
8/9/2020 - 14:45:46.837Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms
8/9/2020 - 14:45:46.838Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk
8/9/2020 - 14:45:46.877Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk\desktop.ini
8/9/2020 - 14:45:46.877Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk\desktop.ini
8/9/2020 - 14:45:46.878Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.878Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.879Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData
8/9/2020 - 14:45:46.879Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData
8/9/2020 - 14:45:46.879Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft
8/9/2020 - 14:45:46.879Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft
8/9/2020 - 14:45:46.879Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows
8/9/2020 - 14:45:46.879Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows
8/9/2020 - 14:45:46.880Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu
8/9/2020 - 14:45:46.880Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu
8/9/2020 - 14:45:46.880Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs
8/9/2020 - 14:45:46.880Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs
8/9/2020 - 14:45:46.880Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
8/9/2020 - 14:45:46.881Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
8/9/2020 - 14:45:46.881Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
8/9/2020 - 14:45:46.881Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
8/9/2020 - 14:45:46.881Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\desktop.ini
8/9/2020 - 14:45:46.882Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\desktop.ini
8/9/2020 - 14:45:46.882Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
8/9/2020 - 14:45:46.882Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
8/9/2020 - 14:45:46.883Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\LINKINFO.dll
8/9/2020 - 14:45:46.883Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\linkinfo.dll
8/9/2020 - 14:45:46.883Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\linkinfo.dll
8/9/2020 - 14:45:46.884Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.884Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.884Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\ntshrui.dll
8/9/2020 - 14:45:46.884Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\ntshrui.dll
8/9/2020 - 14:45:46.885Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\ntshrui.dll
8/9/2020 - 14:45:46.885Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\srvcli.dll
8/9/2020 - 14:45:46.886Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\srvcli.dll
8/9/2020 - 14:45:46.886Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\srvcli.dll
8/9/2020 - 14:45:46.926Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\cscapi.dll
8/9/2020 - 14:45:46.926Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\cscapi.dll
8/9/2020 - 14:45:46.926Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\cscapi.dll
8/9/2020 - 14:45:46.927Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\slc.dll
8/9/2020 - 14:45:46.928Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\slc.dll
8/9/2020 - 14:45:46.928Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\slc.dll
8/9/2020 - 14:45:46.929Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk
8/9/2020 - 14:45:46.929Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
8/9/2020 - 14:45:46.930Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
8/9/2020 - 14:45:46.930Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
8/9/2020 - 14:45:46.930Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
8/9/2020 - 14:45:46.930Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
8/9/2020 - 14:45:46.934Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnkWindows PowerShell.lnk
8/9/2020 - 14:45:46.934Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.934Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.935Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData
8/9/2020 - 14:45:46.935Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData
8/9/2020 - 14:45:46.935Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft
8/9/2020 - 14:45:46.935Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft
8/9/2020 - 14:45:46.935Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows
8/9/2020 - 14:45:46.935Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows
8/9/2020 - 14:45:46.936Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu
8/9/2020 - 14:45:46.936Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu
8/9/2020 - 14:45:46.936Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs
8/9/2020 - 14:45:46.936Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs
8/9/2020 - 14:45:46.936Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
8/9/2020 - 14:45:46.936Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
8/9/2020 - 14:45:46.937Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
8/9/2020 - 14:45:46.937Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
8/9/2020 - 14:45:46.937Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.937Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.937Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk
8/9/2020 - 14:45:46.937Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
8/9/2020 - 14:45:46.938Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
8/9/2020 - 14:45:46.938Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
8/9/2020 - 14:45:46.938Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
8/9/2020 - 14:45:46.938Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell
8/9/2020 - 14:45:46.938Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnkWindows PowerShell.lnk
8/9/2020 - 14:45:46.938Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
8/9/2020 - 14:45:46.938Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
8/9/2020 - 14:45:46.939Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.939Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.939Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
8/9/2020 - 14:45:46.939Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
8/9/2020 - 14:45:46.939Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32
8/9/2020 - 14:45:46.939Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32
8/9/2020 - 14:45:46.940Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell
8/9/2020 - 14:45:46.940Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell
8/9/2020 - 14:45:46.940Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
8/9/2020 - 14:45:46.940Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
8/9/2020 - 14:45:46.940Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.940Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.941Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell_ise.exe
8/9/2020 - 14:45:46.941Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
8/9/2020 - 14:45:46.941Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
8/9/2020 - 14:45:46.941Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
8/9/2020 - 14:45:46.941Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
8/9/2020 - 14:45:46.942Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
8/9/2020 - 14:45:46.942Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell_ise.exepowershell_ise.exe
8/9/2020 - 14:45:46.946Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.946Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.946Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
8/9/2020 - 14:45:46.946Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
8/9/2020 - 14:45:46.947Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.947Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:46.947Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\hh.exe
8/9/2020 - 14:45:46.948Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
8/9/2020 - 14:45:46.948Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
8/9/2020 - 14:45:46.948Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
8/9/2020 - 14:45:46.948Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
8/9/2020 - 14:45:46.949Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
8/9/2020 - 14:45:46.949Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations
8/9/2020 - 14:45:46.950Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\CRYPTSP.dll
8/9/2020 - 14:45:46.950Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\cryptsp.dll
8/9/2020 - 14:45:46.950Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\cryptsp.dll
8/9/2020 - 14:45:46.951Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
8/9/2020 - 14:45:46.951Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
8/9/2020 - 14:45:46.952Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
8/9/2020 - 14:45:46.952Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
8/9/2020 - 14:45:46.952Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
8/9/2020 - 14:45:46.952Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
8/9/2020 - 14:45:46.953Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
8/9/2020 - 14:45:46.953Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
8/9/2020 - 14:45:46.953Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
8/9/2020 - 14:45:46.954Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
8/9/2020 - 14:45:46.958Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
8/9/2020 - 14:45:46.958Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rsaenh.dll
8/9/2020 - 14:45:46.959Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\2TV8M1DLJNSQH5D2VAT5.temp
8/9/2020 - 14:45:46.959Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\2TV8M1DLJNSQH5D2VAT5.temp
8/9/2020 - 14:45:46.960Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\2TV8M1DLJNSQH5D2VAT5.temp2TV8M1DLJNSQH5D2VAT5.temp
8/9/2020 - 14:45:46.961Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\2TV8M1DLJNSQH5D2VAT5.temp2TV8M1DLJNSQH5D2VAT5.temp
8/9/2020 - 14:45:46.961Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\2TV8M1DLJNSQH5D2VAT5.temp2TV8M1DLJNSQH5D2VAT5.temp
8/9/2020 - 14:45:46.961Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\2TV8M1DLJNSQH5D2VAT5.temp2TV8M1DLJNSQH5D2VAT5.temp
8/9/2020 - 14:45:46.961Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms
8/9/2020 - 14:45:46.962Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\2TV8M1DLJNSQH5D2VAT5.temp
8/9/2020 - 14:45:46.962Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations
8/9/2020 - 14:45:46.962Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\2TV8M1DLJNSQH5D2VAT5.temp2TV8M1DLJNSQH5D2VAT5.temp
8/9/2020 - 14:45:46.963Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations
8/9/2020 - 14:45:46.964Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
8/9/2020 - 14:45:46.965Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\mscoree.dll.local
8/9/2020 - 14:45:46.965Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727
8/9/2020 - 14:45:46.965Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727
8/9/2020 - 14:45:46.965Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\Upgrades.2.0.50727
8/9/2020 - 14:45:46.966Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\Upgrades.2.0.50727
8/9/2020 - 14:45:47.21Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe.config
8/9/2020 - 14:45:47.21Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727
8/9/2020 - 14:45:47.21Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727
8/9/2020 - 14:45:47.21Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
8/9/2020 - 14:45:47.22Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
8/9/2020 - 14:45:47.304Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll
8/9/2020 - 14:45:47.351Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe.Local
8/9/2020 - 14:45:47.351Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs
8/9/2020 - 14:45:47.351Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
8/9/2020 - 14:45:47.354Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
8/9/2020 - 14:45:47.354Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
8/9/2020 - 14:45:47.355Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6\msvcr80.dll
8/9/2020 - 14:45:47.355Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6\msvcr80.dll
8/9/2020 - 14:45:47.356Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6\msvcr80.dll
8/9/2020 - 14:45:47.357Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:47.357Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:45:47.357Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
8/9/2020 - 14:45:47.357Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows
8/9/2020 - 14:45:47.357Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
8/9/2020 - 14:45:47.358Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
8/9/2020 - 14:45:49.57Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config
8/9/2020 - 14:45:49.592Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
8/9/2020 - 14:45:49.592Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
8/9/2020 - 14:45:49.694Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
8/9/2020 - 14:45:49.694Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
8/9/2020 - 14:45:49.694Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
8/9/2020 - 14:45:49.695Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
8/9/2020 - 14:45:49.695Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe.config
8/9/2020 - 14:45:49.908Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\fusion.localgac
8/9/2020 - 14:45:50.612Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config
8/9/2020 - 14:45:50.612Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config.cch
8/9/2020 - 14:45:50.613Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config
8/9/2020 - 14:45:50.614Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config.cch
8/9/2020 - 14:45:50.616Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
8/9/2020 - 14:45:50.616Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
8/9/2020 - 14:45:50.616Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
8/9/2020 - 14:45:50.616Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming
8/9/2020 - 14:45:50.617Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming
8/9/2020 - 14:45:50.617Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming
8/9/2020 - 14:45:50.617Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config
8/9/2020 - 14:45:50.617Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config.cch
8/9/2020 - 14:45:50.625Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\index187.dat
8/9/2020 - 14:45:50.692Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dll
8/9/2020 - 14:45:50.701Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:50.701Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dll
8/9/2020 - 14:45:50.702Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:50.702Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:50.736Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:50.769Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:50.802Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:50.835Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:50.873Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:50.910Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:50.944Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:50.977Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:51.11Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:51.45Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:51.80Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:51.113Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:51.146Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:51.179Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:51.213Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:51.249Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:51.283Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:51.316Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:51.349Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:51.382Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:51.417Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:51.452Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:51.488Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:51.522Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:51.588Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:51.664Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:51.699Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:51.734Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:51.803Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:51.922Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089
8/9/2020 - 14:45:51.961Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089
8/9/2020 - 14:45:51.996Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089
8/9/2020 - 14:45:52.30Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:52.237Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:52.273Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:52.340Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:52.375Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:52.409Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:52.450Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:52.485Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:52.521Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:52.563Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:52.597Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:52.632Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:52.669Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:52.774Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:52.997Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:53.175Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:53.216Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:53.353Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:53.420Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:53.461Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:53.499Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:53.667Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:53.702Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:53.744Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:53.811Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:53.844Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:53.882Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:53.916Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:53.949Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:53.989Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:54.23Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:54.57Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:54.90Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:54.160Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:54.512Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:54.545Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:54.579Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:54.612Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:54.645Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:54.746Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\ole32.dll
8/9/2020 - 14:45:54.815Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:54.848Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:54.884Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:54.918Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:54.952Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:54.994Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:55.29Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:55.96Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:55.198Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:55.231Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:55.273Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:55.309Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:55.343Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:55.377Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:55.413Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:55.447Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:55.523Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:55.577Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:55.634Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:55.672Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:55.706Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:55.739Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:55.778Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:55.845Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:55.882Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:55.916Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:55.950Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:55.984Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.19Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.53Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.86Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.120Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.158Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.193Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.226Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.260Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.294Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.330Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.364Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.398Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.432Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.467Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.501Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.542Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.578Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.646Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.681Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.750Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.807Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.867Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.905Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.939Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:56.972Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:57.5Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:57.44Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:57.79Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:57.112Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:57.146Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:57.179Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:57.213Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:57.248Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:57.282Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:57.322Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:57.357Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\OLEAUT32.dll
8/9/2020 - 14:45:57.357Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:57.391Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:58.439Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:58.476Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:58.544Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:58.584Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:58.619Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:58.653Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:58.721Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:58.755Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:58.839Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Globalization\pt-br.nlp
8/9/2020 - 14:45:58.840Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:58.922Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:58.958Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:59.129Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:45:59.165Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.config
8/9/2020 - 14:45:59.199Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\pubpol4.dat
8/9/2020 - 14:45:59.200Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC\PublisherPolicy.tme
8/9/2020 - 14:45:59.200Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config
8/9/2020 - 14:45:59.201Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
8/9/2020 - 14:45:59.201Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config
8/9/2020 - 14:45:59.201Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
8/9/2020 - 14:45:59.202Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
8/9/2020 - 14:45:59.202Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
8/9/2020 - 14:45:59.202Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
8/9/2020 - 14:45:59.202Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.configmachine.config
8/9/2020 - 14:45:59.308Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:45:59.532Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:45:59.532Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll
8/9/2020 - 14:45:59.566Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
8/9/2020 - 14:45:59.566Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll
8/9/2020 - 14:45:59.566Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
8/9/2020 - 14:45:59.600Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
8/9/2020 - 14:45:59.638Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
8/9/2020 - 14:45:59.676Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
8/9/2020 - 14:45:59.710Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
8/9/2020 - 14:45:59.745Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
8/9/2020 - 14:45:59.778Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
8/9/2020 - 14:45:59.848Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:45:59.848Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:45:59.962Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Management.Automation\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:45:59.962Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:0.65Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:0.65Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
8/9/2020 - 14:46:0.99Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:0.99Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
8/9/2020 - 14:46:0.100Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:0.140Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:0.175Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:0.210Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:0.245Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:0.280Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:0.314Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:0.348Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:0.388Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:0.422Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:0.460Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:0.529Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:0.579Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:0.646Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll
8/9/2020 - 14:46:0.647Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll
8/9/2020 - 14:46:0.647Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
8/9/2020 - 14:46:0.647Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll
8/9/2020 - 14:46:0.647Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
8/9/2020 - 14:46:0.648Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
8/9/2020 - 14:46:0.889Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:0.962Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:1.29Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:1.62Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:1.95Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:1.130Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:1.164Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:1.231Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:1.265Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
8/9/2020 - 14:46:1.298Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll
8/9/2020 - 14:46:1.333Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll
8/9/2020 - 14:46:1.436Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll
8/9/2020 - 14:46:1.488Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe.Local
8/9/2020 - 14:46:1.488Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
8/9/2020 - 14:46:1.489Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
8/9/2020 - 14:46:1.489Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
8/9/2020 - 14:46:1.781Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:1.782Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:1.783Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:1.784Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:1.784Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:1.786Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:1.787Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:1.787Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:1.791Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:1.792Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:1.792Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:1.899Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:1.899Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:1.899Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:1.937Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:1.970Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:2.3Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:2.38Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:2.72Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:2.105Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:2.138Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:2.171Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:2.208Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:2.242Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
8/9/2020 - 14:46:2.243Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
8/9/2020 - 14:46:2.243Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:2.243Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
8/9/2020 - 14:46:2.244Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:2.244Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:2.244Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:2.278Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:2.311Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:2.344Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:2.377Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:2.419Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:2.456Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:2.490Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:2.557Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:2.750Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\BVTBin\Tests\installpackage\csilogfile.log
8/9/2020 - 14:46:2.791Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:2.826Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:2.871Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:2.939Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:2.941Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:2.975Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:3.44Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:3.94Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:3.149Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:3.190Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:3.226Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:3.260Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:3.293Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:3.470Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:3.506Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:3.540Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:3.573Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:3.608Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dll
8/9/2020 - 14:46:3.711Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:3.711Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dll
8/9/2020 - 14:46:3.712Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:3.748Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:3.781Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:3.816Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:3.849Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:3.885Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:3.942Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:3.979Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:4.13Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:4.46Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:4.80Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:4.113Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:4.147Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:4.183Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:4.225Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:4.296Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:4.348Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:4.405Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:4.444Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089
8/9/2020 - 14:46:4.531Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089
8/9/2020 - 14:46:4.532Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:4.567Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:4.600Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:4.634Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:4.668Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:4.703Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:4.743Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:4.777Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:4.811Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:4.845Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:4.882Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:4.916Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:5.22Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:5.56Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:5.90Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:5.124Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:5.158Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:5.192Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:5.226Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:5.260Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:5.293Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:5.327Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:5.360Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:5.394Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:5.427Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:5.464Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:5.578Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:5.625Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:5.658Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:5.692Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:5.770Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:5.804Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:5.838Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:5.912Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:5.946Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:5.979Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:6.19Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:6.53Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:6.87Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:6.122Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:6.157Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:6.191Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:6.225Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:6.264Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:6.297Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:6.332Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:6.365Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:6.398Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:6.432Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:6.501Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:6.537Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:6.571Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:6.605Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:6.640Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:6.710Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:6.763Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:6.823Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:6.863Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:6.933Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:6.967Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:7.1Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:7.36Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:7.70Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
8/9/2020 - 14:46:7.71Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:7.71Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:7.104Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:7.138Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:7.172Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:7.208Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:7.242Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:7.283Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\version.dll
8/9/2020 - 14:46:7.284Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\version.dll
8/9/2020 - 14:46:7.285Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\version.dll
8/9/2020 - 14:46:7.286Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:7.320Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
8/9/2020 - 14:46:7.320Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:7.320Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:7.354Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:7.388Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
8/9/2020 - 14:46:7.388Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:7.388Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:7.422Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:7.458Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:7.533Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\l_intl.nls
8/9/2020 - 14:46:7.604Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:7.638Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\pt-BR\KernelBase.dll.mui
8/9/2020 - 14:46:7.639Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:7.674Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:7.708Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:7.744Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:7.778Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:7.819Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:7.860Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:7.895Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:7.932Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:7.966Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.50Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.97Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.156Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.190Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.223Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.259Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.292Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.330Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.364Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.397Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.430Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.468Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.502Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.537Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.570Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.603Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.637Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.671Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.706Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.740Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.774Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.815Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.849Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.906Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:8.982Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:9.26Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll
