Report #5881 check_circle
- Creation Date: Feb. 12, 2020, 6:14 p.m.
- Last Update: Feb. 13, 2020, 2:14 a.m.
- File: Nota_Fiscal.exe
- Results:
Binary
DLL
False cancel
Size
849.00KB
trid
61.7% Win64 Executable14.7% Win32 Dynamic Link Library10.0% Win32 Executable4.5% OS/2 Executable4.4% Generic Win/DOS Executable
type
PE
wordsize
32
Subsystem
Windows GUI
Hashes
md5
679dd0f68e9f25b4c57bd5bc332fb952
sha1
729691cf9c991ea8423c2cb8902d982e55dea0e4
crc32
0xcd6de346
sha224
c76950183879147db67fc2abc7be94d4be15306ef5884e7b454b91ba
sha256
32d6f959655bef9aefaf606d7d5e0a6882b445387405ed841db8d46b4085bb29
sha384
3c7139cf20df7cba95d4a085824b54a1566a63859dc81232f5b49cd37077ecc9edc82f25f5683667d23d40b66cf53634
sha512
7722af411b3c948ea9b519edb67074490d22263ccb3c1d9f6c023199bae120ac886e8dcd1e71db4ec997f35d9472fa2d45eea5ac820ae00e79f8460f37adb146
ssdeep
24576:sAHnh+eWsN3skA4RV1Hom2KXSmdaw6q5:Lh+ZkldoPKi2awD
Community
Google
False cancel
HashLib
False cancel
YARA
Matches
domain, HasDebugData, CRC32_poly_Constant, escalate_priv, HasRichSignature, VC8_Microsoft_Corporation, CRC32_table, network_http, win_files_operation, IsPE32, AutoIT_compiled_script, screenshot, IP, contentis_base64, keylogger, win_token, AutoIt, IsWindowsGUI, inject_thread, anti_dbg, Microsoft_Visual_Cpp_8, win_registry
Suspicious
True check_circle
Strings
List
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" language="*" processorArchitecture="*" publicKeyToken="6595b64144ccf1df"/>Gt.Ht$WSOCK32.dllFSoftware\AutoIt v3\AutoItCOMCTL32.dllUSERENV.dllVERSION.dllWININET.dllWINMM.dllUxTheme.dll0.0.0.0MPR.dllAUTOITCALLVARIABLE%d255.255.255.255SeDebugPrivilegeSeRestorePrivilege<"t|<%tx<'tt<$tp<&tl<!th<otd<]t`<[t\<\tX<\Include\fr-befr-cafr-ch0%1F1O1i1w1This is a third-party compiled AutoIt script.BACKSPACEHebrewDuployanBIncludeHOTKEYSETTaskbarCreatedHOTKEYPRESSEDtoo many forward referencesinvalid range in character classfailed to get memoryclosedfailed to get memorynumber is too bigregular expression is too large\ at end of pattern\c at end of patterntwo named subpatterns have the same nameBROWSER_SEARCHHKEY_CLASSES_ROOTTCPSHUTDOWNBROWSER_REFRESHAutoIt has detected the stack has become corrupt.BROWSER_FORWARDBROWSER_STOPBROWSER_BACKBROWSER_HOMELAUNCH_MAILBROWSER_FAVORTIESHKEY_LOCAL_MACHINELine %d (File "%s"):VOLUME_UPVOLUME_DOWNVOLUME_MUTE] is an invalid data character in JavaScript compatibility modeLAUNCH_MEDIASOFTWARE\Classes\Line %d:TCPLISTENFtpOpenFileWSYSTEM\CurrentControlSet\Control\Nls\LanguageFtpGetFileSizeFTPSETPROXYSW_HIDEAUTOITWINGETTITLEGETCURRENTSELECTIONTCPCLOSESOCKETTCPCONNECTHTTPSETUSERAGENTGETSELECTEDCOUNTGETSELECTEDHTTPSETPROXYWINGETCLASSLISTEWM_GETCONTROLNAMEHControl Panel\MouseControl Panel\AppearanceHttpOpenRequestWHttpSendRequestW/AutoIt3OutputDebugmscoree.dllLAUNCH_APP2LAUNCH_APP1WIN_VISTASeShutdownPrivilegeSeBackupPrivilegeSeIncreaseQuotaPrivilege/AutoIt3ExecuteLineSeAssignPrimaryTokenPrivilege!"#$%%%%%%&&'()*+%%%%%%&&'()*+,,,,,,--./012RRRRRRRRRRRR3345566789::::;<=<=>?>@ABC>@ABCRRRRRDEFGHIJKLMNOAUTOIT.ERROR#requireadmin>>>AUTOIT SCRIPT<<<SHELLDLL_DefViewLOCALAPPDATADIR<requestedPrivileges>\\[\\nrt]|%%|%[-+ 0#]?([0-9]*|\*)?(\.[0-9]*|\.\*)?[hlL]?[diouxXeEfgGs]winsta0\defaultLOGONDNSDOMAIN
Foremost
Matches
0.exe, 849 KB
Suspicious
True check_circle
Heuristics
IPs
hasIPs: True check_circleAllowed: 255.255.255.255, 1, recordSuspicioushasAllowed: True check_circlehasSuspicious: False cancel
URLs
AllowedhasURLs: False cancelSuspicioushasAllowed: False cancelhasSuspicious: False cancel
Files
Allowed: USER32.DLL, kernel32.dll, mscoree.dll, combase.dll, SHELL32.dll, WININET.dll, OLEAUT32.dll, PSAPI.DLL, ADVAPI32.dll, VERSION.dll, USERENV.dll, UxTheme.dll, GDI32.dll, COMCTL32.dll, COMDLG32.dll, ole32.dll, MPR.dll, IPHLPAPI.DLL, WINMM.dll, WSOCK32.dllhasFiles: True check_circleSuspicioushasAllowed: True check_circlehasSuspicious: False cancel