8/9/2020 - 14:46:9.27Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:9.101Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:9.136Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ntdll.dll
8/9/2020 - 14:46:9.138Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:9.174Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.244Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:9.292Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:9.360Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.398Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.434Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.471Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.506Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.540Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.574Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.613Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.652Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.688Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:9.722Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.756Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.791Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.829Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.830Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.830Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.868Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.903Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.903Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.905Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.906Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.907Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.907Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.908Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.946Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:9.980Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:10.15Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:10.49Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:10.83Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:10.118Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:10.152Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:10.186Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089
8/9/2020 - 14:46:10.185Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp
8/9/2020 - 14:46:10.288Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp
8/9/2020 - 14:46:10.356Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:10.389Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:10.422Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:10.492Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:10.541Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:10.606Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:10.644Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:10.678Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:10.712Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:10.747Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:10.780Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:10.813Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:10.850Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:10.896Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:10.931Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dll
8/9/2020 - 14:46:11.66Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:11.66Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dll
8/9/2020 - 14:46:11.67Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:11.100Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:11.140Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:11.174Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:11.208Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:11.241Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:11.274Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:11.307Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:11.342Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:11.381Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:11.416Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:11.450Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:11.485Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089
8/9/2020 - 14:46:11.556Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089
8/9/2020 - 14:46:11.556Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:11.590Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:11.624Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:11.662Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:11.731Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:11.782Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:11.838Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:11.903Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:11.938Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:11.973Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:12.6Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:12.40Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:12.74Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:12.107Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:12.148Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:12.183Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:12.221Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:12.255Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:12.322Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:12.356Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:12.390Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:12.435Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:12.471Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:12.507Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:12.541Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:12.580Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:12.614Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:12.650Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:12.726Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
8/9/2020 - 14:46:12.726Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:12.727Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
8/9/2020 - 14:46:12.727Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:12.727Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll
8/9/2020 - 14:46:12.727Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:12.728Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:12.762Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:12.797Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:12.833Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:12.882Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:13.13Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:13.68Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:13.129Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:13.166Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:13.239Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:13.273Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:13.388Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:13.423Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:13.460Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:13.499Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:13.658Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:13.695Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:13.768Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:13.801Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:13.875Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:13.875Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll
8/9/2020 - 14:46:13.973Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dllMicrosoft.PowerShell.Commands.Diagnostics.dll
8/9/2020 - 14:46:13.973Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll
8/9/2020 - 14:46:13.974Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dllMicrosoft.PowerShell.Commands.Diagnostics.dll
8/9/2020 - 14:46:14.9Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dllMicrosoft.PowerShell.Commands.Diagnostics.dll
8/9/2020 - 14:46:14.43Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dllMicrosoft.PowerShell.Commands.Diagnostics.dll
8/9/2020 - 14:46:14.78Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dllMicrosoft.PowerShell.Commands.Diagnostics.dll
8/9/2020 - 14:46:14.111Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dllMicrosoft.PowerShell.Commands.Diagnostics.dll
8/9/2020 - 14:46:14.144Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dllMicrosoft.PowerShell.Commands.Diagnostics.dll
8/9/2020 - 14:46:14.179Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dllMicrosoft.PowerShell.Commands.Diagnostics.dll
8/9/2020 - 14:46:14.255Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:14.256Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:14.257Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Core\3.5.0.0__b77a5c561934e089
8/9/2020 - 14:46:14.257Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089
8/9/2020 - 14:46:14.365Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089
8/9/2020 - 14:46:14.365Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll
8/9/2020 - 14:46:14.403Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
8/9/2020 - 14:46:14.403Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll
8/9/2020 - 14:46:14.403Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
8/9/2020 - 14:46:14.437Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
8/9/2020 - 14:46:14.477Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
8/9/2020 - 14:46:14.511Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
8/9/2020 - 14:46:14.545Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
8/9/2020 - 14:46:14.579Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
8/9/2020 - 14:46:14.612Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
8/9/2020 - 14:46:14.646Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
8/9/2020 - 14:46:14.679Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
8/9/2020 - 14:46:14.719Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
8/9/2020 - 14:46:14.753Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dllSystem.Core.dll
8/9/2020 - 14:46:14.788Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll
8/9/2020 - 14:46:14.789Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll
8/9/2020 - 14:46:14.789Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dllMicrosoft.PowerShell.Commands.Diagnostics.dll
8/9/2020 - 14:46:14.789Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll
8/9/2020 - 14:46:14.790Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dllMicrosoft.PowerShell.Commands.Diagnostics.dll
8/9/2020 - 14:46:14.790Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dllMicrosoft.PowerShell.Commands.Diagnostics.dll
8/9/2020 - 14:46:14.791Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:14.825Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:14.864Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:14.898Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:14.934Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:15.13Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dll
8/9/2020 - 14:46:15.48Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
8/9/2020 - 14:46:15.48Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dll
8/9/2020 - 14:46:15.48Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
8/9/2020 - 14:46:15.83Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
8/9/2020 - 14:46:15.116Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
8/9/2020 - 14:46:15.149Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
8/9/2020 - 14:46:15.183Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
8/9/2020 - 14:46:15.217Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a
8/9/2020 - 14:46:15.252Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a
8/9/2020 - 14:46:15.253Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
8/9/2020 - 14:46:15.288Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
8/9/2020 - 14:46:15.322Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
8/9/2020 - 14:46:15.356Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
8/9/2020 - 14:46:15.390Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
8/9/2020 - 14:46:15.424Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
8/9/2020 - 14:46:15.460Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
8/9/2020 - 14:46:15.539Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:15.588Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:15.648Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:15.684Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:15.758Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:15.793Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:15.828Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:15.874Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:15.942Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:15.945Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll
8/9/2020 - 14:46:15.987Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
8/9/2020 - 14:46:15.987Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll
8/9/2020 - 14:46:15.988Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
8/9/2020 - 14:46:16.22Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
8/9/2020 - 14:46:16.56Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
8/9/2020 - 14:46:16.90Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
8/9/2020 - 14:46:16.125Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
8/9/2020 - 14:46:16.159Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
8/9/2020 - 14:46:16.193Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
8/9/2020 - 14:46:16.226Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
8/9/2020 - 14:46:16.266Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:16.267Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:16.268Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:16.268Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:16.302Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:16.302Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll
8/9/2020 - 14:46:16.303Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dllMicrosoft.WSMan.Runtime.dll
8/9/2020 - 14:46:16.303Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll
8/9/2020 - 14:46:16.303Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dllMicrosoft.WSMan.Runtime.dll
8/9/2020 - 14:46:16.337Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dllMicrosoft.WSMan.Runtime.dll
8/9/2020 - 14:46:16.372Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dllMicrosoft.WSMan.Runtime.dll
8/9/2020 - 14:46:16.406Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll
8/9/2020 - 14:46:16.407Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll
8/9/2020 - 14:46:16.407Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
8/9/2020 - 14:46:16.407Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll
8/9/2020 - 14:46:16.408Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
8/9/2020 - 14:46:16.408Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
8/9/2020 - 14:46:16.446Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:16.447Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:16.447Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll
8/9/2020 - 14:46:16.447Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll
8/9/2020 - 14:46:16.448Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dllMicrosoft.WSMan.Runtime.dll
8/9/2020 - 14:46:16.448Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll
8/9/2020 - 14:46:16.448Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dllMicrosoft.WSMan.Runtime.dll
8/9/2020 - 14:46:16.448Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dllMicrosoft.WSMan.Runtime.dll
8/9/2020 - 14:46:16.450Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:16.499Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:16.541Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:16.578Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:16.613Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:16.649Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:16.718Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:16.787Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:16.844Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:16.886Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:16.920Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:16.956Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:16.989Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:17.29Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:17.68Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:17.104Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:17.141Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:17.174Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:17.208Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:17.245Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:17.279Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:17.312Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:17.346Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:17.382Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:17.451Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:17.487Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:17.538Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dll
8/9/2020 - 14:46:17.609Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:17.609Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dll
8/9/2020 - 14:46:17.610Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:17.644Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:17.678Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:17.712Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:17.747Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:17.787Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:17.821Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:17.858Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089
8/9/2020 - 14:46:17.894Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089
8/9/2020 - 14:46:17.894Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:17.928Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:18.3Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:18.85Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:18.119Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:18.154Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
8/9/2020 - 14:46:18.188Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dllSystem.Transactions.dll
8/9/2020 - 14:46:18.188Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
8/9/2020 - 14:46:18.188Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dllSystem.Transactions.dll
8/9/2020 - 14:46:18.223Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dllSystem.Transactions.dll
8/9/2020 - 14:46:18.258Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dllSystem.Transactions.dll
8/9/2020 - 14:46:18.301Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dllSystem.Transactions.dll
8/9/2020 - 14:46:18.336Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
8/9/2020 - 14:46:18.343Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dllSystem.Transactions.dll
8/9/2020 - 14:46:18.343Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dllSystem.Transactions.dll
8/9/2020 - 14:46:18.344Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe.Local
8/9/2020 - 14:46:18.344Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
8/9/2020 - 14:46:18.345Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
8/9/2020 - 14:46:18.345Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
8/9/2020 - 14:46:18.346Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
8/9/2020 - 14:46:18.346Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dllSystem.Transactions.dll
8/9/2020 - 14:46:18.347Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dllSystem.Transactions.dll
8/9/2020 - 14:46:18.347Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dllSystem.Transactions.dll
8/9/2020 - 14:46:18.349Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:18.351Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:18.352Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:18.352Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:18.353Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:18.354Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:18.354Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:18.435Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:18.480Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:18.514Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:18.515Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:18.515Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:18.515Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:18.516Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:18.551Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:18.588Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:18.623Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:18.657Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:18.691Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:18.726Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:18.760Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:18.794Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:18.829Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:18.939Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:18.974Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:18.975Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:18.975Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:19.9Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:19.43Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:19.43Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:19.43Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:19.43Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:19.44Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:19.44Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:19.46Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:19.122Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:19.196Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:19.246Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:19.246Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll
8/9/2020 - 14:46:19.246Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
8/9/2020 - 14:46:19.246Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll
8/9/2020 - 14:46:19.246Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
8/9/2020 - 14:46:19.299Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
8/9/2020 - 14:46:19.345Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
8/9/2020 - 14:46:19.379Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
8/9/2020 - 14:46:19.414Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
8/9/2020 - 14:46:19.448Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
8/9/2020 - 14:46:19.482Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
8/9/2020 - 14:46:19.520Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
8/9/2020 - 14:46:19.553Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:19.554Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:19.555Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll
8/9/2020 - 14:46:19.555Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll
8/9/2020 - 14:46:19.555Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
8/9/2020 - 14:46:19.555Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll
8/9/2020 - 14:46:19.556Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
8/9/2020 - 14:46:19.556Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
8/9/2020 - 14:46:19.557Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:19.602Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dll
8/9/2020 - 14:46:19.672Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:19.672Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dll
8/9/2020 - 14:46:19.672Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:19.708Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:19.742Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:19.776Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:19.810Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:19.859Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:19.895Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:19.930Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:19.965Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a
8/9/2020 - 14:46:20.2Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a
8/9/2020 - 14:46:20.2Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:20.38Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:20.72Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:20.113Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:20.147Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:20.180Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:20.214Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:20.249Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:20.282Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:20.315Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:20.352Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:20.392Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dll
8/9/2020 - 14:46:20.427Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
8/9/2020 - 14:46:20.427Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dll
8/9/2020 - 14:46:20.427Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
8/9/2020 - 14:46:20.498Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
8/9/2020 - 14:46:20.548Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
8/9/2020 - 14:46:20.621Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
8/9/2020 - 14:46:20.661Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
8/9/2020 - 14:46:20.695Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
8/9/2020 - 14:46:20.729Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a
8/9/2020 - 14:46:20.796Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a
8/9/2020 - 14:46:20.797Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
8/9/2020 - 14:46:20.831Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
8/9/2020 - 14:46:20.866Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
8/9/2020 - 14:46:20.899Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
8/9/2020 - 14:46:20.932Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
8/9/2020 - 14:46:20.965Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
8/9/2020 - 14:46:20.999Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
8/9/2020 - 14:46:21.32Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
8/9/2020 - 14:46:21.118Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:21.154Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:21.154Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll
8/9/2020 - 14:46:21.188Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dllMicrosoft.PowerShell.Security.dll
8/9/2020 - 14:46:21.188Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll
8/9/2020 - 14:46:21.189Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dllMicrosoft.PowerShell.Security.dll
8/9/2020 - 14:46:21.222Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dllMicrosoft.PowerShell.Security.dll
8/9/2020 - 14:46:21.255Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dllMicrosoft.PowerShell.Security.dll
8/9/2020 - 14:46:21.289Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dllMicrosoft.PowerShell.Security.dll
8/9/2020 - 14:46:21.322Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dllMicrosoft.PowerShell.Security.dll
8/9/2020 - 14:46:21.355Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:21.356Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35
8/9/2020 - 14:46:21.358Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll
8/9/2020 - 14:46:21.360Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll
8/9/2020 - 14:46:21.361Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dllMicrosoft.PowerShell.Security.dll
8/9/2020 - 14:46:21.363Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll
8/9/2020 - 14:46:21.363Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dllMicrosoft.PowerShell.Security.dll
8/9/2020 - 14:46:21.363Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dllMicrosoft.PowerShell.Security.dll
8/9/2020 - 14:46:21.365Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:21.457Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:21.492Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:21.526Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:21.559Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:21.592Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:21.634Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Globalization\en.nlp
8/9/2020 - 14:46:21.635Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.config
8/9/2020 - 14:46:21.636Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\Microsoft.PowerShell.ConsoleHost.resources\1.0.0.0_pt-BR_31bf3856ad364e35
8/9/2020 - 14:46:21.637Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
8/9/2020 - 14:46:21.637Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
8/9/2020 - 14:46:21.638Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll
8/9/2020 - 14:46:21.638Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dllMicrosoft.PowerShell.ConsoleHost.Resources.dll
8/9/2020 - 14:46:21.638Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll
8/9/2020 - 14:46:21.638Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dllMicrosoft.PowerShell.ConsoleHost.Resources.dll
8/9/2020 - 14:46:21.673Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dllMicrosoft.PowerShell.ConsoleHost.Resources.dll
8/9/2020 - 14:46:21.708Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dllMicrosoft.PowerShell.ConsoleHost.Resources.dll
8/9/2020 - 14:46:21.785Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dllMicrosoft.PowerShell.ConsoleHost.Resources.dll
8/9/2020 - 14:46:21.829Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dllMicrosoft.PowerShell.ConsoleHost.Resources.dll
8/9/2020 - 14:46:21.915Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
8/9/2020 - 14:46:21.916Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
8/9/2020 - 14:46:21.916Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll
8/9/2020 - 14:46:21.916Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll
8/9/2020 - 14:46:21.916Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dllMicrosoft.PowerShell.ConsoleHost.Resources.dll
8/9/2020 - 14:46:21.916Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll
8/9/2020 - 14:46:21.916Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dllMicrosoft.PowerShell.ConsoleHost.Resources.dll
8/9/2020 - 14:46:21.917Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dllMicrosoft.PowerShell.ConsoleHost.Resources.dll
8/9/2020 - 14:46:21.918Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:22.29Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:22.69Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:22.108Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dllMicrosoft.PowerShell.ConsoleHost.dll
8/9/2020 - 14:46:22.146Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:22.180Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:22.214Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:22.258Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:22.295Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:22.296Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:22.296Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:22.297Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:22.301Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:22.335Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:22.336Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:22.336Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:22.337Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:22.337Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:22.338Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:22.338Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:22.373Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:22.374Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:22.388Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:22.390Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:22.460Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:22.495Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:22.529Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:22.564Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:22.600Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:22.636Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:22.680Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:22.715Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:22.750Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:22.784Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:22.817Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:22.850Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:22.889Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:23.23Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:23.84Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:23.132Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:23.180Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:23.217Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:23.250Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:23.290Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:23.323Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:23.356Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:23.389Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:23.429Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:23.464Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:23.500Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:23.534Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:23.567Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:23.600Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:23.633Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:23.666Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:23.702Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:23.738Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:23.775Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:23.817Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:23.851Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:23.953Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:23.987Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:24.26Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:24.116Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:24.238Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:24.282Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:24.343Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:24.387Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:24.422Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:24.502Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:24.541Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:24.580Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:24.616Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:24.658Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:24.701Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:24.736Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:24.776Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:24.810Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:24.848Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:24.888Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:24.932Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:25.14Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:25.55Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:25.122Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:25.159Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:25.192Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:25.242Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:25.290Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:25.370Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:25.407Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:25.485Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:25.538Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:25.595Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:25.629Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:25.665Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:25.699Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dll
8/9/2020 - 14:46:25.767Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:25.767Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dll
8/9/2020 - 14:46:25.767Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:25.768Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:25.802Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:25.836Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:25.873Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:25.907Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:25.940Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:25.983Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:26.17Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a
8/9/2020 - 14:46:26.120Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a
8/9/2020 - 14:46:26.120Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:26.154Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:26.187Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:26.221Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:26.261Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:26.295Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:26.329Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:26.362Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:26.396Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:26.429Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:26.464Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:26.507Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:26.546Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:26.586Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:26.714Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:26.771Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:26.826Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:26.900Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:26.933Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:26.966Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:27.8Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:27.46Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Management.Automation.resources\1.0.0.0_pt-BR_31bf3856ad364e35
8/9/2020 - 14:46:27.46Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
8/9/2020 - 14:46:27.82Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
8/9/2020 - 14:46:27.82Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll
8/9/2020 - 14:46:27.119Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
8/9/2020 - 14:46:27.119Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll
8/9/2020 - 14:46:27.120Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
8/9/2020 - 14:46:27.153Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
8/9/2020 - 14:46:27.186Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
8/9/2020 - 14:46:27.219Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
8/9/2020 - 14:46:27.253Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
8/9/2020 - 14:46:27.287Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
8/9/2020 - 14:46:27.287Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
8/9/2020 - 14:46:27.288Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll
8/9/2020 - 14:46:27.288Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll
8/9/2020 - 14:46:27.288Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
8/9/2020 - 14:46:27.289Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll
8/9/2020 - 14:46:27.289Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
8/9/2020 - 14:46:27.289Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
8/9/2020 - 14:46:27.290Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
8/9/2020 - 14:46:27.325Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:27.364Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:27.398Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:27.432Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:27.467Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\shfolder.dll
8/9/2020 - 14:46:27.468Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\shfolder.dll
8/9/2020 - 14:46:27.503Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\shfolder.dll
8/9/2020 - 14:46:27.704Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\Documents
8/9/2020 - 14:46:27.705Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\Documents
8/9/2020 - 14:46:27.708Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:27.746Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:27.861Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:27.933Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:28.54Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:28.125Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
8/9/2020 - 14:46:28.125Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
8/9/2020 - 14:46:28.127Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xml
8/9/2020 - 14:46:28.162Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xmlgetevent.types.ps1xml
8/9/2020 - 14:46:28.163Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xml
8/9/2020 - 14:46:28.230Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:28.247Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:28.291Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:28.325Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:28.359Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:28.392Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:28.425Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:28.462Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:28.497Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:28.531Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:28.571Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:28.604Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:28.675Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:28.712Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:28.747Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:28.782Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:28.818Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:28.876Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xml
8/9/2020 - 14:46:28.876Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xmlgetevent.types.ps1xml
8/9/2020 - 14:46:28.876Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xmlgetevent.types.ps1xml
8/9/2020 - 14:46:28.877Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xmlgetevent.types.ps1xml
8/9/2020 - 14:46:28.878Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xmlgetevent.types.ps1xml
8/9/2020 - 14:46:28.878Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xmlgetevent.types.ps1xml
8/9/2020 - 14:46:28.878Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xmlgetevent.types.ps1xml
8/9/2020 - 14:46:28.878Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xmlgetevent.types.ps1xml
8/9/2020 - 14:46:28.883Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:28.883Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:28.884Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:28.884Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:28.894Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xml
8/9/2020 - 14:46:28.894Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\getevent.types.ps1xmlgetevent.types.ps1xml
8/9/2020 - 14:46:28.894Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:28.898Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:28.899Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:28.899Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:28.935Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:28.938Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:28.939Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:28.939Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:28.940Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:28.940Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:28.941Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:28.993Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:29.32Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:29.106Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:29.141Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:29.210Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:29.266Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:29.339Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:29.439Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:29.478Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:29.514Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:29.547Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:29.587Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:29.695Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:29.785Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:29.819Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:30.92Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:30.187Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:30.222Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:30.442Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xml
8/9/2020 - 14:46:30.443Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.443Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.444Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.444Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.446Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:30.447Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:30.562Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.562Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.562Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.562Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.562Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.563Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.563Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.563Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.563Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.563Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.563Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.564Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.564Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.564Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.564Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.566Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.566Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.566Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.566Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.567Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.567Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.567Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.567Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.567Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.567Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.567Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.567Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.568Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.568Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.568Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.568Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.569Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.569Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.569Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.569Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.569Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.569Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.570Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.570Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.570Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.570Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xml
8/9/2020 - 14:46:30.571Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\types.ps1xmltypes.ps1xml
8/9/2020 - 14:46:30.624Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:30.680Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:30.807Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:30.841Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:30.876Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:30.911Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:30.945Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:30.978Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:31.12Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:31.46Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:31.80Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:31.113Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:31.147Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:31.180Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:31.213Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:31.247Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:31.281Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:31.314Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:31.349Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:31.384Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:31.422Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:31.467Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:31.507Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:31.541Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:31.575Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:31.617Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:31.655Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:31.696Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:31.931Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:31.990Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:32.69Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.180Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.214Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.249Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.283Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.316Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.349Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.388Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.422Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.458Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.494Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.528Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.561Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.594Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.627Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.663Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.697Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.732Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.765Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.798Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.833Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.875Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.909Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.942Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:32.976Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:33.9Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:33.43Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:33.114Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:33.163Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:33.216Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:33.253Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:33.288Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:33.324Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:33.357Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:33.399Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:33.433Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:33.467Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:33.502Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:33.536Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:33.569Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:33.602Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:33.635Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:33.675Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:33.709Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:33.743Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:33.777Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:33.810Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:33.845Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:33.884Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:33.927Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuratio#\8761b5c0fc91ae519d028c4ea26a862f\System.Configuration.Install.ni.dllSystem.Configuration.Install.ni.dll
8/9/2020 - 14:46:33.962Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:33.997Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:34.30Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:34.64Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:34.99Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:34.132Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:34.173Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:34.208Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:34.242Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.ServiceProce#\34212bfb8a205eb6b050ce2c826f2c3b\System.ServiceProcess.ni.dllSystem.ServiceProcess.ni.dll
8/9/2020 - 14:46:34.294Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:34.382Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:34.436Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:34.492Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:34.534Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:34.603Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:34.637Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:34.670Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:34.771Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
8/9/2020 - 14:46:34.772Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0
8/9/2020 - 14:46:34.772Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml
8/9/2020 - 14:46:34.806Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
8/9/2020 - 14:46:34.806Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xml
8/9/2020 - 14:46:34.840Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xmlWSMan.Format.ps1xml
8/9/2020 - 14:46:34.840Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xml
8/9/2020 - 14:46:34.910Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
8/9/2020 - 14:46:34.910Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml
8/9/2020 - 14:46:34.910Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:34.910Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xml
8/9/2020 - 14:46:34.911Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xmlFileSystem.format.ps1xml
8/9/2020 - 14:46:34.911Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xml
8/9/2020 - 14:46:34.945Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:34.945Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml
8/9/2020 - 14:46:34.979Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:34.979Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml
8/9/2020 - 14:46:35.13Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xmlPowerShellTrace.format.ps1xml
8/9/2020 - 14:46:35.13Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xml
8/9/2020 - 14:46:35.13Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xmlRegistry.format.ps1xml
8/9/2020 - 14:46:35.30Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:35.64Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:35.99Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:35.168Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\tzres.dll
8/9/2020 - 14:46:35.168Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\tzres.dll
8/9/2020 - 14:46:35.169Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\tzres.dll
8/9/2020 - 14:46:35.169Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\tzres.dll
8/9/2020 - 14:46:35.180Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:35.217Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml
8/9/2020 - 14:46:35.218Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
8/9/2020 - 14:46:35.218Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
8/9/2020 - 14:46:35.219Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:35.220Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
8/9/2020 - 14:46:35.220Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
8/9/2020 - 14:46:35.220Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
8/9/2020 - 14:46:35.221Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
8/9/2020 - 14:46:35.221Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
8/9/2020 - 14:46:35.221Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
8/9/2020 - 14:46:35.221Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
8/9/2020 - 14:46:35.221Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
8/9/2020 - 14:46:35.221Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml
8/9/2020 - 14:46:35.222Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xmlDiagnostics.Format.ps1xml
8/9/2020 - 14:46:35.222Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:35.256Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:35.257Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:35.257Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:35.258Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:35.258Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:35.259Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:35.260Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:35.262Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:35.262Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:35.268Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:35.302Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:35.479Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xml
8/9/2020 - 14:46:35.480Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xmlWSMan.Format.ps1xml
8/9/2020 - 14:46:35.480Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xmlWSMan.Format.ps1xml
8/9/2020 - 14:46:35.481Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xmlWSMan.Format.ps1xml
8/9/2020 - 14:46:35.481Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xmlWSMan.Format.ps1xml
8/9/2020 - 14:46:35.481Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xmlWSMan.Format.ps1xml
8/9/2020 - 14:46:35.481Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xmlWSMan.Format.ps1xml
8/9/2020 - 14:46:35.481Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xmlWSMan.Format.ps1xml
8/9/2020 - 14:46:35.481Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xmlWSMan.Format.ps1xml
8/9/2020 - 14:46:35.481Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xmlWSMan.Format.ps1xml
8/9/2020 - 14:46:35.481Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xml
8/9/2020 - 14:46:35.482Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WSMan.Format.ps1xmlWSMan.Format.ps1xml
8/9/2020 - 14:46:35.546Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:35.582Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xml
8/9/2020 - 14:46:35.582Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
8/9/2020 - 14:46:35.582Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
8/9/2020 - 14:46:35.583Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
8/9/2020 - 14:46:35.583Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
8/9/2020 - 14:46:35.583Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
8/9/2020 - 14:46:35.583Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
8/9/2020 - 14:46:35.583Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
8/9/2020 - 14:46:35.583Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
8/9/2020 - 14:46:35.583Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
8/9/2020 - 14:46:35.583Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
8/9/2020 - 14:46:35.583Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xml
8/9/2020 - 14:46:35.583Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Certificate.format.ps1xmlCertificate.format.ps1xml
8/9/2020 - 14:46:35.770Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:35.828Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:35.872Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
8/9/2020 - 14:46:35.990Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.991Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.991Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.993Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.993Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.993Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.993Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.993Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.994Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.994Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.994Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.994Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.994Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.994Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.994Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.994Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.995Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.995Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.995Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.995Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.995Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.995Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.996Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.996Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xmlDotNetTypes.format.ps1xml
8/9/2020 - 14:46:35.998Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:35.999Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:36.35Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:36.68Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:36.101Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:36.134Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\29259da8265e0e428d9682df679f81d2\System.Xml.ni.dllSystem.Xml.ni.dll
8/9/2020 - 14:46:36.180Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xml
8/9/2020 - 14:46:36.181Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xmlFileSystem.format.ps1xml
8/9/2020 - 14:46:36.181Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xmlFileSystem.format.ps1xml
8/9/2020 - 14:46:36.181Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xmlFileSystem.format.ps1xml
8/9/2020 - 14:46:36.182Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xmlFileSystem.format.ps1xml
8/9/2020 - 14:46:36.182Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xmlFileSystem.format.ps1xml
8/9/2020 - 14:46:36.182Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xmlFileSystem.format.ps1xml
8/9/2020 - 14:46:36.182Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xmlFileSystem.format.ps1xml
8/9/2020 - 14:46:36.182Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xmlFileSystem.format.ps1xml
8/9/2020 - 14:46:36.182Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xmlFileSystem.format.ps1xml
8/9/2020 - 14:46:36.182Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xml
8/9/2020 - 14:46:36.182Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\FileSystem.format.ps1xmlFileSystem.format.ps1xml
8/9/2020 - 14:46:36.184Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xml
8/9/2020 - 14:46:36.184Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.184Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.226Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.260Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.260Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.260Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.260Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.260Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.260Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.260Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.261Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.261Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.261Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.261Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.261Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.261Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.261Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.262Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.262Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.262Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.263Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.263Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.263Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.263Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.263Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.263Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.263Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.263Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.263Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.264Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.264Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.264Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.264Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.264Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.264Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.265Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.265Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.265Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.265Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.265Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.265Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.266Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.266Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.266Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.266Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.266Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.266Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.266Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.266Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.266Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.266Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.267Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.267Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.267Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.267Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.267Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.267Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.267Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.267Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.267Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.267Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.268Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.268Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.268Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.268Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.268Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.268Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xml
8/9/2020 - 14:46:36.269Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Help.format.ps1xmlHelp.format.ps1xml
8/9/2020 - 14:46:36.315Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
8/9/2020 - 14:46:36.370Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.371Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.371Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.372Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.372Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.372Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.372Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.377Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.377Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.377Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.377Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.412Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.412Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.412Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.412Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.412Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.413Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.413Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.413Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.413Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.413Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.414Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.414Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.414Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.414Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.414Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.414Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.415Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xmlPowerShellCore.format.ps1xml
8/9/2020 - 14:46:36.430Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml
8/9/2020 - 14:46:36.431Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xmlPowerShellTrace.format.ps1xml
8/9/2020 - 14:46:36.431Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xmlPowerShellTrace.format.ps1xml
8/9/2020 - 14:46:36.432Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xmlPowerShellTrace.format.ps1xml
8/9/2020 - 14:46:36.432Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xmlPowerShellTrace.format.ps1xml
8/9/2020 - 14:46:36.432Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xmlPowerShellTrace.format.ps1xml
8/9/2020 - 14:46:36.432Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xmlPowerShellTrace.format.ps1xml
8/9/2020 - 14:46:36.433Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xmlPowerShellTrace.format.ps1xml
8/9/2020 - 14:46:36.433Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xmlPowerShellTrace.format.ps1xml
8/9/2020 - 14:46:36.433Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml
8/9/2020 - 14:46:36.433Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xmlPowerShellTrace.format.ps1xml
8/9/2020 - 14:46:36.434Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xml
8/9/2020 - 14:46:36.434Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xmlRegistry.format.ps1xml
8/9/2020 - 14:46:36.434Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xmlRegistry.format.ps1xml
8/9/2020 - 14:46:36.435Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xmlRegistry.format.ps1xml
8/9/2020 - 14:46:36.435Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xmlRegistry.format.ps1xml
8/9/2020 - 14:46:36.435Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xmlRegistry.format.ps1xml
8/9/2020 - 14:46:36.435Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xmlRegistry.format.ps1xml
8/9/2020 - 14:46:36.435Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xmlRegistry.format.ps1xml
8/9/2020 - 14:46:36.436Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xmlRegistry.format.ps1xml
8/9/2020 - 14:46:36.436Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xml
8/9/2020 - 14:46:36.436Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Registry.format.ps1xmlRegistry.format.ps1xml
8/9/2020 - 14:46:36.515Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:36.607Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dllMicrosoft.WSMan.Management.dll
8/9/2020 - 14:46:36.687Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:36.747Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\Microsoft.WSMan.Management.resources\1.0.0.0_pt-BR_31bf3856ad364e35
8/9/2020 - 14:46:36.748Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
8/9/2020 - 14:46:36.749Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
8/9/2020 - 14:46:36.749Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll
8/9/2020 - 14:46:36.749Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dllMicrosoft.WSMan.Management.resources.dll
8/9/2020 - 14:46:36.749Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll
8/9/2020 - 14:46:36.749Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dllMicrosoft.WSMan.Management.resources.dll
8/9/2020 - 14:46:36.783Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dllMicrosoft.WSMan.Management.resources.dll
8/9/2020 - 14:46:36.816Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dllMicrosoft.WSMan.Management.resources.dll
8/9/2020 - 14:46:36.849Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dllMicrosoft.WSMan.Management.resources.dll
8/9/2020 - 14:46:36.890Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
8/9/2020 - 14:46:36.890Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
8/9/2020 - 14:46:36.891Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll
8/9/2020 - 14:46:36.891Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll
8/9/2020 - 14:46:36.891Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dllMicrosoft.WSMan.Management.resources.dll
8/9/2020 - 14:46:36.892Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll
8/9/2020 - 14:46:36.892Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dllMicrosoft.WSMan.Management.resources.dll
8/9/2020 - 14:46:36.892Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dllMicrosoft.WSMan.Management.resources.dll
8/9/2020 - 14:46:37.47Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:37.121Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:37.155Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:37.190Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:37.226Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:37.259Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:37.292Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:37.393Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:37.426Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:37.460Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:37.508Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:37.542Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:37.586Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:37.624Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\secur32.dll
8/9/2020 - 14:46:37.625Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\secur32.dll
8/9/2020 - 14:46:37.625Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\secur32.dll
8/9/2020 - 14:46:37.625Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\secur32.dll
8/9/2020 - 14:46:37.625Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\SSPICLI.DLL
8/9/2020 - 14:46:37.625Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\sspicli.dll
8/9/2020 - 14:46:37.626Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\sspicli.dll
8/9/2020 - 14:46:37.626Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:37.663Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:37.697Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:37.746Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
8/9/2020 - 14:46:37.787Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:38.83Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:38.89Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
8/9/2020 - 14:46:38.90Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot
8/9/2020 - 14:46:38.90Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:38.128Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:38.128Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:38.130Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:46:38.130Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:46:38.131Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:46:38.131Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:46:38.139Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:46:38.139Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:46:38.139Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:46:38.139Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:46:38.140Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:46:38.140Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:46:38.255Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:38.263Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Transactions\b244a460caa24cae27edccf8bd6661ea\System.Transactions.ni.dllSystem.Transactions.ni.dll
8/9/2020 - 14:46:38.266Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
8/9/2020 - 14:46:38.334Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dllSystem.Management.Automation.Resources.dll
8/9/2020 - 14:46:38.399Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\Microsoft.PowerShell.Security.resources\1.0.0.0_pt-BR_31bf3856ad364e35
8/9/2020 - 14:46:38.400Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
8/9/2020 - 14:46:38.401Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
8/9/2020 - 14:46:38.401Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dll
8/9/2020 - 14:46:38.401Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dllMicrosoft.PowerShell.Security.Resources.dll
8/9/2020 - 14:46:38.401Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dll
8/9/2020 - 14:46:38.402Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dllMicrosoft.PowerShell.Security.Resources.dll
8/9/2020 - 14:46:38.402Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dllMicrosoft.PowerShell.Security.Resources.dll
8/9/2020 - 14:46:38.403Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dllMicrosoft.PowerShell.Security.Resources.dll
8/9/2020 - 14:46:38.403Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
8/9/2020 - 14:46:38.404Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35
8/9/2020 - 14:46:38.404Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dll
8/9/2020 - 14:46:38.404Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dll
8/9/2020 - 14:46:38.404Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dllMicrosoft.PowerShell.Security.Resources.dll