Binary
Sizes
RVARVA: 16Suspicious: False cancelCodeSize: 286720Suspicious: False cancelImageAddress: 4194304Suspicious: False cancelStackStack: 4096Suspicious: False cancelHeadersHeaders: 1024Suspicious: False cancelSuspicious: False cancel
Symbols
NumberNumber: 0Suspicious: True check_circlePointerPointer: 0Suspicious: True check_circleDirectoriesNumber: 16Suspicious: False cancel
Checksum
Value: 907292Suspicous: False cancel
Sections
Allowed: .text, .rdata, .data, .rsrc, .relocSuspicioushasAllowed: True check_circlehasSections: True check_circlehasSuspicious: False cancel
Versions
OSVersion: 5Suspicious: False cancelImageVersion: True check_circleSuspicious: 5LinkerVersion: 12.0Suspicious: False cancelSubsystemVersion: 5.1Suspicious: False cancelSuspicious: False cancel
EntryPoint
Address: 163850Suspicious: False cancel
Anomalies
Anomalies: The Debug TimeDateStamp(s) and the file header TimeDateStamp do not match.hasAnomalies: True check_circle
Libraries
Allowed: user32.dll, kernel32.dll, mscoree.dll, combase.dll, shell32.dll, wininet.dll, oleaut32.dll, psapi.dll, advapi32.dll, version.dll, userenv.dll, uxtheme.dll, gdi32.dll, comctl32.dll, comdlg32.dll, ole32.dll, mpr.dll, winmm.dll, wsock32.dllhasLibs: True check_circleSuspicious: iphlpapi.dllhasAllowed: True check_circlehasSuspicious: True check_circle
Timestamp
Past: False cancelValid: True check_circleValue: 2018-02-15 10:15:34Future: False cancel
Compilation
Packed: False cancelMissing: False cancelPackersCompiled: True check_circleCompilers: Microsoft Visual C++ 8, VC8 -> Microsoft Corporation
Obfuscation
XOR: False cancelFuzzing: True check_circle
PEDetector
Matches
None
Suspicious
False cancel
Disassembly
hasTricks
True check_circle
Tricks
pushret
.data: 1.rsrc: 2.text: 2.rdata: 13
nopsequence
.text: 4
pushpopmath
.rsrc: 2.text: 31.rdata: 7.reloc: 30
garbagebytes
.data: 1.rsrc: 1.text: 2.rdata: 5
hookdetection
.rdata: 3.reloc: 4
stealthimport
.text: 1
software breakpoint
.text: 9.rdata: 1.reloc: 5
programcontrolflowchange
.data: 1.rsrc: 1.text: 2.rdata: 5
cpuinstructionsresultscomparison
.rsrc: 7.rdata: 9
AVclass
autoit
1
VirusTotal
md5
679dd0f68e9f25b4c57bd5bc332fb952
sha1
729691cf9c991ea8423c2cb8902d982e55dea0e4
SCANS (DETECTION RATE = 58.21%)
AVG
result: Win32:Malware-genupdate: 20181101version: 18.4.3895.0detected: True check_circle
CMC
update: 20181101version: 1.1.0.977detected: False cancel
MAX
result: malware (ai score=100)update: 20181101version: 2018.9.12.1detected: True check_circle
Bkav
update: 20181101version: 1.3.0.9898detected: False cancel
K7GW
result: Trojan-Downloader ( 005274351 )update: 20181101version: 11.9.28899detected: True check_circle
ALYac
result: Trojan.GenericKD.40129517update: 20181101version: 1.1.1.5detected: True check_circle
Avast
result: Win32:Malware-genupdate: 20181101version: 18.4.3895.0detected: True check_circle
Avira
result: HEUR/AGEN.1000243update: 20181101version: 8.3.3.6detected: True check_circle
Baidu
update: 20181101version: 1.0.0.2detected: False cancel
Cyren
result: W32/Trojan.TCET-5951update: 20181101version: 6.0.0.4detected: True check_circle
DrWeb
update: 20181101version: 7.0.33.6080detected: False cancel
GData
result: Trojan.GenericKD.40129517update: 20181101version: A:25.19177B:25.13572detected: True check_circle
Panda
result: Trj/CI.Aupdate: 20181101version: 4.6.4.2detected: True check_circle
VBA32
result: TrojanDownloader.AutoItupdate: 20181101version: 3.33.0detected: True check_circle
VIPRE
result: Trojan.Win32.Generic!BTupdate: 20181101version: 70672detected: True check_circle
Zoner
update: 20181101version: 1.0detected: False cancel
ClamAV
update: 20181101version: 0.100.2.0detected: False cancel
F-Prot
update: 20181101version: 4.7.1.166detected: False cancel
Ikarus
result: Trojan-Downloader.Win32.AutoItupdate: 20181101version: 0.1.5.2detected: True check_circle
McAfee
result: Artemis!679DD0F68E9Fupdate: 20181101version: 6.0.6.653detected: True check_circle
Rising
update: 20181101version: 25.0.0.24detected: False cancel
Sophos
result: Mal/Generic-Supdate: 20181101version: 4.98.0detected: True check_circle
Yandex
update: 20181101version: 5.5.1.3detected: False cancel
Zillya
update: 20181101version: 2.0.0.3682detected: False cancel
Alibaba
update: 20180921version: 0.1.0.2detected: False cancel
Arcabit
result: Trojan.Generic.D26453EDupdate: 20181101version: 1.0.0.833detected: True check_circle
Babable
update: 20180918version: 9107201detected: False cancel
Endgame
update: 20180730version: 3.0.1detected: False cancel
TACHYON
update: 20181101version: 2018-11-01.02detected: False cancel
Tencent
result: Win32.Trojan-downloader.Autoit.Wpttupdate: 20181101version: 1.0.0.1detected: True check_circle
ViRobot
update: 20181101version: 2014.3.20.0detected: False cancel
Webroot
result: W32.Adware.Genupdate: 20181101version: 1.0.0.403detected: True check_circle
eGambit
update: 20181101detected: False cancel
Ad-Aware
result: Trojan.GenericKD.40129517update: 20181101version: 3.0.5.370detected: True check_circle
AegisLab
result: Trojan.Win32.Autoit.a!cupdate: 20181101version: 4.2detected: True check_circle
Emsisoft
result: Trojan.GenericKD.40129517 (B)update: 20181101version: 2018.4.0.1029detected: True check_circle
F-Secure
result: Trojan.GenericKD.40129517update: 20181101version: 11.0.19100.45detected: True check_circle
Fortinet
result: W32/Autoit.OKV!trupdate: 20181101version: 5.4.247.0detected: True check_circle
Invincea
result: heuristicupdate: 20180717version: 6.3.5.26121detected: True check_circle
Jiangmin
update: 20181101version: 16.0.100detected: False cancel
Kingsoft
update: 20181101version: 2013.8.14.323detected: False cancel
Paloalto
result: generic.mlupdate: 20181101version: 1.0detected: True check_circle
Symantec
result: Trojan.Gen.2update: 20181101version: 1.8.0.0detected: True check_circle
AhnLab-V3
result: Downloader/Win32.Autoit.C2408950update: 20181101version: 3.13.1.22397detected: True check_circle
Antiy-AVL
result: Trojan/Generic.ASVCS3S.1E5update: 20181101version: 3.0.0.1detected: True check_circle
Kaspersky
result: Trojan-Downloader.Win32.Autoit.rhkupdate: 20181101version: 15.0.1.13detected: True check_circle
Microsoft
result: Trojan:Win32/Tiggre!rfnupdate: 20181101version: 1.1.15400.4detected: True check_circle
Qihoo-360
result: Win32/Trojan.Downloader.fffupdate: 20181101version: 1.0.0.1120detected: True check_circle
TheHacker
update: 20181031version: 6.8.0.5.3804detected: False cancel
Trustlook
update: 20181101version: 1.0detected: False cancel
ZoneAlarm
result: Trojan-Downloader.Win32.Autoit.rhkupdate: 20181101version: 1.0detected: True check_circle
Cybereason
update: 20180225version: 1.2.27detected: False cancel
ESET-NOD32
result: a variant of Win32/TrojanDownloader.Autoit.OKVupdate: 20181101version: 18311detected: True check_circle
TrendMicro
update: 20181101version: 10.0.0.1040detected: False cancel
BitDefender
result: Trojan.GenericKD.40129517update: 20181101version: 7.2detected: True check_circle
CrowdStrike
result: malicious_confidence_100% (W)update: 20181022version: 1.0detected: True check_circle
K7AntiVirus
result: Trojan-Downloader ( 005274351 )update: 20181101version: 11.9.28899detected: True check_circle
SentinelOne
result: static engine - maliciousupdate: 20181011version: 1.0.19.245detected: True check_circle
Avast-Mobile
update: 20181101version: 181101-02detected: False cancel