8/9/2020 - 14:46:38.404Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dll
8/9/2020 - 14:46:38.405Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dllMicrosoft.PowerShell.Security.Resources.dll
8/9/2020 - 14:46:38.405Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dllMicrosoft.PowerShell.Security.Resources.dll
8/9/2020 - 14:46:38.736Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:38.769Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:38.864Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
8/9/2020 - 14:46:38.864Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
8/9/2020 - 14:46:38.864Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
8/9/2020 - 14:46:38.865Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
8/9/2020 - 14:46:38.932Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:46:38.932Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:46:38.932Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:46:38.932Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\
8/9/2020 - 14:46:38.932Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
8/9/2020 - 14:46:38.932Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
8/9/2020 - 14:46:38.933Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
8/9/2020 - 14:46:38.933Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
8/9/2020 - 14:46:38.934Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
8/9/2020 - 14:46:38.934Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
8/9/2020 - 14:46:38.934Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
8/9/2020 - 14:46:38.935Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
8/9/2020 - 14:46:38.935Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:39.19Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
8/9/2020 - 14:46:39.19Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
8/9/2020 - 14:46:39.83Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:39.84Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:39.85Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:39.86Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:39.348Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:39.447Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:39.554Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:39.602Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:39.655Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:39.692Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:39.726Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.DirectorySer#\d56182df8af7a981e8c272549c931fa5\System.DirectoryServices.ni.dllSystem.DirectoryServices.ni.dll
8/9/2020 - 14:46:39.810Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:40.153Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:40.189Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dll
8/9/2020 - 14:46:40.256Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:40.256Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dll
8/9/2020 - 14:46:40.256Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:40.297Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:40.331Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:40.364Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:40.398Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:40.431Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:40.465Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:40.499Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:40.533Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:40.573Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:40.607Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:40.640Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:40.673Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:40.709Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:40.778Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089
8/9/2020 - 14:46:40.885Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089
8/9/2020 - 14:46:40.885Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:40.922Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:40.956Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:40.989Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:41.22Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:41.55Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:41.88Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
8/9/2020 - 14:46:41.122Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
8/9/2020 - 14:46:41.122Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
8/9/2020 - 14:46:41.122Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
8/9/2020 - 14:46:41.155Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
8/9/2020 - 14:46:41.188Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
8/9/2020 - 14:46:41.221Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
8/9/2020 - 14:46:41.255Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
8/9/2020 - 14:46:41.290Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
8/9/2020 - 14:46:41.323Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
8/9/2020 - 14:46:41.331Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
8/9/2020 - 14:46:41.331Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
8/9/2020 - 14:46:41.331Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
8/9/2020 - 14:46:41.332Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe.Local
8/9/2020 - 14:46:41.333Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
8/9/2020 - 14:46:41.333Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
8/9/2020 - 14:46:41.333Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
8/9/2020 - 14:46:41.334Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
8/9/2020 - 14:46:41.335Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
8/9/2020 - 14:46:41.335Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
8/9/2020 - 14:46:41.371Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
8/9/2020 - 14:46:41.372Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:41.372Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:41.406Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:41.406Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:41.440Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:41.440Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:41.441Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:41.441Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:41.442Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:41.442Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dllSystem.Data.dll
8/9/2020 - 14:46:41.443Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:41.444Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:41.444Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:41.445Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:41.446Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:41.446Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:41.451Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:41.451Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:41.505Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:41.540Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:41.582Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:41.615Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:41.652Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:41.685Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:41.930Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:41.965Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.35Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.93Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.149Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.187Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.220Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.253Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.287Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.321Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.360Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.394Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.428Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.462Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.496Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.529Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.562Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.596Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.629Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.663Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.696Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.729Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.762Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.795Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.830Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.866Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.902Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.936Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:42.994Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:43.31Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:43.244Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\profile.ps1
8/9/2020 - 14:46:43.245Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\Microsoft.PowerShell_profile.ps1
8/9/2020 - 14:46:43.245Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\Documents\WindowsPowerShell\profile.ps1
8/9/2020 - 14:46:43.245Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1
8/9/2020 - 14:46:43.564Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:43.565Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:43.761Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dllMicrosoft.PowerShell.Commands.Utility.dll
8/9/2020 - 14:46:43.932Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:44.32Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:44.66Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:44.172Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:44.249Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:44.282Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:44.317Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:44.350Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:44.383Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:44.737Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:44.795Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Globalization\en-us.nlp
8/9/2020 - 14:46:44.796Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089
8/9/2020 - 14:46:44.796Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089
8/9/2020 - 14:46:44.879Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089
8/9/2020 - 14:46:44.879Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll
8/9/2020 - 14:46:44.950Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dllmscorlib.resources.dll
8/9/2020 - 14:46:44.950Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll
8/9/2020 - 14:46:44.951Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dllmscorlib.resources.dll
8/9/2020 - 14:46:44.984Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dllmscorlib.resources.dll
8/9/2020 - 14:46:45.17Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dllmscorlib.resources.dll
8/9/2020 - 14:46:45.51Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dllmscorlib.resources.dll
8/9/2020 - 14:46:45.85Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dllmscorlib.resources.dll
8/9/2020 - 14:46:45.119Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089
8/9/2020 - 14:46:45.120Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089
8/9/2020 - 14:46:45.120Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll
8/9/2020 - 14:46:45.122Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll
8/9/2020 - 14:46:45.125Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dllmscorlib.resources.dll
8/9/2020 - 14:46:45.125Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll
8/9/2020 - 14:46:45.127Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dllmscorlib.resources.dll
8/9/2020 - 14:46:45.127Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dllmscorlib.resources.dll
8/9/2020 - 14:46:45.128Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dllmscorlib.resources.dll
8/9/2020 - 14:46:45.441Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:45.499Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:45.533Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:45.610Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:45.657Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:45.802Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:45.837Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:45.875Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:45.911Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:45.979Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:46.21Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:46.54Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:46.87Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:46.122Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:46.165Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:46.199Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:46.233Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:46.266Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:46.309Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:46.535Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dllSystem.Management.Automation.dll
8/9/2020 - 14:46:46.571Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dllMicrosoft.PowerShell.Commands.Management.dll
8/9/2020 - 14:46:46.638Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:46.681Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:46.715Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:46.750Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:46.806Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:46.840Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:46.878Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:46.920Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:46.955Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:46.989Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:47.56Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:47.90Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:47.124Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:47.230Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\RpcRtRemote.dll
8/9/2020 - 14:46:47.231Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\RpcRtRemote.dll
8/9/2020 - 14:46:47.231Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\RpcRtRemote.dllRpcRtRemote.dll
8/9/2020 - 14:46:47.231Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\RpcRtRemote.dll
8/9/2020 - 14:46:47.232Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\RpcRtRemote.dllRpcRtRemote.dll
8/9/2020 - 14:46:47.269Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:47.303Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dll
8/9/2020 - 14:46:47.304Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dllWMINet_Utils.dll
8/9/2020 - 14:46:47.305Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dll
8/9/2020 - 14:46:47.305Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dllWMINet_Utils.dll
8/9/2020 - 14:46:47.305Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dllWMINet_Utils.dll
8/9/2020 - 14:46:47.340Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dllWMINet_Utils.dll
8/9/2020 - 14:46:47.341Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dll
8/9/2020 - 14:46:47.349Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dllWMINet_Utils.dll
8/9/2020 - 14:46:47.349Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dllWMINet_Utils.dll
8/9/2020 - 14:46:47.350Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe.Local
8/9/2020 - 14:46:47.350Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
8/9/2020 - 14:46:47.350Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
8/9/2020 - 14:46:47.350Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
8/9/2020 - 14:46:47.351Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dllWMINet_Utils.dll
8/9/2020 - 14:46:47.481Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:47.552Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:47.596Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\wmiutils.dll
8/9/2020 - 14:46:47.596Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\wmiutils.dll
8/9/2020 - 14:46:47.597Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\wbemcomn.dll
8/9/2020 - 14:46:47.597Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbemcomn.dll
8/9/2020 - 14:46:47.597Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbemcomn.dll
8/9/2020 - 14:46:47.598Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\Logs
8/9/2020 - 14:46:47.599Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\Logs
8/9/2020 - 14:46:47.601Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\wbemprox.dll
8/9/2020 - 14:46:47.601Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\wbemprox.dll
8/9/2020 - 14:46:47.637Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:47.671Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\oleaut32.dll
8/9/2020 - 14:46:47.708Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\nlaapi.dll
8/9/2020 - 14:46:47.708Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\nlaapi.dll
8/9/2020 - 14:46:47.708Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\NapiNSP.dll
8/9/2020 - 14:46:47.708Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\NapiNSP.dll
8/9/2020 - 14:46:47.777Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\pnrpnsp.dll
8/9/2020 - 14:46:47.778Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\pnrpnsp.dll
8/9/2020 - 14:46:47.846Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\mswsock.dll
8/9/2020 - 14:46:47.847Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\mswsock.dll
8/9/2020 - 14:46:47.847Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\DNSAPI.dll
8/9/2020 - 14:46:47.848Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\dnsapi.dll
8/9/2020 - 14:46:47.848Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\dnsapi.dll
8/9/2020 - 14:46:47.849Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\winrnr.dll
8/9/2020 - 14:46:47.849Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\winrnr.dll
8/9/2020 - 14:46:47.951Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\IPHLPAPI.DLL
8/9/2020 - 14:46:47.951Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\IPHLPAPI.DLL
8/9/2020 - 14:46:47.952Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\IPHLPAPI.DLL
8/9/2020 - 14:46:47.952Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\WINNSI.DLL
8/9/2020 - 14:46:47.952Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\winnsi.dll
8/9/2020 - 14:46:47.953Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\winnsi.dll
8/9/2020 - 14:46:47.991Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\FWPUCLNT.DLL
8/9/2020 - 14:46:47.992Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\FWPUCLNT.DLL
8/9/2020 - 14:46:48.61Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\rasadhlp.dll
8/9/2020 - 14:46:48.61Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rasadhlp.dll
8/9/2020 - 14:46:48.62Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\rasadhlp.dll
8/9/2020 - 14:46:48.238Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\wbemsvc.dll
8/9/2020 - 14:46:48.238Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\wbemsvc.dll
8/9/2020 - 14:46:48.275Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\fastprox.dll
8/9/2020 - 14:46:48.276Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\fastprox.dll
8/9/2020 - 14:46:48.276Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\NTDSAPI.dll
8/9/2020 - 14:46:48.277Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\ntdsapi.dll
8/9/2020 - 14:46:48.277Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\ntdsapi.dll
8/9/2020 - 14:46:48.572Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:50.302Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:50.307Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:50.518Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:50.589Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\pt-BR\wmiutils.dll.mui
8/9/2020 - 14:46:50.590Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\system32\wbem\pt\wmiutils.dll.mui
8/9/2020 - 14:46:50.590Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\en-US\wmiutils.dll.mui
8/9/2020 - 14:46:50.625Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\wbem\en-US\wmiutils.dll.muiwmiutils.dll.mui
8/9/2020 - 14:46:51.2Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:51.84Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:51.118Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:51.151Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\423a86328b4997e022986fc2450b9971\System.Management.ni.dllSystem.Management.ni.dll
8/9/2020 - 14:46:51.720Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:51.762Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System\9b0f837c5a73d17be9743868915d6115\System.ni.dllSystem.ni.dll
8/9/2020 - 14:46:51.797Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\fe6ac93181b40a571892e14bfb9d65f2\mscorlib.ni.dllmscorlib.ni.dll
8/9/2020 - 14:46:53.540Read804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\assembly\NativeImages_v2.0.50727_64\System.Data\2ef0e7c843a98f5ad2702a8755d1558b\System.Data.ni.dllSystem.Data.ni.dll
8/9/2020 - 14:46:53.616Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config.cch.804.1122156
8/9/2020 - 14:46:53.617Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config.cch.804.1122156
8/9/2020 - 14:46:53.617Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Users\Behemot\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config.cch.804.1122156
8/9/2020 - 14:46:53.619Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\netutils.dll
8/9/2020 - 14:46:53.619Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\netutils.dll
8/9/2020 - 14:46:53.619Open804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\netutils.dll
8/9/2020 - 14:46:53.627Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Monitor
8/9/2020 - 14:46:53.627Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\pt-BR\powershell.exe.muipowershell.exe.mui
8/9/2020 - 14:46:53.627Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757
8/9/2020 - 14:46:53.627Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_14556c1e8b95d0b8
8/9/2020 - 14:46:53.628Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
8/9/2020 - 14:46:53.628Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
8/9/2020 - 14:46:53.628Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\pt-BR\KernelBase.dll.muiKernelBase.dll.mui
8/9/2020 - 14:46:53.628Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
8/9/2020 - 14:46:53.629Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
8/9/2020 - 14:46:53.629Unknown804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_88df89932faf0bf6
8/9/2020 - 14:46:53.656Open1488C:\Monitor\proc.exeC:\
8/9/2020 - 14:46:53.657Unknown1488C:\Monitor\proc.exeC:\
8/9/2020 - 14:46:53.657Open1488C:\Monitor\proc.exeC:\
8/9/2020 - 14:46:53.657Unknown1488C:\Monitor\proc.exeC:\
8/9/2020 - 14:46:53.657Open1488C:\Monitor\proc.exeC:\2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.658Write1488C:\Monitor\proc.exeC:\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.658Unknown1488C:\Monitor\proc.exeC:\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.658Open1488C:\Monitor\proc.exeC:\
8/9/2020 - 14:46:53.658Open1488C:\Monitor\proc.exeC:\Monitor
8/9/2020 - 14:46:53.658Unknown1488C:\Monitor\proc.exeC:\Monitor
8/9/2020 - 14:46:53.658Open1488C:\Monitor\proc.exeC:\Monitor
8/9/2020 - 14:46:53.659Unknown1488C:\Monitor\proc.exeC:\Monitor
8/9/2020 - 14:46:53.659Open1488C:\Monitor\proc.exeC:\Monitor\2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.660Write1488C:\Monitor\proc.exeC:\Monitor\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.660Unknown1488C:\Monitor\proc.exeC:\Monitor\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.660Open1488C:\Monitor\proc.exeC:\Program Files
8/9/2020 - 14:46:53.660Unknown1488C:\Monitor\proc.exeC:\Program Files
8/9/2020 - 14:46:53.660Open1488C:\Monitor\proc.exeC:\Program Files
8/9/2020 - 14:46:53.661Unknown1488C:\Monitor\proc.exeC:\Program Files
8/9/2020 - 14:46:53.661Open1488C:\Monitor\proc.exeC:\Program Files\2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.661Write1488C:\Monitor\proc.exeC:\Program Files\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.662Unknown1488C:\Monitor\proc.exeC:\Program Files\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.662Open1488C:\Monitor\proc.exeC:\Program Files (x86)
8/9/2020 - 14:46:53.662Unknown1488C:\Monitor\proc.exeC:\Program Files (x86)
8/9/2020 - 14:46:53.662Open1488C:\Monitor\proc.exeC:\Program Files (x86)
8/9/2020 - 14:46:53.662Unknown1488C:\Monitor\proc.exeC:\Program Files (x86)
8/9/2020 - 14:46:53.662Open1488C:\Monitor\proc.exeC:\Program Files (x86)\2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.663Write1488C:\Monitor\proc.exeC:\Program Files (x86)\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.663Unknown1488C:\Monitor\proc.exeC:\Program Files (x86)\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.663Open1488C:\Monitor\proc.exeC:\Recovery
8/9/2020 - 14:46:53.663Unknown1488C:\Monitor\proc.exeC:\Recovery
8/9/2020 - 14:46:53.663Open1488C:\Monitor\proc.exeC:\Recovery
8/9/2020 - 14:46:53.664Unknown1488C:\Monitor\proc.exeC:\Recovery
8/9/2020 - 14:46:53.664Open1488C:\Monitor\proc.exeC:\Recovery\2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.664Write1488C:\Monitor\proc.exeC:\Recovery\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.664Unknown1488C:\Monitor\proc.exeC:\Recovery\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.664Open1488C:\Monitor\proc.exeC:\Users
8/9/2020 - 14:46:53.685Unknown1488C:\Monitor\proc.exeC:\Users
8/9/2020 - 14:46:53.685Open1488C:\Monitor\proc.exeC:\Users
8/9/2020 - 14:46:53.687Unknown1488C:\Monitor\proc.exeC:\Users
8/9/2020 - 14:46:53.687Open1488C:\Monitor\proc.exeC:\Users\2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.687Write1488C:\Monitor\proc.exeC:\Users\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.688Unknown1488C:\Monitor\proc.exeC:\Users\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.688Unknown1488C:\Monitor\proc.exeC:\
8/9/2020 - 14:46:53.688Open1488C:\Monitor\proc.exeC:\Monitor
8/9/2020 - 14:46:53.689Open1488C:\Monitor\proc.exeC:\Monitor\Files
8/9/2020 - 14:46:53.689Unknown1488C:\Monitor\proc.exeC:\Monitor\Files
8/9/2020 - 14:46:53.689Open1488C:\Monitor\proc.exeC:\Monitor\Files
8/9/2020 - 14:46:53.690Unknown1488C:\Monitor\proc.exeC:\Monitor\Files
8/9/2020 - 14:46:53.690Open1488C:\Monitor\proc.exeC:\Monitor\Files\2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.690Write1488C:\Monitor\proc.exeC:\Monitor\Files\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.691Unknown1488C:\Monitor\proc.exeC:\Monitor\Files\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.691Open1488C:\Monitor\proc.exeC:\Monitor\Malware
8/9/2020 - 14:46:53.691Unknown1488C:\Monitor\proc.exeC:\Monitor\Malware
8/9/2020 - 14:46:53.691Open1488C:\Monitor\proc.exeC:\Monitor\Malware
8/9/2020 - 14:46:53.693Unknown1488C:\Monitor\proc.exeC:\Monitor\Malware
8/9/2020 - 14:46:53.693Open1488C:\Monitor\proc.exeC:\2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.694Write1488C:\Monitor\proc.exeC:\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.694Unknown1488C:\Monitor\proc.exeC:\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.694Open1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package
8/9/2020 - 14:46:53.694Unknown1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package
8/9/2020 - 14:46:53.694Open1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package
8/9/2020 - 14:46:53.702Unknown1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package
8/9/2020 - 14:46:53.703Open1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package\2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.711Write1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.711Unknown1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.711Unknown1488C:\Monitor\proc.exeC:\Monitor
8/9/2020 - 14:46:53.711Open1488C:\Monitor\proc.exeC:\Program Files
8/9/2020 - 14:46:53.711Unknown1488C:\Monitor\proc.exeC:\Program Files
8/9/2020 - 14:46:53.711Open1488C:\Monitor\proc.exeC:\Program Files (x86)
8/9/2020 - 14:46:53.712Unknown1488C:\Monitor\proc.exeC:\Program Files (x86)
8/9/2020 - 14:46:53.712Open1488C:\Monitor\proc.exeC:\Recovery
8/9/2020 - 14:46:53.712Open1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13
8/9/2020 - 14:46:53.712Unknown1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13
8/9/2020 - 14:46:53.712Open1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13
8/9/2020 - 14:46:53.712Unknown1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13
8/9/2020 - 14:46:53.712Open1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.712Write1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.713Unknown1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.713Unknown1488C:\Monitor\proc.exeC:\Recovery
8/9/2020 - 14:46:53.713Open1488C:\Monitor\proc.exeC:\Users
8/9/2020 - 14:46:53.713Open1488C:\Monitor\proc.exeC:\Users\Behemot
8/9/2020 - 14:46:53.713Unknown1488C:\Monitor\proc.exeC:\Users\Behemot
8/9/2020 - 14:46:53.713Open1488C:\Monitor\proc.exeC:\Users\Behemot
8/9/2020 - 14:46:53.713Unknown1488C:\Monitor\proc.exeC:\Users\Behemot
8/9/2020 - 14:46:53.713Open1488C:\Monitor\proc.exeC:\Users\Behemot\2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.714Write1488C:\Monitor\proc.exeC:\Users\Behemot\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.714Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.714Open1488C:\Monitor\proc.exeC:\Users\Default
8/9/2020 - 14:46:53.714Unknown1488C:\Monitor\proc.exeC:\Users\Default
8/9/2020 - 14:46:53.714Open1488C:\Monitor\proc.exeC:\Users\Default
8/9/2020 - 14:46:53.714Unknown1488C:\Monitor\proc.exeC:\Users\Default
8/9/2020 - 14:46:53.714Open1488C:\Monitor\proc.exeC:\Users\Default\2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.716Write1488C:\Monitor\proc.exeC:\Users\Default\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.716Unknown1488C:\Monitor\proc.exeC:\Users\Default\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.716Open1488C:\Monitor\proc.exeC:\Users\Public
8/9/2020 - 14:46:53.716Unknown1488C:\Monitor\proc.exeC:\Users\Public
8/9/2020 - 14:46:53.716Open1488C:\Monitor\proc.exeC:\Users\Public
8/9/2020 - 14:46:53.717Unknown1488C:\Monitor\proc.exeC:\Users\Public
8/9/2020 - 14:46:53.717Open1488C:\Monitor\proc.exeC:\Users\Public\2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.717Write1488C:\Monitor\proc.exeC:\Users\Public\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.717Unknown1488C:\Monitor\proc.exeC:\Users\Public\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.717Unknown1488C:\Monitor\proc.exeC:\Users
8/9/2020 - 14:46:53.717Open1488C:\Monitor\proc.exeC:\Monitor\Files
8/9/2020 - 14:46:53.717Open1488C:\Monitor\proc.exeC:\Monitor\Files\DeletedFiles
8/9/2020 - 14:46:53.717Unknown1488C:\Monitor\proc.exeC:\Monitor\Files\DeletedFiles
8/9/2020 - 14:46:53.718Open1488C:\Monitor\proc.exeC:\Monitor\Files\DeletedFiles
8/9/2020 - 14:46:53.718Unknown1488C:\Monitor\proc.exeC:\Monitor\Files\DeletedFiles
8/9/2020 - 14:46:53.718Open1488C:\Monitor\proc.exeC:\Monitor\Files\DeletedFiles\2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.719Write1488C:\Monitor\proc.exeC:\Monitor\Files\DeletedFiles\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.719Unknown1488C:\Monitor\proc.exeC:\Monitor\Files\DeletedFiles\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.719Open1488C:\Monitor\proc.exeC:\Monitor\Files\Logs
8/9/2020 - 14:46:53.719Unknown1488C:\Monitor\proc.exeC:\Monitor\Files\Logs
8/9/2020 - 14:46:53.719Open1488C:\Monitor\proc.exeC:\Monitor\Files\Logs
8/9/2020 - 14:46:53.719Unknown1488C:\Monitor\proc.exeC:\Monitor\Files\Logs
8/9/2020 - 14:46:53.719Open1488C:\Monitor\proc.exeC:\Monitor\Files\Logs\2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.719Write1488C:\Monitor\proc.exeC:\Monitor\Files\Logs\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.720Unknown1488C:\Monitor\proc.exeC:\Monitor\Files\Logs\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.720Unknown1488C:\Monitor\proc.exeC:\Monitor\Files
8/9/2020 - 14:46:53.720Open1488C:\Monitor\proc.exeC:\Monitor\Malware
8/9/2020 - 14:46:53.720Unknown1488C:\Monitor\proc.exeC:\Monitor\Malware
8/9/2020 - 14:46:53.720Open1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package
8/9/2020 - 14:46:53.720Open1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.cat
8/9/2020 - 14:46:53.720Read1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
8/9/2020 - 14:46:53.720Read1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
8/9/2020 - 14:46:53.727Open1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.cat
8/9/2020 - 14:46:53.729Open1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.inf
8/9/2020 - 14:46:53.729Read1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
8/9/2020 - 14:46:53.730Open1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.inf
8/9/2020 - 14:46:53.732Unknown1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package
8/9/2020 - 14:46:53.732Open1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13
8/9/2020 - 14:46:53.732Open1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
8/9/2020 - 14:46:53.732Read1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
8/9/2020 - 14:46:53.733Read1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
8/9/2020 - 14:46:53.733Open1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
8/9/2020 - 14:46:53.735Open1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
8/9/2020 - 14:46:53.736Read1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
8/9/2020 - 14:46:53.736Read1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
8/9/2020 - 14:46:53.737Open1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
8/9/2020 - 14:46:53.739Unknown1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13
8/9/2020 - 14:46:53.739Open1488C:\Monitor\proc.exeC:\Users\Behemot
8/9/2020 - 14:46:53.739Open1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts
8/9/2020 - 14:46:53.739Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts
8/9/2020 - 14:46:53.739Open1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts
8/9/2020 - 14:46:53.739Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts
8/9/2020 - 14:46:53.739Open1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts\2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.740Write1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.740Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.740Open1488C:\Monitor\proc.exeC:\Users\Behemot\Desktop
8/9/2020 - 14:46:53.740Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Desktop
8/9/2020 - 14:46:53.740Open1488C:\Monitor\proc.exeC:\Users\Behemot\Desktop
8/9/2020 - 14:46:53.740Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Desktop
8/9/2020 - 14:46:53.740Open1488C:\Monitor\proc.exeC:\Users\Behemot\Desktop\2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.789Read1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
8/9/2020 - 14:46:53.790Read1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
8/9/2020 - 14:46:53.791Read1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
8/9/2020 - 14:46:53.791Read1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
8/9/2020 - 14:46:53.792Write1488C:\Monitor\proc.exeC:\Users\Behemot\Desktop\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.795Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Desktop\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.795Open1488C:\Monitor\proc.exeC:\Users\Behemot\Documents
8/9/2020 - 14:46:53.796Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Documents
8/9/2020 - 14:46:53.796Open1488C:\Monitor\proc.exeC:\Users\Behemot\Documents
8/9/2020 - 14:46:53.798Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Documents
8/9/2020 - 14:46:53.799Open1488C:\Monitor\proc.exeC:\Users\Behemot\Documents\2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.837Read1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
8/9/2020 - 14:46:53.837Read1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
8/9/2020 - 14:46:53.838Write1488C:\Monitor\proc.exeC:\Users\Behemot\Documents\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.838Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Documents\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.838Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads
8/9/2020 - 14:46:53.839Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads
8/9/2020 - 14:46:53.839Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads
8/9/2020 - 14:46:53.839Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads
8/9/2020 - 14:46:53.839Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.876Write1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
8/9/2020 - 14:46:53.876Write1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
8/9/2020 - 14:46:53.888Write1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
8/9/2020 - 14:46:53.898Write1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
8/9/2020 - 14:46:53.899Write1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
8/9/2020 - 14:46:53.899Write1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
8/9/2020 - 14:46:53.899Write1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
8/9/2020 - 14:46:53.899Write1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
8/9/2020 - 14:46:53.899Unknown1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
8/9/2020 - 14:46:53.899Open1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.cat
8/9/2020 - 14:46:53.900Open1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package
8/9/2020 - 14:46:53.900Unknown1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
8/9/2020 - 14:46:53.900Unknown1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package
8/9/2020 - 14:46:53.900Unknown1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
8/9/2020 - 14:46:53.901Open1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
8/9/2020 - 14:46:53.901Open1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13
8/9/2020 - 14:46:53.901Unknown1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\boot.sdi
8/9/2020 - 14:46:53.901Unknown1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13
8/9/2020 - 14:46:53.938Write1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.938Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.938Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites
8/9/2020 - 14:46:53.938Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites
8/9/2020 - 14:46:53.939Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites
8/9/2020 - 14:46:53.939Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites
8/9/2020 - 14:46:53.939Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.986Unknown1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
8/9/2020 - 14:46:53.986Open1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.inf
8/9/2020 - 14:46:53.986Open1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package
8/9/2020 - 14:46:53.987Unknown1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
8/9/2020 - 14:46:53.987Unknown1488C:\Monitor\proc.exeC:\Monitor\WindowsKernelCaptureDriver Package
8/9/2020 - 14:46:53.987Unknown1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
8/9/2020 - 14:46:53.987Open1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
8/9/2020 - 14:46:53.987Open1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13
8/9/2020 - 14:46:53.989Unknown1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13\Winre.wim
8/9/2020 - 14:46:53.989Unknown1488C:\Monitor\proc.exeC:\Recovery\cb520dab-4f12-11e8-9b22-525400842a13
8/9/2020 - 14:46:53.995Write1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.995Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:53.995Open1488C:\Monitor\proc.exeC:\Users\Behemot\Links
8/9/2020 - 14:46:53.996Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Links
8/9/2020 - 14:46:53.996Open1488C:\Monitor\proc.exeC:\Users\Behemot\Links
8/9/2020 - 14:46:53.996Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Links
8/9/2020 - 14:46:53.996Open1488C:\Monitor\proc.exeC:\Users\Behemot\Links\2x93mlc4s-readme.txt
8/9/2020 - 14:46:54.36Write1488C:\Monitor\proc.exeC:\Users\Behemot\Links\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:54.37Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Links\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:54.37Open1488C:\Monitor\proc.exeC:\Users\Behemot\Music
8/9/2020 - 14:46:54.37Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Music
8/9/2020 - 14:46:54.37Open1488C:\Monitor\proc.exeC:\Users\Behemot\Music
8/9/2020 - 14:46:54.37Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Music
8/9/2020 - 14:46:54.37Open1488C:\Monitor\proc.exeC:\Users\Behemot\Music\2x93mlc4s-readme.txt
8/9/2020 - 14:46:54.73Write1488C:\Monitor\proc.exeC:\Users\Behemot\Music\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:54.73Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Music\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:46:54.73Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:54.74Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:54.75Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\uxtheme.dll
8/9/2020 - 14:46:54.75Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\uxtheme.dll
8/9/2020 - 14:46:54.180Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\bcryptprimitives.dll
8/9/2020 - 14:46:54.180Unknown1488C:\Monitor\proc.exeC:\Windows\SysWOW64\bcryptprimitives.dllbcryptprimitives.dll
8/9/2020 - 14:46:54.181Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\bcryptprimitives.dll
8/9/2020 - 14:46:54.182Unknown1488C:\Monitor\proc.exeC:\Windows\SysWOW64\bcryptprimitives.dllbcryptprimitives.dll
8/9/2020 - 14:46:54.190Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:54.191Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:54.191Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:54.247Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:55.266Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:55.269Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:55.269Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:55.269Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:55.392Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:56.432Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:56.435Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:56.436Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:56.436Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:56.504Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:57.522Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:57.523Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:46:57.523Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:46:57.528Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:57.529Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:57.529Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:57.618Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:57.619Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:46:57.619Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:46:57.680Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:46:58.706Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:46:58.711Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:58.711Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:58.712Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:58.723Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:58.723Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:46:58.723Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:46:58.732Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:46:59.734Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:46:59.744Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:59.745Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:59.745Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:59.786Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:46:59.787Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:46:59.787Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:46:59.830Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:0.833Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:0.833Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:0.833Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:0.837Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:0.837Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:0.837Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:0.889Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:0.889Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:0.889Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:0.934Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:0.934Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:0.934Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:0.975Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:1.996Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:2.0Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:2.0Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:2.0Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:2.41Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:2.41Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:2.41Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:2.82Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:2.82Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:2.83Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:2.123Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:3.148Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:3.152Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:3.152Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:3.152Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:3.195Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:3.196Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:3.196Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:3.236Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:3.237Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:3.237Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:3.278Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:4.311Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:4.311Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:4.312Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:4.315Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:4.315Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:4.315Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:4.356Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:4.356Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:4.357Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:4.397Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:4.397Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:4.398Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:4.438Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:4.438Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:4.439Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:4.514Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:5.518Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:5.521Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:5.522Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:5.522Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:5.570Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:5.571Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:5.572Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:5.614Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:5.615Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:5.615Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:5.657Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:5.690Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:5.690Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:5.731Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:6.760Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:6.767Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:6.767Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:6.767Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:6.818Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:6.818Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:6.818Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:6.954Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:6.954Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:6.955Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:7.0Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:7.0Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:7.0Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:7.42Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:8.75Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:8.76Open1488C:\Monitor\proc.exeC:\Users\Behemot\Pictures
8/9/2020 - 14:47:8.77Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Pictures
8/9/2020 - 14:47:8.77Open1488C:\Monitor\proc.exeC:\Users\Behemot\Pictures
8/9/2020 - 14:47:8.78Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Pictures
8/9/2020 - 14:47:8.78Open1488C:\Monitor\proc.exeC:\Users\Behemot\Pictures\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.79Write1488C:\Monitor\proc.exeC:\Users\Behemot\Pictures\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.80Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Pictures\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.80Open1488C:\Monitor\proc.exeC:\Users\Behemot\Saved Games
8/9/2020 - 14:47:8.81Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Saved Games
8/9/2020 - 14:47:8.81Open1488C:\Monitor\proc.exeC:\Users\Behemot\Saved Games
8/9/2020 - 14:47:8.81Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Saved Games
8/9/2020 - 14:47:8.81Open1488C:\Monitor\proc.exeC:\Users\Behemot\Saved Games\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.82Write1488C:\Monitor\proc.exeC:\Users\Behemot\Saved Games\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.83Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Saved Games\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.83Open1488C:\Monitor\proc.exeC:\Users\Behemot\Searches
8/9/2020 - 14:47:8.83Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Searches
8/9/2020 - 14:47:8.83Open1488C:\Monitor\proc.exeC:\Users\Behemot\Searches
8/9/2020 - 14:47:8.83Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Searches
8/9/2020 - 14:47:8.83Open1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.120Write1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.121Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.121Open1488C:\Monitor\proc.exeC:\Users\Behemot\Videos
8/9/2020 - 14:47:8.122Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Videos
8/9/2020 - 14:47:8.123Open1488C:\Monitor\proc.exeC:\Users\Behemot\Videos
8/9/2020 - 14:47:8.124Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Videos
8/9/2020 - 14:47:8.124Open1488C:\Monitor\proc.exeC:\Users\Behemot\Videos\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.124Write1488C:\Monitor\proc.exeC:\Users\Behemot\Videos\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.125Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Videos\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.125Unknown1488C:\Monitor\proc.exeC:\Users\Behemot
8/9/2020 - 14:47:8.125Open1488C:\Monitor\proc.exeC:\Users\Default
8/9/2020 - 14:47:8.125Open1488C:\Monitor\proc.exeC:\Users\Default\Desktop
8/9/2020 - 14:47:8.125Unknown1488C:\Monitor\proc.exeC:\Users\Default\Desktop
8/9/2020 - 14:47:8.125Open1488C:\Monitor\proc.exeC:\Users\Default\Desktop
8/9/2020 - 14:47:8.126Unknown1488C:\Monitor\proc.exeC:\Users\Default\Desktop
8/9/2020 - 14:47:8.126Open1488C:\Monitor\proc.exeC:\Users\Default\Desktop\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.170Write1488C:\Monitor\proc.exeC:\Users\Default\Desktop\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.171Unknown1488C:\Monitor\proc.exeC:\Users\Default\Desktop\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.171Open1488C:\Monitor\proc.exeC:\Users\Default\Documents
8/9/2020 - 14:47:8.172Unknown1488C:\Monitor\proc.exeC:\Users\Default\Documents
8/9/2020 - 14:47:8.172Open1488C:\Monitor\proc.exeC:\Users\Default\Documents
8/9/2020 - 14:47:8.173Unknown1488C:\Monitor\proc.exeC:\Users\Default\Documents
8/9/2020 - 14:47:8.173Read1488C:\Monitor\proc.exeC:\Users\Default\Documents
8/9/2020 - 14:47:8.173Open1488C:\Monitor\proc.exeC:\Users\Default\Documents\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.208Write1488C:\Monitor\proc.exeC:\Users\Default\Documents\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.208Unknown1488C:\Monitor\proc.exeC:\Users\Default\Documents\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.208Open1488C:\Monitor\proc.exeC:\Users\Default\Downloads
8/9/2020 - 14:47:8.209Unknown1488C:\Monitor\proc.exeC:\Users\Default\Downloads
8/9/2020 - 14:47:8.209Open1488C:\Monitor\proc.exeC:\Users\Default\Downloads
8/9/2020 - 14:47:8.209Unknown1488C:\Monitor\proc.exeC:\Users\Default\Downloads
8/9/2020 - 14:47:8.209Open1488C:\Monitor\proc.exeC:\Users\Default\Downloads\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.210Write1488C:\Monitor\proc.exeC:\Users\Default\Downloads\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.210Unknown1488C:\Monitor\proc.exeC:\Users\Default\Downloads\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.211Open1488C:\Monitor\proc.exeC:\Users\Default\Favorites
8/9/2020 - 14:47:8.246Unknown1488C:\Monitor\proc.exeC:\Users\Default\Favorites
8/9/2020 - 14:47:8.247Open1488C:\Monitor\proc.exeC:\Users\Default\Favorites
8/9/2020 - 14:47:8.247Unknown1488C:\Monitor\proc.exeC:\Users\Default\Favorites
8/9/2020 - 14:47:8.247Open1488C:\Monitor\proc.exeC:\Users\Default\Favorites\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.248Write1488C:\Monitor\proc.exeC:\Users\Default\Favorites\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.248Unknown1488C:\Monitor\proc.exeC:\Users\Default\Favorites\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.248Open1488C:\Monitor\proc.exeC:\Users\Default\Links
8/9/2020 - 14:47:8.249Unknown1488C:\Monitor\proc.exeC:\Users\Default\Links
8/9/2020 - 14:47:8.249Open1488C:\Monitor\proc.exeC:\Users\Default\Links
8/9/2020 - 14:47:8.250Unknown1488C:\Monitor\proc.exeC:\Users\Default\Links
8/9/2020 - 14:47:8.250Open1488C:\Monitor\proc.exeC:\Users\Default\Links\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.285Write1488C:\Monitor\proc.exeC:\Users\Default\Links\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.286Unknown1488C:\Monitor\proc.exeC:\Users\Default\Links\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.286Open1488C:\Monitor\proc.exeC:\Users\Default\Music
8/9/2020 - 14:47:8.287Unknown1488C:\Monitor\proc.exeC:\Users\Default\Music
8/9/2020 - 14:47:8.287Open1488C:\Monitor\proc.exeC:\Users\Default\Music
8/9/2020 - 14:47:8.287Unknown1488C:\Monitor\proc.exeC:\Users\Default\Music
8/9/2020 - 14:47:8.287Open1488C:\Monitor\proc.exeC:\Users\Default\Music\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.288Write1488C:\Monitor\proc.exeC:\Users\Default\Music\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.288Unknown1488C:\Monitor\proc.exeC:\Users\Default\Music\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.289Open1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT.LOG1
8/9/2020 - 14:47:8.289Read1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT.LOG1NTUSER.DAT.LOG1
8/9/2020 - 14:47:8.289Read1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT.LOG1NTUSER.DAT.LOG1
8/9/2020 - 14:47:8.290Open1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT.LOG1
8/9/2020 - 14:47:8.291Open1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:8.291Read1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:8.291Read1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:8.292Open1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:8.294Open1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:8.294Read1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:8.295Read1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:8.295Open1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:8.331Read1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT.LOG1NTUSER.DAT.LOG1
8/9/2020 - 14:47:8.331Read1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT.LOG1NTUSER.DAT.LOG1
8/9/2020 - 14:47:8.333Open1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:8.333Read1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:8.333Read1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:8.333Open1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:8.335Open1488C:\Monitor\proc.exeC:\Users\Default\Pictures
8/9/2020 - 14:47:8.336Unknown1488C:\Monitor\proc.exeC:\Users\Default\Pictures
8/9/2020 - 14:47:8.336Open1488C:\Monitor\proc.exeC:\Users\Default\Pictures
8/9/2020 - 14:47:8.336Unknown1488C:\Monitor\proc.exeC:\Users\Default\Pictures
8/9/2020 - 14:47:8.336Open1488C:\Monitor\proc.exeC:\Users\Default\Pictures\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.337Write1488C:\Monitor\proc.exeC:\Users\Default\Pictures\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.337Unknown1488C:\Monitor\proc.exeC:\Users\Default\Pictures\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.337Open1488C:\Monitor\proc.exeC:\Users\Default\Saved Games
8/9/2020 - 14:47:8.337Unknown1488C:\Monitor\proc.exeC:\Users\Default\Saved Games
8/9/2020 - 14:47:8.337Open1488C:\Monitor\proc.exeC:\Users\Default\Saved Games
8/9/2020 - 14:47:8.338Unknown1488C:\Monitor\proc.exeC:\Users\Default\Saved Games
8/9/2020 - 14:47:8.338Open1488C:\Monitor\proc.exeC:\Users\Default\Saved Games\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.338Write1488C:\Monitor\proc.exeC:\Users\Default\Saved Games\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.338Unknown1488C:\Monitor\proc.exeC:\Users\Default\Saved Games\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.339Open1488C:\Monitor\proc.exeC:\Users\Default\Videos
8/9/2020 - 14:47:8.339Unknown1488C:\Monitor\proc.exeC:\Users\Default\Videos
8/9/2020 - 14:47:8.339Open1488C:\Monitor\proc.exeC:\Users\Default\Videos
8/9/2020 - 14:47:8.339Unknown1488C:\Monitor\proc.exeC:\Users\Default\Videos
8/9/2020 - 14:47:8.339Open1488C:\Monitor\proc.exeC:\Users\Default\Videos\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.341Write1488C:\Monitor\proc.exeC:\Users\Default\Videos\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.341Unknown1488C:\Monitor\proc.exeC:\Users\Default\Videos\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.341Unknown1488C:\Monitor\proc.exeC:\Users\Default
8/9/2020 - 14:47:8.342Open1488C:\Monitor\proc.exeC:\Users\Public
8/9/2020 - 14:47:8.342Open1488C:\Monitor\proc.exeC:\Users\Public\Desktop
8/9/2020 - 14:47:8.342Unknown1488C:\Monitor\proc.exeC:\Users\Public\Desktop
8/9/2020 - 14:47:8.342Open1488C:\Monitor\proc.exeC:\Users\Public\Desktop
8/9/2020 - 14:47:8.343Unknown1488C:\Monitor\proc.exeC:\Users\Public\Desktop
8/9/2020 - 14:47:8.343Open1488C:\Monitor\proc.exeC:\Users\Public\Desktop\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.344Write1488C:\Monitor\proc.exeC:\Users\Public\Desktop\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.345Unknown1488C:\Monitor\proc.exeC:\Users\Public\Desktop\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.345Open1488C:\Monitor\proc.exeC:\Users\Public\Documents
8/9/2020 - 14:47:8.345Unknown1488C:\Monitor\proc.exeC:\Users\Public\Documents
8/9/2020 - 14:47:8.345Open1488C:\Monitor\proc.exeC:\Users\Public\Documents
8/9/2020 - 14:47:8.346Unknown1488C:\Monitor\proc.exeC:\Users\Public\Documents
8/9/2020 - 14:47:8.346Open1488C:\Monitor\proc.exeC:\Users\Public\Documents\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.346Write1488C:\Monitor\proc.exeC:\Users\Public\Documents\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.346Unknown1488C:\Monitor\proc.exeC:\Users\Public\Documents\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.347Open1488C:\Monitor\proc.exeC:\Users\Public\Downloads
8/9/2020 - 14:47:8.347Unknown1488C:\Monitor\proc.exeC:\Users\Public\Downloads
8/9/2020 - 14:47:8.347Open1488C:\Monitor\proc.exeC:\Users\Public\Downloads
8/9/2020 - 14:47:8.348Unknown1488C:\Monitor\proc.exeC:\Users\Public\Downloads
8/9/2020 - 14:47:8.348Open1488C:\Monitor\proc.exeC:\Users\Public\Downloads\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.348Write1488C:\Monitor\proc.exeC:\Users\Public\Downloads\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.348Unknown1488C:\Monitor\proc.exeC:\Users\Public\Downloads\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.348Open1488C:\Monitor\proc.exeC:\Users\Public\Favorites
8/9/2020 - 14:47:8.349Unknown1488C:\Monitor\proc.exeC:\Users\Public\Favorites
8/9/2020 - 14:47:8.349Open1488C:\Monitor\proc.exeC:\Users\Public\Favorites
8/9/2020 - 14:47:8.349Unknown1488C:\Monitor\proc.exeC:\Users\Public\Favorites
8/9/2020 - 14:47:8.349Open1488C:\Monitor\proc.exeC:\Users\Public\Favorites\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.352Write1488C:\Monitor\proc.exeC:\Users\Public\Favorites\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.352Unknown1488C:\Monitor\proc.exeC:\Users\Public\Favorites\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.352Open1488C:\Monitor\proc.exeC:\Users\Public\Libraries
8/9/2020 - 14:47:8.353Unknown1488C:\Monitor\proc.exeC:\Users\Public\Libraries
8/9/2020 - 14:47:8.353Open1488C:\Monitor\proc.exeC:\Users\Public\Libraries
8/9/2020 - 14:47:8.353Unknown1488C:\Monitor\proc.exeC:\Users\Public\Libraries
8/9/2020 - 14:47:8.353Open1488C:\Monitor\proc.exeC:\Users\Public\Libraries\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.353Write1488C:\Monitor\proc.exeC:\Users\Public\Libraries\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.354Unknown1488C:\Monitor\proc.exeC:\Users\Public\Libraries\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.354Open1488C:\Monitor\proc.exeC:\Users\Public\Music
8/9/2020 - 14:47:8.354Unknown1488C:\Monitor\proc.exeC:\Users\Public\Music
8/9/2020 - 14:47:8.354Open1488C:\Monitor\proc.exeC:\Users\Public\Music
8/9/2020 - 14:47:8.354Unknown1488C:\Monitor\proc.exeC:\Users\Public\Music
8/9/2020 - 14:47:8.355Open1488C:\Monitor\proc.exeC:\Users\Public\Music\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.355Write1488C:\Monitor\proc.exeC:\Users\Public\Music\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.355Unknown1488C:\Monitor\proc.exeC:\Users\Public\Music\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.355Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures
8/9/2020 - 14:47:8.356Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures
8/9/2020 - 14:47:8.356Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures
8/9/2020 - 14:47:8.356Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures
8/9/2020 - 14:47:8.356Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.356Write1488C:\Monitor\proc.exeC:\Users\Public\Pictures\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.357Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.357Open1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV
8/9/2020 - 14:47:8.357Unknown1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV
8/9/2020 - 14:47:8.357Open1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV
8/9/2020 - 14:47:8.358Unknown1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV
8/9/2020 - 14:47:8.358Open1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.360Write1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.360Unknown1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.361Open1488C:\Monitor\proc.exeC:\Users\Public\Videos
8/9/2020 - 14:47:8.361Unknown1488C:\Monitor\proc.exeC:\Users\Public\Videos
8/9/2020 - 14:47:8.361Open1488C:\Monitor\proc.exeC:\Users\Public\Videos
8/9/2020 - 14:47:8.361Unknown1488C:\Monitor\proc.exeC:\Users\Public\Videos
8/9/2020 - 14:47:8.361Open1488C:\Monitor\proc.exeC:\Users\Public\Videos\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.362Write1488C:\Monitor\proc.exeC:\Users\Public\Videos\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.362Unknown1488C:\Monitor\proc.exeC:\Users\Public\Videos\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.362Unknown1488C:\Monitor\proc.exeC:\Users\Public
8/9/2020 - 14:47:8.362Open1488C:\Monitor\proc.exeC:\Monitor\Files\DeletedFiles
8/9/2020 - 14:47:8.363Unknown1488C:\Monitor\proc.exeC:\Monitor\Files\DeletedFiles
8/9/2020 - 14:47:8.363Open1488C:\Monitor\proc.exeC:\Monitor\Files\Logs
8/9/2020 - 14:47:8.363Unknown1488C:\Monitor\proc.exeC:\Monitor\Files\Logs
8/9/2020 - 14:47:8.363Open1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts
8/9/2020 - 14:47:8.363Open1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts\Behemot.contact
8/9/2020 - 14:47:8.364Read1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
8/9/2020 - 14:47:8.364Read1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
8/9/2020 - 14:47:8.365Open1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts\Behemot.contact
8/9/2020 - 14:47:8.367Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts
8/9/2020 - 14:47:8.367Open1488C:\Monitor\proc.exeC:\Users\Behemot\Desktop
8/9/2020 - 14:47:8.367Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Desktop
8/9/2020 - 14:47:8.367Open1488C:\Monitor\proc.exeC:\Users\Behemot\Documents
8/9/2020 - 14:47:8.368Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Documents
8/9/2020 - 14:47:8.368Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads
8/9/2020 - 14:47:8.368Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor
8/9/2020 - 14:47:8.368Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor
8/9/2020 - 14:47:8.368Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor
8/9/2020 - 14:47:8.369Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor
8/9/2020 - 14:47:8.369Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.369Write1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.369Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.370Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor.zip
8/9/2020 - 14:47:8.370Read1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor.zip
8/9/2020 - 14:47:8.370Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor.zip
8/9/2020 - 14:47:8.415Read1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:8.415Read1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:8.417Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads
8/9/2020 - 14:47:8.417Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites
8/9/2020 - 14:47:8.417Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links
8/9/2020 - 14:47:8.419Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links
8/9/2020 - 14:47:8.419Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links
8/9/2020 - 14:47:8.420Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links
8/9/2020 - 14:47:8.420Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.459Write1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT.LOG1NTUSER.DAT.LOG1
8/9/2020 - 14:47:8.460Read1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:8.460Read1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:8.461Write1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.462Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.462Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil
8/9/2020 - 14:47:8.463Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil
8/9/2020 - 14:47:8.463Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil
8/9/2020 - 14:47:8.463Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil
8/9/2020 - 14:47:8.463Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.464Write1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.465Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.465Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites
8/9/2020 - 14:47:8.465Open1488C:\Monitor\proc.exeC:\Users\Behemot\Links
8/9/2020 - 14:47:8.465Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Links
8/9/2020 - 14:47:8.466Open1488C:\Monitor\proc.exeC:\Users\Behemot\Music
8/9/2020 - 14:47:8.466Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Music
8/9/2020 - 14:47:8.466Open1488C:\Monitor\proc.exeC:\Users\Behemot\Pictures
8/9/2020 - 14:47:8.466Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Pictures
8/9/2020 - 14:47:8.466Open1488C:\Monitor\proc.exeC:\Users\Behemot\Saved Games
8/9/2020 - 14:47:8.466Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Saved Games
8/9/2020 - 14:47:8.467Open1488C:\Monitor\proc.exeC:\Users\Behemot\Searches
8/9/2020 - 14:47:8.467Open1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Everywhere.search-ms
8/9/2020 - 14:47:8.467Read1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
8/9/2020 - 14:47:8.467Read1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
8/9/2020 - 14:47:8.467Open1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Everywhere.search-ms
8/9/2020 - 14:47:8.468Open1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Everywhere.search-ms
8/9/2020 - 14:47:8.468Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
8/9/2020 - 14:47:8.468Open1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Everywhere.search-ms
8/9/2020 - 14:47:8.469Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
8/9/2020 - 14:47:8.469Open1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Everywhere.search-ms
8/9/2020 - 14:47:8.469Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
8/9/2020 - 14:47:8.469Open1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Everywhere.search-ms
8/9/2020 - 14:47:8.469Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
8/9/2020 - 14:47:8.470Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
8/9/2020 - 14:47:8.470Open1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Everywhere.search-ms
8/9/2020 - 14:47:8.472Open1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Indexed Locations.search-ms
8/9/2020 - 14:47:8.472Read1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
8/9/2020 - 14:47:8.472Open1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Indexed Locations.search-ms
8/9/2020 - 14:47:8.472Open1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Indexed Locations.search-ms
8/9/2020 - 14:47:8.473Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
8/9/2020 - 14:47:8.473Open1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Indexed Locations.search-ms
8/9/2020 - 14:47:8.473Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
8/9/2020 - 14:47:8.473Open1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Indexed Locations.search-ms
8/9/2020 - 14:47:8.474Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
8/9/2020 - 14:47:8.474Open1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Indexed Locations.search-ms
8/9/2020 - 14:47:8.474Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
8/9/2020 - 14:47:8.474Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
8/9/2020 - 14:47:8.474Open1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Indexed Locations.search-ms
8/9/2020 - 14:47:8.476Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Searches
8/9/2020 - 14:47:8.476Open1488C:\Monitor\proc.exeC:\Users\Behemot\Videos
8/9/2020 - 14:47:8.477Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Videos
8/9/2020 - 14:47:8.477Open1488C:\Monitor\proc.exeC:\Users\Default\Desktop
8/9/2020 - 14:47:8.477Unknown1488C:\Monitor\proc.exeC:\Users\Default\Desktop
8/9/2020 - 14:47:8.477Open1488C:\Monitor\proc.exeC:\Users\Default\Documents
8/9/2020 - 14:47:8.478Unknown1488C:\Monitor\proc.exeC:\Users\Default\Documents
8/9/2020 - 14:47:8.478Open1488C:\Monitor\proc.exeC:\Users\Default\Downloads
8/9/2020 - 14:47:8.478Unknown1488C:\Monitor\proc.exeC:\Users\Default\Downloads
8/9/2020 - 14:47:8.478Open1488C:\Monitor\proc.exeC:\Users\Default\Favorites
8/9/2020 - 14:47:8.478Unknown1488C:\Monitor\proc.exeC:\Users\Default\Favorites
8/9/2020 - 14:47:8.478Open1488C:\Monitor\proc.exeC:\Users\Default\Links
8/9/2020 - 14:47:8.479Unknown1488C:\Monitor\proc.exeC:\Users\Default\Links
8/9/2020 - 14:47:8.479Open1488C:\Monitor\proc.exeC:\Users\Default\Music
8/9/2020 - 14:47:8.479Unknown1488C:\Monitor\proc.exeC:\Users\Default\Music
8/9/2020 - 14:47:8.479Open1488C:\Monitor\proc.exeC:\Users\Default\Pictures
8/9/2020 - 14:47:8.479Unknown1488C:\Monitor\proc.exeC:\Users\Default\Pictures
8/9/2020 - 14:47:8.479Open1488C:\Monitor\proc.exeC:\Users\Default\Saved Games
8/9/2020 - 14:47:8.480Unknown1488C:\Monitor\proc.exeC:\Users\Default\Saved Games
8/9/2020 - 14:47:8.480Open1488C:\Monitor\proc.exeC:\Users\Default\Videos
8/9/2020 - 14:47:8.480Unknown1488C:\Monitor\proc.exeC:\Users\Default\Videos
8/9/2020 - 14:47:8.480Open1488C:\Monitor\proc.exeC:\Users\Public\Desktop
8/9/2020 - 14:47:8.480Unknown1488C:\Monitor\proc.exeC:\Users\Public\Desktop
8/9/2020 - 14:47:8.480Open1488C:\Monitor\proc.exeC:\Users\Public\Documents
8/9/2020 - 14:47:8.481Unknown1488C:\Monitor\proc.exeC:\Users\Public\Documents
8/9/2020 - 14:47:8.481Open1488C:\Monitor\proc.exeC:\Users\Public\Downloads
8/9/2020 - 14:47:8.481Unknown1488C:\Monitor\proc.exeC:\Users\Public\Downloads
8/9/2020 - 14:47:8.481Open1488C:\Monitor\proc.exeC:\Users\Public\Favorites
8/9/2020 - 14:47:8.481Unknown1488C:\Monitor\proc.exeC:\Users\Public\Favorites
8/9/2020 - 14:47:8.481Open1488C:\Monitor\proc.exeC:\Users\Public\Libraries
8/9/2020 - 14:47:8.482Open1488C:\Monitor\proc.exeC:\Users\Public\Libraries\RecordedTV.library-ms
8/9/2020 - 14:47:8.482Read1488C:\Monitor\proc.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
8/9/2020 - 14:47:8.482Read1488C:\Monitor\proc.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
8/9/2020 - 14:47:8.483Open1488C:\Monitor\proc.exeC:\Users\Public\Libraries\RecordedTV.library-ms
8/9/2020 - 14:47:8.485Unknown1488C:\Monitor\proc.exeC:\Users\Public\Libraries
8/9/2020 - 14:47:8.485Open1488C:\Monitor\proc.exeC:\Users\Public\Music
8/9/2020 - 14:47:8.485Open1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music
8/9/2020 - 14:47:8.485Unknown1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music
8/9/2020 - 14:47:8.486Open1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music
8/9/2020 - 14:47:8.486Unknown1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music
8/9/2020 - 14:47:8.486Open1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.486Write1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.487Unknown1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.487Unknown1488C:\Monitor\proc.exeC:\Users\Public\Music
8/9/2020 - 14:47:8.487Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures
8/9/2020 - 14:47:8.487Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures
8/9/2020 - 14:47:8.487Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures
8/9/2020 - 14:47:8.488Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures
8/9/2020 - 14:47:8.488Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures
8/9/2020 - 14:47:8.488Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.488Write1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.489Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.489Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures
8/9/2020 - 14:47:8.489Open1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV
8/9/2020 - 14:47:8.489Open1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\Sample Media
8/9/2020 - 14:47:8.491Unknown1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\Sample Media
8/9/2020 - 14:47:8.491Open1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\Sample Media
8/9/2020 - 14:47:8.491Unknown1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\Sample Media
8/9/2020 - 14:47:8.491Open1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\Sample Media\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.492Write1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\Sample Media\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.492Unknown1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\Sample Media\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.492Unknown1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV
8/9/2020 - 14:47:8.492Open1488C:\Monitor\proc.exeC:\Users\Public\Videos
8/9/2020 - 14:47:8.493Open1488C:\Monitor\proc.exeC:\Users\Public\Videos\Sample Videos
8/9/2020 - 14:47:8.493Unknown1488C:\Monitor\proc.exeC:\Users\Public\Videos\Sample Videos
8/9/2020 - 14:47:8.493Open1488C:\Monitor\proc.exeC:\Users\Public\Videos\Sample Videos
8/9/2020 - 14:47:8.493Unknown1488C:\Monitor\proc.exeC:\Users\Public\Videos\Sample Videos
8/9/2020 - 14:47:8.536Read1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:8.536Read1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:8.493Open1488C:\Monitor\proc.exeC:\Users\Public\Videos\Sample Videos\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.538Write1488C:\Monitor\proc.exeC:\Users\Public\Videos\Sample Videos\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.539Unknown1488C:\Monitor\proc.exeC:\Users\Public\Videos\Sample Videos\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.539Unknown1488C:\Monitor\proc.exeC:\Users\Public\Videos
8/9/2020 - 14:47:8.539Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor
8/9/2020 - 14:47:8.539Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor
8/9/2020 - 14:47:8.540Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor
8/9/2020 - 14:47:8.540Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor
8/9/2020 - 14:47:8.540Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor
8/9/2020 - 14:47:8.540Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.541Write1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.541Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.541Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor
8/9/2020 - 14:47:8.541Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links
8/9/2020 - 14:47:8.541Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.url
8/9/2020 - 14:47:8.541Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
8/9/2020 - 14:47:8.541Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.url
8/9/2020 - 14:47:8.543Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.url
8/9/2020 - 14:47:8.544Read1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
8/9/2020 - 14:47:8.544Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.url
8/9/2020 - 14:47:8.546Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links
8/9/2020 - 14:47:8.546Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil
8/9/2020 - 14:47:8.546Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.url
8/9/2020 - 14:47:8.546Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
8/9/2020 - 14:47:8.546Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.url
8/9/2020 - 14:47:8.549Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.url
8/9/2020 - 14:47:8.549Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
8/9/2020 - 14:47:8.549Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.url
8/9/2020 - 14:47:8.551Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.url
8/9/2020 - 14:47:8.552Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
8/9/2020 - 14:47:8.552Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.url
8/9/2020 - 14:47:8.554Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil
8/9/2020 - 14:47:8.554Open1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music
8/9/2020 - 14:47:8.554Open1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
8/9/2020 - 14:47:8.554Read1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
8/9/2020 - 14:47:8.555Read1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
8/9/2020 - 14:47:8.555Open1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