Malwarebytes
update: 20181101version: 2.1.1.1115detected: False cancel
TotalDefense
update: 20181101version: 37.1.62.1detected: False cancel
CAT-QuickHeal
update: 20181031version: 14.00detected: False cancel
NANO-Antivirus
result: Trojan.Win32.Autoit.eydtdhupdate: 20181101version: 1.0.134.24299detected: True check_circle
MicroWorld-eScan
result: Trojan.GenericKD.40129517update: 20181101version: 14.0.297.0detected: True check_circle
SUPERAntiSpyware
update: 20181031version: 5.6.0.1032detected: False cancel
McAfee-GW-Edition
result: BehavesLike.Win32.Downloader.chupdate: 20181101version: v2017.3010detected: True check_circle
TrendMicro-HouseCall
update: 20181101version: 10.0.0.1040detected: False cancel
total
67
sha256
32d6f959655bef9aefaf606d7d5e0a6882b445387405ed841db8d46b4085bb29
scan_id
32d6f959655bef9aefaf606d7d5e0a6882b445387405ed841db8d46b4085bb29-1541091271
resource
679dd0f68e9f25b4c57bd5bc332fb952
positives
39
scan_date
2018-11-01 16:54:31
verbose_msg
Scan finished, information embedded
response_code
1
File
Trace
13/2/2020 - 1:45:57.668 | Open | 1480 | C:\malware.exe | C:\Monitor | |
13/2/2020 - 1:45:57.668 | Unknown | 1480 | C:\malware.exe | C:\Monitor | |
13/2/2020 - 1:45:57.715 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | |
13/2/2020 - 1:45:57.762 | Unknown | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | powershell.exe |
13/2/2020 - 1:45:57.762 | Open | 1480 | C:\malware.exe | C:\PROPSYS.dll | |
13/2/2020 - 1:45:57.762 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\propsys.dll | |
13/2/2020 - 1:45:57.762 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\propsys.dll | |
13/2/2020 - 1:45:57.762 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:45:57.762 | Open | 1480 | C:\malware.exe | C:\malware.exe.Local | |
13/2/2020 - 1:45:57.762 | Open | 1480 | C:\malware.exe | C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d | |
13/2/2020 - 1:45:57.762 | Unknown | 1480 | C:\malware.exe | C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d | |
13/2/2020 - 1:45:57.762 | Open | 1480 | C:\malware.exe | C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d | |
13/2/2020 - 1:45:57.762 | Open | 1480 | C:\malware.exe | C:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches | |
13/2/2020 - 1:45:57.762 | Open | 1480 | C:\malware.exe | C:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches\cversions.1.db | |
13/2/2020 - 1:45:57.762 | Open | 1480 | C:\malware.exe | C:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches | |
13/2/2020 - 1:45:57.762 | Open | 1480 | C:\malware.exe | C:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches\cversions.1.db | |
13/2/2020 - 1:45:57.762 | Open | 1480 | C:\malware.exe | C:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000000.db | |
13/2/2020 - 1:45:57.778 | Open | 1480 | C:\malware.exe | C:\Users\Behemot\Desktop\desktop.ini | |
13/2/2020 - 1:45:57.778 | Read | 1480 | C:\malware.exe | C:\Users\Behemot\Desktop\desktop.ini | |
13/2/2020 - 1:45:57.778 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\propsys.dll | |
13/2/2020 - 1:45:57.778 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\propsys.dll | |
13/2/2020 - 1:45:57.778 | Open | 1480 | C:\malware.exe | C:\Windows\System32\propsys.dll | |
13/2/2020 - 1:45:57.778 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\propsys.dll | |
13/2/2020 - 1:45:57.778 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\propsys.dll | |
13/2/2020 - 1:45:57.778 | Open | 1480 | C:\malware.exe | C:\Windows\System32\propsys.dll | |
13/2/2020 - 1:45:57.778 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\urlmon.dll | |
13/2/2020 - 1:45:57.778 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\urlmon.dll | |