8/9/2020 - 14:47:8.557Open1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
8/9/2020 - 14:47:8.558Read1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
8/9/2020 - 14:47:8.558Read1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
8/9/2020 - 14:47:8.558Open1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
8/9/2020 - 14:47:8.560Open1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3
8/9/2020 - 14:47:8.560Read1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
8/9/2020 - 14:47:8.561Read1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
8/9/2020 - 14:47:8.561Open1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3
8/9/2020 - 14:47:8.563Unknown1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music
8/9/2020 - 14:47:8.563Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures
8/9/2020 - 14:47:8.563Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
8/9/2020 - 14:47:8.563Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
8/9/2020 - 14:47:8.564Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
8/9/2020 - 14:47:8.564Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
8/9/2020 - 14:47:8.566Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
8/9/2020 - 14:47:8.567Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
8/9/2020 - 14:47:8.567Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
8/9/2020 - 14:47:8.568Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
8/9/2020 - 14:47:8.570Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
8/9/2020 - 14:47:8.571Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
8/9/2020 - 14:47:8.571Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
8/9/2020 - 14:47:8.571Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
8/9/2020 - 14:47:8.611Read1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
8/9/2020 - 14:47:8.611Read1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
8/9/2020 - 14:47:8.573Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
8/9/2020 - 14:47:8.612Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
8/9/2020 - 14:47:8.612Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
8/9/2020 - 14:47:8.613Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
8/9/2020 - 14:47:8.615Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
8/9/2020 - 14:47:8.615Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
8/9/2020 - 14:47:8.615Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
8/9/2020 - 14:47:8.615Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
8/9/2020 - 14:47:8.617Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
8/9/2020 - 14:47:8.618Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
8/9/2020 - 14:47:8.618Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
8/9/2020 - 14:47:8.619Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
8/9/2020 - 14:47:8.621Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
8/9/2020 - 14:47:8.621Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
8/9/2020 - 14:47:8.621Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
8/9/2020 - 14:47:8.622Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
8/9/2020 - 14:47:8.623Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
8/9/2020 - 14:47:8.624Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
8/9/2020 - 14:47:8.624Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
8/9/2020 - 14:47:8.625Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
8/9/2020 - 14:47:8.626Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures
8/9/2020 - 14:47:8.626Open1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\Sample Media
8/9/2020 - 14:47:8.626Open1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv
8/9/2020 - 14:47:8.627Read1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
8/9/2020 - 14:47:8.627Read1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
8/9/2020 - 14:47:8.663Open1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv
8/9/2020 - 14:47:8.665Unknown1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\Sample Media
8/9/2020 - 14:47:8.665Open1488C:\Monitor\proc.exeC:\Users\Public\Videos\Sample Videos
8/9/2020 - 14:47:8.665Open1488C:\Monitor\proc.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
8/9/2020 - 14:47:8.666Read1488C:\Monitor\proc.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
8/9/2020 - 14:47:8.666Read1488C:\Monitor\proc.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
8/9/2020 - 14:47:8.666Open1488C:\Monitor\proc.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
8/9/2020 - 14:47:8.668Unknown1488C:\Monitor\proc.exeC:\Users\Public\Videos\Sample Videos
8/9/2020 - 14:47:8.668Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor
8/9/2020 - 14:47:8.668Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files
8/9/2020 - 14:47:8.669Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files
8/9/2020 - 14:47:8.669Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files
8/9/2020 - 14:47:8.669Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files
8/9/2020 - 14:47:8.669Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.670Write1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.670Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.670Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Malware
8/9/2020 - 14:47:8.670Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Malware
8/9/2020 - 14:47:8.670Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Malware
8/9/2020 - 14:47:8.671Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Malware
8/9/2020 - 14:47:8.671Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Malware\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.671Write1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Malware\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.672Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Malware\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.672Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
8/9/2020 - 14:47:8.672Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
8/9/2020 - 14:47:8.672Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
8/9/2020 - 14:47:8.672Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
8/9/2020 - 14:47:8.673Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
8/9/2020 - 14:47:8.672Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.673Write1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.673Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.673Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor
8/9/2020 - 14:47:8.673Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files
8/9/2020 - 14:47:8.674Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\DeletedFiles
8/9/2020 - 14:47:8.674Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\DeletedFiles
8/9/2020 - 14:47:8.674Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\DeletedFiles
8/9/2020 - 14:47:8.674Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\DeletedFiles
8/9/2020 - 14:47:8.674Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\DeletedFiles\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.675Write1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\DeletedFiles\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.675Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\DeletedFiles\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.675Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\Logs
8/9/2020 - 14:47:8.675Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\Logs
8/9/2020 - 14:47:8.676Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\Logs
8/9/2020 - 14:47:8.676Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\Logs
8/9/2020 - 14:47:8.676Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\Logs\2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.676Write1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\Logs\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.676Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\Logs\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:8.676Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files
8/9/2020 - 14:47:8.677Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Malware
8/9/2020 - 14:47:8.677Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Malware
8/9/2020 - 14:47:8.677Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
8/9/2020 - 14:47:8.677Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.cat
8/9/2020 - 14:47:8.677Read1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
8/9/2020 - 14:47:8.678Read1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
8/9/2020 - 14:47:8.679Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.cat
8/9/2020 - 14:47:8.681Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.inf
8/9/2020 - 14:47:8.682Write1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:8.682Read1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor.zip
8/9/2020 - 14:47:8.682Read1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor.zip
8/9/2020 - 14:47:8.723Read1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
8/9/2020 - 14:47:8.723Read1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
8/9/2020 - 14:47:8.724Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.inf
8/9/2020 - 14:47:8.726Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
8/9/2020 - 14:47:8.726Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\DeletedFiles
8/9/2020 - 14:47:8.726Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\DeletedFiles
8/9/2020 - 14:47:8.726Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\Logs
8/9/2020 - 14:47:8.726Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\Files\Logs
8/9/2020 - 14:47:8.723Write1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT.LOG1NTUSER.DAT.LOG1
8/9/2020 - 14:47:8.732Write1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:8.732Read1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
8/9/2020 - 14:47:8.732Read1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
8/9/2020 - 14:47:8.732Read1488C:\Monitor\proc.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
8/9/2020 - 14:47:8.735Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\drprov.dll
8/9/2020 - 14:47:8.736Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\drprov.dll
8/9/2020 - 14:47:8.740Write1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:8.740Read1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
8/9/2020 - 14:47:8.741Read1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
8/9/2020 - 14:47:8.741Read1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
8/9/2020 - 14:47:8.741Read1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
8/9/2020 - 14:47:8.741Read1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
8/9/2020 - 14:47:8.741Read1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
8/9/2020 - 14:47:8.741Read1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
8/9/2020 - 14:47:8.741Read1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
8/9/2020 - 14:47:8.741Read1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
8/9/2020 - 14:47:8.742Read1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
8/9/2020 - 14:47:8.743Read1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
8/9/2020 - 14:47:8.796Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\winsta.dll
8/9/2020 - 14:47:8.796Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\winsta.dll
8/9/2020 - 14:47:8.798Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\ntlanman.dll
8/9/2020 - 14:47:8.804Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\ntlanman.dll
8/9/2020 - 14:47:8.841Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\davclnt.dll
8/9/2020 - 14:47:8.843Read1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
8/9/2020 - 14:47:8.843Read1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
8/9/2020 - 14:47:8.848Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\davclnt.dll
8/9/2020 - 14:47:8.917Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\davhlpr.dll
8/9/2020 - 14:47:8.919Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\davhlpr.dll
8/9/2020 - 14:47:8.925Read1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
8/9/2020 - 14:47:8.927Read1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
8/9/2020 - 14:47:8.993Open1488C:\Monitor\proc.exeC:\Monitor\wkscli.dll
8/9/2020 - 14:47:8.994Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\wkscli.dll
8/9/2020 - 14:47:8.994Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\wkscli.dll
8/9/2020 - 14:47:8.996Open1488C:\Monitor\proc.exeC:\Monitor\cscapi.dll
8/9/2020 - 14:47:8.996Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\cscapi.dll
8/9/2020 - 14:47:8.997Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\cscapi.dll
8/9/2020 - 14:47:8.998Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
8/9/2020 - 14:47:8.999Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
8/9/2020 - 14:47:9.36Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
8/9/2020 - 14:47:9.36Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
8/9/2020 - 14:47:9.37Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
8/9/2020 - 14:47:9.38Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
8/9/2020 - 14:47:9.76Write1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
8/9/2020 - 14:47:9.77Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
8/9/2020 - 14:47:9.79Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
8/9/2020 - 14:47:9.82Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
8/9/2020 - 14:47:9.83Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
8/9/2020 - 14:47:9.86Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
8/9/2020 - 14:47:9.88Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
8/9/2020 - 14:47:9.91Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
8/9/2020 - 14:47:9.92Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
8/9/2020 - 14:47:9.94Open1488C:\Monitor\proc.exeC:\Monitor\netutils.dll
8/9/2020 - 14:47:9.95Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\netutils.dll
8/9/2020 - 14:47:9.95Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\netutils.dll
8/9/2020 - 14:47:9.98Open1488C:\Monitor\proc.exeC:\Monitor\browcli.dll
8/9/2020 - 14:47:9.98Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\browcli.dll
8/9/2020 - 14:47:9.100Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
8/9/2020 - 14:47:9.100Read1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
8/9/2020 - 14:47:9.102Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\browcli.dll
8/9/2020 - 14:47:9.104Read1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
8/9/2020 - 14:47:9.105Read1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
8/9/2020 - 14:47:9.106Read1488C:\Monitor\proc.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
8/9/2020 - 14:47:9.107Read1488C:\Monitor\proc.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
8/9/2020 - 14:47:9.162Read1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
8/9/2020 - 14:47:9.162Write1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:9.165Write1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor.zip
8/9/2020 - 14:47:9.166Read1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
8/9/2020 - 14:47:9.166Unknown1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT.LOG1NTUSER.DAT.LOG1
8/9/2020 - 14:47:9.166Open1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT.LOG1
8/9/2020 - 14:47:9.166Open1488C:\Monitor\proc.exeC:\Users\Default
8/9/2020 - 14:47:9.166Unknown1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT.LOG1NTUSER.DAT.LOG1
8/9/2020 - 14:47:9.166Unknown1488C:\Monitor\proc.exeC:\Users\Default
8/9/2020 - 14:47:9.167Write1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:9.167Write1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
8/9/2020 - 14:47:9.167Write1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
8/9/2020 - 14:47:9.167Write1488C:\Monitor\proc.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
8/9/2020 - 14:47:9.167Write1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:9.168Write1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
8/9/2020 - 14:47:9.168Write1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
8/9/2020 - 14:47:9.168Write1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
8/9/2020 - 14:47:9.168Write1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
8/9/2020 - 14:47:9.168Write1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
8/9/2020 - 14:47:9.179Write1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
8/9/2020 - 14:47:9.190Write1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
8/9/2020 - 14:47:9.241Write1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
8/9/2020 - 14:47:9.249Write1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
8/9/2020 - 14:47:9.256Write1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
8/9/2020 - 14:47:9.262Write1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
8/9/2020 - 14:47:9.262Write1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
8/9/2020 - 14:47:9.304Write1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
8/9/2020 - 14:47:9.311Write1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
8/9/2020 - 14:47:9.317Write1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
8/9/2020 - 14:47:9.324Write1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
8/9/2020 - 14:47:9.330Write1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
8/9/2020 - 14:47:9.430Write1488C:\Monitor\proc.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
8/9/2020 - 14:47:9.442Write1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
8/9/2020 - 14:47:9.444Write1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
8/9/2020 - 14:47:9.445Unknown1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:9.445Open1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:9.445Open1488C:\Monitor\proc.exeC:\Users\Default
8/9/2020 - 14:47:9.445Unknown1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:9.446Unknown1488C:\Monitor\proc.exeC:\Users\Default
8/9/2020 - 14:47:9.446Write1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor.zip
8/9/2020 - 14:47:9.446Write1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
8/9/2020 - 14:47:9.447Unknown1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:9.447Open1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:9.447Open1488C:\Monitor\proc.exeC:\Users\Default
8/9/2020 - 14:47:9.447Unknown1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:9.448Unknown1488C:\Monitor\proc.exeC:\Users\Default
8/9/2020 - 14:47:9.449Write1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
8/9/2020 - 14:47:9.449Write1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
8/9/2020 - 14:47:9.449Write1488C:\Monitor\proc.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
8/9/2020 - 14:47:9.450Unknown1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:9.450Open1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:9.450Open1488C:\Monitor\proc.exeC:\Users\Default
8/9/2020 - 14:47:9.450Unknown1488C:\Monitor\proc.exeC:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:9.450Unknown1488C:\Monitor\proc.exeC:\Users\Default
8/9/2020 - 14:47:9.451Write1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
8/9/2020 - 14:47:9.451Write1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
8/9/2020 - 14:47:9.452Write1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
8/9/2020 - 14:47:9.452Write1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
8/9/2020 - 14:47:9.452Write1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
8/9/2020 - 14:47:9.452Write1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
8/9/2020 - 14:47:9.452Write1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
8/9/2020 - 14:47:9.452Write1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
8/9/2020 - 14:47:9.453Write1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
8/9/2020 - 14:47:9.454Write1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
8/9/2020 - 14:47:9.454Write1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
8/9/2020 - 14:47:9.454Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
8/9/2020 - 14:47:9.454Open1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts\Behemot.contact
8/9/2020 - 14:47:9.455Open1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts
8/9/2020 - 14:47:9.455Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts\Behemot.contactBehemot.contact
8/9/2020 - 14:47:9.455Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts
8/9/2020 - 14:47:9.456Write1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
8/9/2020 - 14:47:9.456Write1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
8/9/2020 - 14:47:9.456Write1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
8/9/2020 - 14:47:9.456Write1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
8/9/2020 - 14:47:9.456Write1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
8/9/2020 - 14:47:9.456Write1488C:\Monitor\proc.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
8/9/2020 - 14:47:9.457Write1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
8/9/2020 - 14:47:9.457Write1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
8/9/2020 - 14:47:9.457Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor.zip
8/9/2020 - 14:47:9.457Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor.zip
8/9/2020 - 14:47:9.458Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads
8/9/2020 - 14:47:9.458Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor.zip
8/9/2020 - 14:47:9.458Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads
8/9/2020 - 14:47:9.458Write1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
8/9/2020 - 14:47:9.458Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
8/9/2020 - 14:47:9.458Open1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Everywhere.search-ms
8/9/2020 - 14:47:9.459Open1488C:\Monitor\proc.exeC:\Users\Behemot\Searches
8/9/2020 - 14:47:9.459Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Everywhere.search-msEverywhere.search-ms
8/9/2020 - 14:47:9.459Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Searches
8/9/2020 - 14:47:9.460Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
8/9/2020 - 14:47:9.460Open1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Indexed Locations.search-ms
8/9/2020 - 14:47:9.460Open1488C:\Monitor\proc.exeC:\Users\Behemot\Searches
8/9/2020 - 14:47:9.460Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\Indexed Locations.search-msIndexed Locations.search-ms
8/9/2020 - 14:47:9.460Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Searches
8/9/2020 - 14:47:9.461Unknown1488C:\Monitor\proc.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
8/9/2020 - 14:47:9.461Open1488C:\Monitor\proc.exeC:\Users\Public\Libraries\RecordedTV.library-ms
8/9/2020 - 14:47:9.461Open1488C:\Monitor\proc.exeC:\Users\Public\Libraries
8/9/2020 - 14:47:9.462Unknown1488C:\Monitor\proc.exeC:\Users\Public\Libraries\RecordedTV.library-msRecordedTV.library-ms
8/9/2020 - 14:47:9.462Unknown1488C:\Monitor\proc.exeC:\Users\Public\Libraries
8/9/2020 - 14:47:9.463Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.url
8/9/2020 - 14:47:9.463Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links
8/9/2020 - 14:47:9.463Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\Galeria do Web Slice.urlGaleria do Web Slice.url
8/9/2020 - 14:47:9.463Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links
8/9/2020 - 14:47:9.464Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
8/9/2020 - 14:47:9.465Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
8/9/2020 - 14:47:9.465Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.url
8/9/2020 - 14:47:9.465Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links
8/9/2020 - 14:47:9.465Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\Sites Sugeridos.urlSites Sugeridos.url
8/9/2020 - 14:47:9.465Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links
8/9/2020 - 14:47:9.466Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.url
8/9/2020 - 14:47:9.466Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil
8/9/2020 - 14:47:9.466Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\Microsoft Brasil.urlMicrosoft Brasil.url
8/9/2020 - 14:47:9.467Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil
8/9/2020 - 14:47:9.467Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.url
8/9/2020 - 14:47:9.510Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil
8/9/2020 - 14:47:9.510Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\MSN Brasil.urlMSN Brasil.url
8/9/2020 - 14:47:9.513Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil
8/9/2020 - 14:47:9.514Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.url
8/9/2020 - 14:47:9.515Open1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil
8/9/2020 - 14:47:9.515Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil\Windows Brasil.urlWindows Brasil.url
8/9/2020 - 14:47:9.515Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links for Brasil
8/9/2020 - 14:47:9.516Unknown1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
8/9/2020 - 14:47:9.516Open1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
8/9/2020 - 14:47:9.516Open1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music
8/9/2020 - 14:47:9.516Unknown1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Kalimba.mp3
8/9/2020 - 14:47:9.517Unknown1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music
8/9/2020 - 14:47:9.518Unknown1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
8/9/2020 - 14:47:9.518Open1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
8/9/2020 - 14:47:9.518Open1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music
8/9/2020 - 14:47:9.519Unknown1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3Maid with the Flaxen Hair.mp3
8/9/2020 - 14:47:9.519Unknown1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music
8/9/2020 - 14:47:9.520Unknown1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
8/9/2020 - 14:47:9.520Open1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3
8/9/2020 - 14:47:9.520Open1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music
8/9/2020 - 14:47:9.520Unknown1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music\Sleep Away.mp3Sleep Away.mp3
8/9/2020 - 14:47:9.521Unknown1488C:\Monitor\proc.exeC:\Users\Public\Music\Sample Music
8/9/2020 - 14:47:9.521Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
8/9/2020 - 14:47:9.522Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
8/9/2020 - 14:47:9.522Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures
8/9/2020 - 14:47:9.522Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpgChrysanthemum.jpg
8/9/2020 - 14:47:9.522Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures
8/9/2020 - 14:47:9.523Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
8/9/2020 - 14:47:9.523Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
8/9/2020 - 14:47:9.523Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures
8/9/2020 - 14:47:9.524Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Desert.jpg
8/9/2020 - 14:47:9.525Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures
8/9/2020 - 14:47:9.526Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
8/9/2020 - 14:47:9.526Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
8/9/2020 - 14:47:9.526Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures
8/9/2020 - 14:47:9.527Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpgHydrangeas.jpg
8/9/2020 - 14:47:9.527Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures
8/9/2020 - 14:47:9.528Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
8/9/2020 - 14:47:9.528Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
8/9/2020 - 14:47:9.529Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures
8/9/2020 - 14:47:9.529Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpgJellyfish.jpg
8/9/2020 - 14:47:9.529Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures
8/9/2020 - 14:47:9.530Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
8/9/2020 - 14:47:9.530Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
8/9/2020 - 14:47:9.530Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures
8/9/2020 - 14:47:9.531Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Koala.jpg
8/9/2020 - 14:47:9.531Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures
8/9/2020 - 14:47:9.532Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
8/9/2020 - 14:47:9.532Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
8/9/2020 - 14:47:9.533Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures
8/9/2020 - 14:47:9.533Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpgLighthouse.jpg
8/9/2020 - 14:47:9.534Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures
8/9/2020 - 14:47:9.534Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
8/9/2020 - 14:47:9.534Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
8/9/2020 - 14:47:9.535Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures
8/9/2020 - 14:47:9.535Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Penguins.jpg
8/9/2020 - 14:47:9.535Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures
8/9/2020 - 14:47:9.536Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
8/9/2020 - 14:47:9.536Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
8/9/2020 - 14:47:9.537Open1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures
8/9/2020 - 14:47:9.537Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures\Tulips.jpg
8/9/2020 - 14:47:9.537Unknown1488C:\Monitor\proc.exeC:\Users\Public\Pictures\Sample Pictures
8/9/2020 - 14:47:9.538Unknown1488C:\Monitor\proc.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
8/9/2020 - 14:47:9.538Open1488C:\Monitor\proc.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
8/9/2020 - 14:47:9.540Open1488C:\Monitor\proc.exeC:\Users\Public\Videos\Sample Videos
8/9/2020 - 14:47:9.540Unknown1488C:\Monitor\proc.exeC:\Users\Public\Videos\Sample Videos\Wildlife.wmv
8/9/2020 - 14:47:9.541Unknown1488C:\Monitor\proc.exeC:\Users\Public\Videos\Sample Videos
8/9/2020 - 14:47:9.541Unknown1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
8/9/2020 - 14:47:9.541Open1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv
8/9/2020 - 14:47:9.541Open1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\Sample Media
8/9/2020 - 14:47:9.541Unknown1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtvwin7_scenic-demoshort_raw.wtv
8/9/2020 - 14:47:9.542Unknown1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\Sample Media
8/9/2020 - 14:47:9.543Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
8/9/2020 - 14:47:9.543Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.cat
8/9/2020 - 14:47:9.543Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
8/9/2020 - 14:47:9.543Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\windowskernelcapturedriver.catwindowskernelcapturedriver.cat
8/9/2020 - 14:47:9.544Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
8/9/2020 - 14:47:9.544Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
8/9/2020 - 14:47:9.544Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.inf
8/9/2020 - 14:47:9.545Open1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
8/9/2020 - 14:47:9.545Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package\WindowsKernelCaptureDriver.infWindowsKernelCaptureDriver.inf
8/9/2020 - 14:47:9.545Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\Monitor\WindowsKernelCaptureDriver Package
8/9/2020 - 14:47:11.542Open1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.543Unknown1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.543Unknown1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.542Open1488C:\Monitor\proc.exe\Device\Mup\.\.\
8/9/2020 - 14:47:11.544Open1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.544Unknown1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.544Unknown1488C:\Monitor\proc.exe\Device\Mup\.\.\
8/9/2020 - 14:47:11.544Unknown1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.545Open1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.545Unknown1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.545Unknown1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.545Open1488C:\Monitor\proc.exe\Device\Mup\.\.\
8/9/2020 - 14:47:11.546Open1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.546Unknown1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.546Unknown1488C:\Monitor\proc.exe\Device\Mup\.\.\
8/9/2020 - 14:47:11.546Unknown1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.547Open1488C:\Monitor\proc.exeC:\Monitor\srvcli.dll
8/9/2020 - 14:47:11.547Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\srvcli.dll
8/9/2020 - 14:47:11.547Open1488C:\Monitor\proc.exeC:\Windows\SysWOW64\srvcli.dll
8/9/2020 - 14:47:11.550Open1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.550Unknown1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.550Unknown1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.550Open1488C:\Monitor\proc.exe\Device\Mup\.\.\
8/9/2020 - 14:47:11.551Open1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.551Unknown1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.551Unknown1488C:\Monitor\proc.exe\Device\Mup\.\.\
8/9/2020 - 14:47:11.551Unknown1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.552Open1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.552Unknown1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.552Open1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.553Unknown1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.553Unknown1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.553Unknown1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace
8/9/2020 - 14:47:11.552Open1488C:\Monitor\proc.exe\Device\Mup\;Csc\.\.\W7VM1
8/9/2020 - 14:47:11.553Open1488C:\Monitor\proc.exeC:\Windows\CSC\v2.0.6\namespace\W7VM1
8/9/2020 - 14:47:11.554Open1488C:\Monitor\proc.exe\Device\Mup\W7VM1\Users\
8/9/2020 - 14:47:13.616Unknown1488C:\Monitor\proc.exe\Device\Mup\W7VM1\Users\
8/9/2020 - 14:47:13.682Open1488C:\Monitor\proc.exe\Device\Mup\W7VM1\Users\
8/9/2020 - 14:47:14.166Unknown1488C:\Monitor\proc.exe\Device\Mup\W7VM1\Users\
8/9/2020 - 14:47:14.233Open1488C:\Monitor\proc.exe\Device\Mup\W7VM1\Users\2x93mlc4s-readme.txt
8/9/2020 - 14:47:14.763Write1488C:\Monitor\proc.exe\Device\Mup\W7VM1\Users\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:14.763Write1488C:\Monitor\proc.exeC:\Users\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:14.763Unknown1488C:\Monitor\proc.exe\Device\Mup\W7VM1\Users\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:14.839Open1488C:\Monitor\proc.exe\Device\Mup\W7VM1\Users\
8/9/2020 - 14:47:15.412Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot
8/9/2020 - 14:47:15.906Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot
8/9/2020 - 14:47:15.973Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot
8/9/2020 - 14:47:16.522Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot
8/9/2020 - 14:47:16.588Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\2x93mlc4s-readme.txt
8/9/2020 - 14:47:17.378Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:17.378Write1488C:\Monitor\proc.exeC:\Users\Behemot\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:17.379Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:17.449Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default
8/9/2020 - 14:47:18.42Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default
8/9/2020 - 14:47:18.111Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default
8/9/2020 - 14:47:18.582Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default
8/9/2020 - 14:47:18.649Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\2x93mlc4s-readme.txt
8/9/2020 - 14:47:19.546Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:19.546Write1488C:\Monitor\proc.exeC:\Users\Default\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:19.546Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:19.613Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public
8/9/2020 - 14:47:20.147Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public
8/9/2020 - 14:47:20.213Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public
8/9/2020 - 14:47:20.687Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public
8/9/2020 - 14:47:20.753Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\2x93mlc4s-readme.txt
8/9/2020 - 14:47:21.632Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:21.632Write1488C:\Monitor\proc.exeC:\Users\Public\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:21.633Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:21.802Unknown1488C:\Monitor\proc.exe\Device\Mup\W7VM1\Users\
8/9/2020 - 14:47:21.802Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot
8/9/2020 - 14:47:22.409Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Contacts
8/9/2020 - 14:47:22.911Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Contacts
8/9/2020 - 14:47:22.980Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Contacts
8/9/2020 - 14:47:23.448Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Contacts
8/9/2020 - 14:47:23.518Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Contacts\2x93mlc4s-readme.txt
8/9/2020 - 14:47:24.386Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Contacts\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:24.386Write1488C:\Monitor\proc.exeC:\Users\Behemot\Contacts\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:24.386Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Contacts\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:24.453Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Desktop
8/9/2020 - 14:47:24.987Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Desktop
8/9/2020 - 14:47:25.53Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Desktop
8/9/2020 - 14:47:25.518Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Desktop
8/9/2020 - 14:47:25.583Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Desktop\2x93mlc4s-readme.txt
8/9/2020 - 14:47:26.443Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Desktop\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:26.443Write1488C:\Monitor\proc.exeC:\Users\Behemot\Desktop\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:26.444Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Desktop\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:26.512Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Documents
8/9/2020 - 14:47:26.988Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Documents
8/9/2020 - 14:47:27.55Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Documents
8/9/2020 - 14:47:27.661Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Documents
8/9/2020 - 14:47:27.727Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\documents\2x93mlc4s-readme.txt
8/9/2020 - 14:47:28.413Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\documents\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:28.413Write1488C:\Monitor\proc.exeC:\Users\Behemot\Documents\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:28.413Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\documents\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:28.482Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Downloads
8/9/2020 - 14:47:29.37Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Downloads
8/9/2020 - 14:47:29.115Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Downloads
8/9/2020 - 14:47:29.576Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Downloads
8/9/2020 - 14:47:29.642Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\downloads\2x93mlc4s-readme.txt
8/9/2020 - 14:47:30.377Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\downloads\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:30.377Write1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:30.377Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\downloads\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:30.444Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Favorites
8/9/2020 - 14:47:30.906Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Favorites