13/2/2020 - 1:45:57.778 | Open | 1480 | C:\malware.exe | C:\Secur32.dll | |
13/2/2020 - 1:45:57.778 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\secur32.dll | |
13/2/2020 - 1:45:57.793 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\secur32.dll | |
13/2/2020 - 1:45:57.887 | Open | 1480 | C:\malware.exe | C:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files | |
13/2/2020 - 1:45:57.887 | Unknown | 1480 | C:\malware.exe | C:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files | |
13/2/2020 - 1:45:57.887 | Open | 1480 | C:\malware.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies | |
13/2/2020 - 1:45:57.887 | Unknown | 1480 | C:\malware.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies | |
13/2/2020 - 1:45:57.887 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | |
13/2/2020 - 1:45:57.887 | Unknown | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | powershell.exe |
13/2/2020 - 1:45:57.887 | Open | 1480 | C:\malware.exe | C:\ | |
13/2/2020 - 1:45:57.887 | Unknown | 1480 | C:\malware.exe | C:\ | |
13/2/2020 - 1:45:57.887 | Open | 1480 | C:\malware.exe | C:\Windows | |
13/2/2020 - 1:45:57.887 | Unknown | 1480 | C:\malware.exe | C:\Windows | |
13/2/2020 - 1:45:57.887 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell | |
13/2/2020 - 1:45:57.887 | Unknown | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell | |
13/2/2020 - 1:45:57.887 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | |
13/2/2020 - 1:45:57.887 | Unknown | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | powershell.exe |
13/2/2020 - 1:45:57.887 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0 | |
13/2/2020 - 1:45:57.887 | Unknown | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0 | |
13/2/2020 - 1:45:57.887 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell | |
13/2/2020 - 1:45:57.887 | Unknown | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell | |
13/2/2020 - 1:45:57.903 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:45:57.903 | Unknown | 1480 | C:\malware.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:45:57.903 | Open | 1480 | C:\malware.exe | C:\Windows | |
13/2/2020 - 1:45:57.903 | Unknown | 1480 | C:\malware.exe | C:\Windows | |
13/2/2020 - 1:45:57.903 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | |
13/2/2020 - 1:45:57.903 | Unknown | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | powershell.exe |
13/2/2020 - 1:45:57.903 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | |
13/2/2020 - 1:45:57.903 | Unknown | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | powershell.exe |
13/2/2020 - 1:45:57.903 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | |
13/2/2020 - 1:45:57.903 | Unknown | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | powershell.exe |
13/2/2020 - 1:45:57.903 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe:Zone.Identifier | |
13/2/2020 - 1:45:57.903 | Open | 1480 | C:\malware.exe | C:\Monitor | |
13/2/2020 - 1:45:57.903 | Unknown | 1480 | C:\malware.exe | C:\Monitor | |
13/2/2020 - 1:45:57.903 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | |
13/2/2020 - 1:45:57.903 | Read | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | powershell.exe |
13/2/2020 - 1:45:57.965 | Read | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | powershell.exe |
13/2/2020 - 1:45:58.12 | Read | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | powershell.exe |
13/2/2020 - 1:45:58.59 | Read | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | powershell.exe |
13/2/2020 - 1:45:58.106 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\apphelp.dll | |
13/2/2020 - 1:45:58.106 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\apphelp.dll | |
13/2/2020 - 1:45:58.106 | Open | 1480 | C:\malware.exe | C:\Windows\AppPatch\sysmain.sdb | |
13/2/2020 - 1:45:58.106 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0 | |
13/2/2020 - 1:45:58.106 | Unknown | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0 | |
13/2/2020 - 1:45:58.106 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | |
13/2/2020 - 1:45:58.106 | Unknown | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | powershell.exe |
13/2/2020 - 1:45:58.106 | Open | 1480 | C:\malware.exe | C:\ | |
13/2/2020 - 1:45:58.106 | Unknown | 1480 | C:\malware.exe | C:\ | |
13/2/2020 - 1:45:58.106 | Open | 1480 | C:\malware.exe | C:\Windows | |
13/2/2020 - 1:45:58.106 | Unknown | 1480 | C:\malware.exe | C:\Windows | |
13/2/2020 - 1:45:58.106 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell | |
13/2/2020 - 1:45:58.106 | Unknown | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell | |
13/2/2020 - 1:45:58.106 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0 | |
13/2/2020 - 1:45:58.106 | Unknown | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0 | |
13/2/2020 - 1:45:58.106 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | |
13/2/2020 - 1:45:58.106 | Read | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | powershell.exe |
13/2/2020 - 1:45:58.106 | Read | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | powershell.exe |
13/2/2020 - 1:45:58.106 | Read | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | powershell.exe |
13/2/2020 - 1:45:58.106 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\ui\SwDRM.dll | |
13/2/2020 - 1:45:58.106 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\sfc.dll | |
13/2/2020 - 1:45:58.106 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\sfc.dll | |
13/2/2020 - 1:45:58.106 | Open | 1480 | C:\malware.exe | C:\sfc_os.DLL | |
13/2/2020 - 1:45:58.106 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\sfc_os.dll | |
13/2/2020 - 1:45:58.106 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\sfc_os.dll | |
13/2/2020 - 1:45:58.106 | Open | 1480 | C:\malware.exe | C:\Windows\winsxs\FileMaps\$$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms | |
13/2/2020 - 1:45:58.106 | Read | 1480 | C:\malware.exe | C:\Windows\winsxs\FileMaps\$$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms | $$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms |
13/2/2020 - 1:45:58.106 | Read | 1480 | C:\malware.exe | C:\Windows\winsxs\FileMaps\$$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms | $$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms |
13/2/2020 - 1:45:58.106 | Read | 1480 | C:\malware.exe | C:\Windows\winsxs\FileMaps\$$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms | $$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms |
13/2/2020 - 1:45:58.106 | Read | 1480 | C:\malware.exe | C:\Windows\winsxs\FileMaps\$$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms | $$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms |
13/2/2020 - 1:45:58.106 | Read | 1480 | C:\malware.exe | C:\Windows\winsxs\FileMaps\$$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms | $$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms |
13/2/2020 - 1:45:58.106 | Read | 1480 | C:\malware.exe | C:\Windows\winsxs\FileMaps\$$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms | $$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms |
13/2/2020 - 1:45:58.106 | Read | 1480 | C:\malware.exe | C:\Windows\winsxs\FileMaps\$$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms | $$_system32_windowspowershell_v1.0_3f102d555ee05d33.cdf-ms |
13/2/2020 - 1:45:58.106 | Unknown | 1480 | C:\malware.exe | C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d | |