8/9/2020 - 14:47:30.972Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Favorites
8/9/2020 - 14:47:31.505Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Favorites
8/9/2020 - 14:47:31.572Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\favorites\2x93mlc4s-readme.txt
8/9/2020 - 14:47:32.232Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\favorites\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:32.232Write1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:32.233Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\favorites\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:32.300Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Links
8/9/2020 - 14:47:32.837Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Links
8/9/2020 - 14:47:32.916Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Links
8/9/2020 - 14:47:33.349Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Links
8/9/2020 - 14:47:33.416Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Links\2x93mlc4s-readme.txt
8/9/2020 - 14:47:34.339Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Links\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:34.339Write1488C:\Monitor\proc.exeC:\Users\Behemot\Links\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:34.339Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Links\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:34.407Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Music
8/9/2020 - 14:47:34.915Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Music
8/9/2020 - 14:47:35.8Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Music
8/9/2020 - 14:47:35.484Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Music
8/9/2020 - 14:47:35.560Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Music\2x93mlc4s-readme.txt
8/9/2020 - 14:47:36.416Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Music\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:36.416Write1488C:\Monitor\proc.exeC:\Users\Behemot\Music\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:36.416Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Music\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:47:36.485Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:36.816Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:37.158Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:37.159Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:37.241Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:37.241Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:37.241Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:37.357Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:37.357Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:37.726Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:38.75Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:38.995Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
8/9/2020 - 14:47:39.88Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:39.88Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:39.88Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:39.167Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:39.168Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:39.168Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:39.251Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:40.278Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:40.627Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:40.627Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:40.703Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:40.704Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:40.704Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:40.779Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:40.780Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:41.181Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:41.511Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:41.950Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
8/9/2020 - 14:47:42.17Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:42.17Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:42.17Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:42.92Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:42.93Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:42.93Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:42.168Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:43.187Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:43.575Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:43.575Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:43.673Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:43.673Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:43.673Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:43.749Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:43.749Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:44.81Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:44.411Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:44.916Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
8/9/2020 - 14:47:44.982Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:44.982Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:44.983Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:45.60Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:45.60Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:45.60Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:45.70Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:46.83Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:46.414Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:46.746Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:47.217Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:47.217Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:47.291Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:47.291Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:47.292Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:47.366Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:47.366Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:47.701Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:48.38Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:48.548Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
8/9/2020 - 14:47:48.615Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:48.615Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:48.615Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:48.691Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:48.691Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:48.691Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:48.768Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:48.768Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:49.98Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:50.130Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:51.221Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:51.586Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:51.586Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:51.666Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:51.666Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:51.666Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:51.742Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:51.742Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:52.198Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:52.533Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:52.989Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
8/9/2020 - 14:47:53.97Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:53.97Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:53.97Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:53.106Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:53.106Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:53.106Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:53.114Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:53.114Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:53.472Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:54.81Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:55.164Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:55.572Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:55.572Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:55.647Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:55.647Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:55.647Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:55.720Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:47:55.720Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:56.83Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:56.411Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:56.952Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
8/9/2020 - 14:47:57.18Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:57.18Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:57.18Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:57.94Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:47:57.94Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:57.94Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:57.170Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:57.170Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:57.500Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:58.171Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:59.267Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:47:59.599Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:47:59.930Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:0.302Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:0.302Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:0.409Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:0.409Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:0.409Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:0.485Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:0.485Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:0.816Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:1.149Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:1.666Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
8/9/2020 - 14:48:1.732Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:2.112Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:3.166Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:3.233Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:3.233Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:3.233Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:3.309Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:3.309Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:3.309Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:3.384Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:3.384Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:3.725Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:4.395Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:5.477Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:5.810Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:5.810Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:5.887Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:5.888Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:5.888Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:5.963Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:5.964Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:6.366Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:6.696Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:7.205Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
8/9/2020 - 14:48:7.271Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:7.688Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:8.331Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:8.398Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:8.398Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:8.398Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:8.477Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:8.477Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:8.477Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:8.553Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:8.553Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:8.969Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:9.579Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:10.678Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:11.12Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:11.12Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:11.137Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:11.137Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:11.137Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:11.237Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:11.237Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:11.567Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:11.938Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:12.492Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
8/9/2020 - 14:48:12.558Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:12.893Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:13.540Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:13.626Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:13.626Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:13.626Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:13.701Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:13.701Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:13.701Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:13.777Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:13.777Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:14.109Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:14.753Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:15.880Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:16.244Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:16.575Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:16.954Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:16.954Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:17.30Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:17.31Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:17.31Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:17.151Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:17.152Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:17.500Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:17.827Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:18.266Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
8/9/2020 - 14:48:18.379Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:18.732Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:19.333Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:19.398Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:19.398Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:19.398Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:19.472Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:19.472Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:19.473Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:19.594Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:19.594Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:19.945Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:20.550Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:20.617Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:21.23Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:22.83Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:23.202Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:23.544Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:23.545Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:23.629Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:23.630Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:23.630Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:23.707Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:23.707Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:24.70Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:24.481Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:24.938Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
8/9/2020 - 14:48:25.5Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:25.344Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:26.53Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:26.121Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:26.121Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:26.121Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:26.200Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:26.200Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:26.200Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:26.278Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:26.278Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:26.611Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:27.366Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:27.431Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:27.762Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:28.447Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:29.544Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:29.875Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:29.876Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:30.17Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:30.17Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:30.17Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:30.158Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:30.158Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:30.538Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:30.893Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:31.399Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\ntuser.dat.LOG1ntuser.dat.LOG1
8/9/2020 - 14:48:31.465Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:31.899Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:32.567Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:32.634Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:32.634Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:32.634Open1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:32.773Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\ntuser.dat.LOG1
8/9/2020 - 14:48:32.773Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:32.773Open1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:32.967Unknown1488C:\Monitor\proc.exeC:\Users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
8/9/2020 - 14:48:32.967Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:33.320Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:33.995Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blfNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
8/9/2020 - 14:48:34.61Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:34.456Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:35.120Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-msNTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:36.198Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
8/9/2020 - 14:48:36.528Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Pictures
8/9/2020 - 14:48:37.90Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Pictures
8/9/2020 - 14:48:37.158Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Pictures
8/9/2020 - 14:48:37.615Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Pictures
8/9/2020 - 14:48:37.681Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Pictures\2x93mlc4s-readme.txt
8/9/2020 - 14:48:38.524Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Pictures\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:38.524Write1488C:\Monitor\proc.exeC:\Users\Behemot\Pictures\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:38.524Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Pictures\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:38.591Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Saved Games
8/9/2020 - 14:48:39.97Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Saved Games
8/9/2020 - 14:48:39.165Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Saved Games
8/9/2020 - 14:48:39.654Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Saved Games
8/9/2020 - 14:48:39.720Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\saved games\2x93mlc4s-readme.txt
8/9/2020 - 14:48:40.375Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\saved games\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:40.375Write1488C:\Monitor\proc.exeC:\Users\Behemot\Saved Games\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:40.375Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\saved games\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:40.484Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Searches
8/9/2020 - 14:48:40.983Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Searches
8/9/2020 - 14:48:41.52Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Searches
8/9/2020 - 14:48:41.520Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Searches
8/9/2020 - 14:48:41.586Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Searches\2x93mlc4s-readme.txt
8/9/2020 - 14:48:42.457Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Searches\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:42.457Write1488C:\Monitor\proc.exeC:\Users\Behemot\Searches\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:42.458Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Searches\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:42.528Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Videos
8/9/2020 - 14:48:42.997Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Videos
8/9/2020 - 14:48:43.63Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Videos
8/9/2020 - 14:48:43.607Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Videos
8/9/2020 - 14:48:43.673Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Videos\2x93mlc4s-readme.txt
8/9/2020 - 14:48:44.436Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Videos\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:44.436Write1488C:\Monitor\proc.exeC:\Users\Behemot\Videos\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:44.436Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Videos\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:44.602Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot
8/9/2020 - 14:48:44.717Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default
8/9/2020 - 14:48:45.291Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Desktop
8/9/2020 - 14:48:45.750Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Desktop
8/9/2020 - 14:48:45.818Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Desktop
8/9/2020 - 14:48:46.347Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Desktop
8/9/2020 - 14:48:46.414Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Desktop\2x93mlc4s-readme.txt
8/9/2020 - 14:48:53.271Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Desktop\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:53.271Write1488C:\Monitor\proc.exeC:\Users\Default\Desktop\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:53.271Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Desktop\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:53.338Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Documents
8/9/2020 - 14:48:53.881Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Documents
8/9/2020 - 14:48:53.949Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Documents
8/9/2020 - 14:48:54.416Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Documents
8/9/2020 - 14:48:54.483Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\documents\2x93mlc4s-readme.txt
8/9/2020 - 14:48:55.222Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\documents\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:55.222Write1488C:\Monitor\proc.exeC:\Users\Default\Documents\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:55.222Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\documents\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:55.291Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Downloads
8/9/2020 - 14:48:55.757Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Downloads
8/9/2020 - 14:48:55.824Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Downloads
8/9/2020 - 14:48:56.361Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Downloads
8/9/2020 - 14:48:56.427Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\downloads\2x93mlc4s-readme.txt
8/9/2020 - 14:48:57.79Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\downloads\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:57.79Write1488C:\Monitor\proc.exeC:\Users\Default\Downloads\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:57.79Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\downloads\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:57.145Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Favorites
8/9/2020 - 14:48:57.677Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Favorites
8/9/2020 - 14:48:57.744Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Favorites
8/9/2020 - 14:48:58.240Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Favorites
8/9/2020 - 14:48:58.308Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\favorites\2x93mlc4s-readme.txt
8/9/2020 - 14:48:59.84Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\favorites\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:59.84Write1488C:\Monitor\proc.exeC:\Users\Default\Favorites\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:59.84Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\favorites\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:48:59.153Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Links
8/9/2020 - 14:48:59.628Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Links
8/9/2020 - 14:48:59.695Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Links
8/9/2020 - 14:49:0.203Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Links
8/9/2020 - 14:49:0.269Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Links\2x93mlc4s-readme.txt
8/9/2020 - 14:49:1.65Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Links\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:1.65Write1488C:\Monitor\proc.exeC:\Users\Default\Links\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:1.65Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Links\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:1.133Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Music
8/9/2020 - 14:49:1.670Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Music
8/9/2020 - 14:49:1.737Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Music
8/9/2020 - 14:49:2.197Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Music
8/9/2020 - 14:49:2.263Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Music\2x93mlc4s-readme.txt
8/9/2020 - 14:49:3.170Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Music\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:3.170Write1488C:\Monitor\proc.exeC:\Users\Default\Music\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:3.170Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Music\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:3.238Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Pictures
8/9/2020 - 14:49:3.694Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Pictures
8/9/2020 - 14:49:3.760Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Pictures
8/9/2020 - 14:49:4.291Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Pictures
8/9/2020 - 14:49:4.357Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Pictures\2x93mlc4s-readme.txt
8/9/2020 - 14:49:5.109Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Pictures\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:5.109Write1488C:\Monitor\proc.exeC:\Users\Default\Pictures\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:5.109Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Pictures\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:5.341Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Saved Games
8/9/2020 - 14:49:5.796Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Saved Games
8/9/2020 - 14:49:5.863Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Saved Games
8/9/2020 - 14:49:6.319Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Saved Games
8/9/2020 - 14:49:6.426Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\saved games\2x93mlc4s-readme.txt
8/9/2020 - 14:49:7.110Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\saved games\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:7.110Write1488C:\Monitor\proc.exeC:\Users\Default\Saved Games\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:7.110Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\saved games\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:7.176Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Videos
8/9/2020 - 14:49:7.685Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Videos
8/9/2020 - 14:49:7.775Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Videos
8/9/2020 - 14:49:8.274Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Videos
8/9/2020 - 14:49:8.340Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Videos\2x93mlc4s-readme.txt
8/9/2020 - 14:49:9.164Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Videos\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:9.164Write1488C:\Monitor\proc.exeC:\Users\Default\Videos\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:9.164Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default\Videos\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:9.331Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Default
8/9/2020 - 14:49:9.397Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public
8/9/2020 - 14:49:9.950Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Desktop
8/9/2020 - 14:49:10.482Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Desktop
8/9/2020 - 14:49:10.554Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Desktop
8/9/2020 - 14:49:11.10Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Desktop
8/9/2020 - 14:49:11.76Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Desktop\2x93mlc4s-readme.txt
8/9/2020 - 14:49:11.902Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Desktop\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:11.902Write1488C:\Monitor\proc.exeC:\Users\Public\Desktop\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:11.902Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Desktop\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:11.968Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Documents
8/9/2020 - 14:49:12.473Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Documents
8/9/2020 - 14:49:12.561Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Documents
8/9/2020 - 14:49:13.125Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Documents
8/9/2020 - 14:49:13.191Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\documents\2x93mlc4s-readme.txt
8/9/2020 - 14:49:13.911Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\documents\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:13.911Write1488C:\Monitor\proc.exeC:\Users\Public\Documents\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:13.911Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\documents\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:13.978Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Downloads
8/9/2020 - 14:49:14.436Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Downloads
8/9/2020 - 14:49:14.503Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Downloads
8/9/2020 - 14:49:15.41Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Downloads
8/9/2020 - 14:49:15.107Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\downloads\2x93mlc4s-readme.txt
8/9/2020 - 14:49:15.782Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\downloads\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:15.782Write1488C:\Monitor\proc.exeC:\Users\Public\Downloads\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:15.782Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\downloads\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:15.849Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Favorites
8/9/2020 - 14:49:16.391Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Favorites
8/9/2020 - 14:49:16.458Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Favorites
8/9/2020 - 14:49:16.929Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Favorites
8/9/2020 - 14:49:16.996Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\favorites\2x93mlc4s-readme.txt
8/9/2020 - 14:49:17.726Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\favorites\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:17.726Write1488C:\Monitor\proc.exeC:\Users\Public\Favorites\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:17.726Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\favorites\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:17.794Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Libraries
8/9/2020 - 14:49:18.332Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Libraries
8/9/2020 - 14:49:18.398Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Libraries
8/9/2020 - 14:49:18.926Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Libraries
8/9/2020 - 14:49:18.993Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\libraries\2x93mlc4s-readme.txt
8/9/2020 - 14:49:19.687Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\libraries\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:19.687Write1488C:\Monitor\proc.exeC:\Users\Public\Libraries\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:19.687Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\libraries\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:19.782Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Music
8/9/2020 - 14:49:20.244Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Music
8/9/2020 - 14:49:20.310Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Music
8/9/2020 - 14:49:20.787Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Music
8/9/2020 - 14:49:20.896Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Music\2x93mlc4s-readme.txt
8/9/2020 - 14:49:21.687Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Music\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:21.687Write1488C:\Monitor\proc.exeC:\Users\Public\Music\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:21.687Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Music\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:21.753Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Pictures
8/9/2020 - 14:49:22.291Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Pictures
8/9/2020 - 14:49:22.357Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Pictures
8/9/2020 - 14:49:22.824Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Pictures
8/9/2020 - 14:49:27.863Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Pictures\2x93mlc4s-readme.txt
8/9/2020 - 14:49:28.746Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Pictures\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:28.746Write1488C:\Monitor\proc.exeC:\Users\Public\Pictures\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:28.746Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Pictures\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:28.812Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Recorded TV
8/9/2020 - 14:49:29.315Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Recorded TV
8/9/2020 - 14:49:29.390Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Recorded TV
8/9/2020 - 14:49:29.884Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Recorded TV
8/9/2020 - 14:49:29.951Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\recorded tv\2x93mlc4s-readme.txt
8/9/2020 - 14:49:30.609Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\recorded tv\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:30.609Write1488C:\Monitor\proc.exeC:\Users\Public\Recorded TV\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:30.609Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\recorded tv\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:30.716Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Videos
8/9/2020 - 14:49:31.232Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Videos
8/9/2020 - 14:49:31.298Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Videos
8/9/2020 - 14:49:31.756Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Videos
8/9/2020 - 14:49:31.823Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Videos\2x93mlc4s-readme.txt
8/9/2020 - 14:49:32.693Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Videos\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:32.693Write1488C:\Monitor\proc.exeC:\Users\Public\Videos\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:32.694Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public\Videos\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:32.964Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Public
8/9/2020 - 14:49:33.33Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Contacts
8/9/2020 - 14:49:33.985Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Contacts
8/9/2020 - 14:49:34.51Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Desktop
8/9/2020 - 14:49:34.978Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Desktop
8/9/2020 - 14:49:35.44Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Documents
8/9/2020 - 14:49:36.5Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Documents
8/9/2020 - 14:49:36.72Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Downloads
8/9/2020 - 14:49:36.862Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Downloads\Monitor
8/9/2020 - 14:49:37.404Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Downloads\Monitor
8/9/2020 - 14:49:37.470Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Downloads\Monitor
8/9/2020 - 14:49:37.949Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Downloads\Monitor
8/9/2020 - 14:49:38.15Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Downloads\Monitor\2x93mlc4s-readme.txt
8/9/2020 - 14:49:38.824Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Downloads\Monitor\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:38.824Write1488C:\Monitor\proc.exeC:\Users\Behemot\Downloads\Monitor\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:38.824Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Downloads\Monitor\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:39.10Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Downloads
8/9/2020 - 14:49:39.76Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Favorites
8/9/2020 - 14:49:39.861Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Favorites\Links
8/9/2020 - 14:49:40.391Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Favorites\Links
8/9/2020 - 14:49:40.458Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Favorites\Links
8/9/2020 - 14:49:40.964Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Favorites\Links
8/9/2020 - 14:49:41.31Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Favorites\Links\2x93mlc4s-readme.txt
8/9/2020 - 14:49:41.850Write1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Favorites\Links\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:41.850Write1488C:\Monitor\proc.exeC:\Users\Behemot\Favorites\Links\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:41.850Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Favorites\Links\2x93mlc4s-readme.txt2x93mlc4s-readme.txt
8/9/2020 - 14:49:41.917Open1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Favorites\Links for Brasil
8/9/2020 - 14:49:42.376Unknown1488C:\Monitor\proc.exe\Device\Mup\w7vm1\users\Behemot\Favorites\Links for Brasil

Process
Trace
8/9/2020 - 14:45:42.512Create1480C:\malware.exe1488C:\Monitor\proc.exe
8/9/2020 - 14:45:45.873Create1488C:\Monitor\proc.exe804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
8/9/2020 - 14:46:53.627Terminate1488C:\Monitor\proc.exe804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe

Analysis
Reason
Timeout

Status
Sucessfully Executed

Results
1

Registry
Trace
8/9/2020 - 14:45:45.679Write1488C:\Monitor\proc.exe\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Facebook_AssistantYbr
8/9/2020 - 14:45:45.680Write1488C:\Monitor\proc.exe\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Facebook_AssistantS6yP
8/9/2020 - 14:45:45.682Write1488C:\Monitor\proc.exe\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Facebook_AssistantdA2U3
8/9/2020 - 14:45:45.684Write1488C:\Monitor\proc.exe\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Facebook_Assistant8eN335
8/9/2020 - 14:45:45.686Write1488C:\Monitor\proc.exe\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Facebook_AssistantzEhXReE
8/9/2020 - 14:45:45.695Write1488C:\Monitor\proc.exe\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Facebook_AssistantfOvNL4TU
8/9/2020 - 14:45:45.696Write1488C:\Monitor\proc.exe\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunBV7BRrErOX
8/9/2020 - 14:45:46.532Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.533Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.534Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.540Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.594Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.595Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.595Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.595Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.595Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.596Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.596Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.596Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.597Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.597Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.597Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.597Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.598Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.598Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.598Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.599Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.600Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.600Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.600Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.601Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.601Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.601Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.601Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.602Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.602Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.602Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.604Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.604Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.604Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.605Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.605Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.605Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.606Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.606Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.606Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.606Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.607Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.607Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.607Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.607Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.608Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.608Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.608Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.608Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.609Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.609Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.609Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.610Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.610Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.611Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.611Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.611Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.611Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.612Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.612Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.612Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.613Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.613Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.613Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.632Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.762Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.763Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.763Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.764Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.765Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.765Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.766Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.766Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.767Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.768Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.768Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.773Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.773Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.780Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:45:46.780Write804C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeHKCU\Local Settings\MuiCache\5\96383CDBLanguageList
8/9/2020 - 14:46:54.183Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000Owner
8/9/2020 - 14:46:54.184Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000SessionHash
8/9/2020 - 14:46:54.184Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000Sequence
8/9/2020 - 14:46:54.185Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:46:54.185Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:46:55.266Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:46:55.266Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:46:56.433Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:46:56.433Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:46:57.525Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:46:57.525Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:46:58.707Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:46:58.707Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:46:59.735Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:46:59.735Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:47:0.834Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:47:0.834Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:47:1.997Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:47:1.997Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:47:3.149Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:47:3.149Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:47:4.313Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:47:4.313Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:47:5.519Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:47:5.519Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:47:6.763Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:47:6.763Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:47:37.150Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:47:37.150Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:47:40.617Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:47:40.619Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:47:43.571Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:47:43.571Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:47:47.211Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:47:47.211Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:47:51.582Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:47:51.582Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:47:55.566Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:47:55.566Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:48:0.299Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:48:0.299Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:48:5.807Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:48:5.808Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:48:11.10Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:48:11.10Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:48:16.950Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:48:16.950Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:48:23.540Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:48:23.541Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash
8/9/2020 - 14:48:29.874Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFiles0000
8/9/2020 - 14:48:29.874Write1488C:\Monitor\proc.exeHKCU\Software\Microsoft\RestartManager\Session0000RegFilesHash

File Summary
Created
Identified: True check_circle

Deleted
Identified: False cancel

Process Summary
Created
Identified: True check_circle

Deleted
Identified: True check_circle

Registry Summary
Proxy
Identified: False cancel

AutoRun
Identified: False cancel

Created
Identified: True check_circle

Deleted
Identified: False cancel

Browsers
Identified: False cancel

Internet
Identified: False cancel

Loading...

DNS
Query

Response

TCP
Info

UDP
Info

HTTP
Info

Summary
DNS
False cancel

TCP
False cancel

UDP
False cancel

HTTP
False cancel

Results
BINARY
NFS 2.0 (Threshold = 0.8)
confidence: 80.00%
suspicious: False cancel

Decision Tree (NFS-BRMalware)
confidence: 100.00%
suspicious: True check_circle

MalConv (Ember: Raw Bytes, Threshold=0.5)
confidence: 95.00%
suspicious: True check_circle

Random Forest (100 estimators, NFS-BRMalware)
confidence: 65.00%
suspicious: False cancel

Non-Negative MalConv (Ember: Raw Bytes, Threshold=0.35)
confidence: 47.18%
suspicious: True check_circle

LightGDM (Ember: File Characteristics, Threshold=0.8336)
confidence: 63.54%
suspicious: False cancel

Add to Collection
Download