13/2/2020 - 1:45:58.106 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Prefetch\POWERSHELL.EXE-767FB1AE.pf | |
13/2/2020 - 1:45:58.106 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows | |
13/2/2020 - 1:45:58.106 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\System32\wow64.dll | |
13/2/2020 - 1:45:58.122 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\System32\wow64.dll | |
13/2/2020 - 1:45:58.122 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\System32\wow64win.dll | |
13/2/2020 - 1:45:58.122 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\System32\wow64win.dll | |
13/2/2020 - 1:45:58.122 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\System32\wow64cpu.dll | |
13/2/2020 - 1:45:58.122 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\System32\wow64cpu.dll | |
13/2/2020 - 1:45:58.122 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\System32\wow64log.dll | |
13/2/2020 - 1:45:58.122 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows | |
13/2/2020 - 1:45:58.122 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows | |
13/2/2020 - 1:45:58.122 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor | |
13/2/2020 - 1:45:58.122 | Unknown | 1480 | C:\malware.exe | C:\Windows | |
13/2/2020 - 1:45:58.122 | Unknown | 1480 | C:\malware.exe | C:\Monitor | |
13/2/2020 - 1:45:58.122 | Unknown | 1480 | C:\malware.exe | C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d | |
13/2/2020 - 1:45:58.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\sechost.dll | |
13/2/2020 - 1:45:58.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\sechost.dll | |
13/2/2020 - 1:45:58.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\ATL.DLL | |
13/2/2020 - 1:45:58.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\atl.dll | |
13/2/2020 - 1:45:58.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\atl.dll | |
13/2/2020 - 1:45:58.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\mscoree.dll | |
13/2/2020 - 1:45:58.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\mscoree.dll | |
13/2/2020 - 1:45:58.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\mscoree.dll | |
13/2/2020 - 1:45:58.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\imm32.dll | |
13/2/2020 - 1:45:58.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\imm32.dll | |
13/2/2020 - 1:45:58.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\imm32.dll | |
13/2/2020 - 1:45:58.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\imm32.dll | |
13/2/2020 - 1:45:58.356 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\imm32.dll | |
13/2/2020 - 1:45:58.356 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\imm32.dll | |
13/2/2020 - 1:45:58.356 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\pt-BR\powershell.exe.mui | |
13/2/2020 - 1:45:58.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\pt-BR\powershell.exe.mui | powershell.exe.mui |
13/2/2020 - 1:45:58.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\rpcss.dll | |
13/2/2020 - 1:45:58.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\rpcss.dll | |
13/2/2020 - 1:45:58.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\uxtheme.dll | |
13/2/2020 - 1:45:58.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\uxtheme.dll | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe.Local | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d | |
13/2/2020 - 1:45:58.450 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d\comctl32.dll | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d\comctl32.dll | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\WindowsShell.Manifest | |
13/2/2020 - 1:45:58.450 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\WindowsShell.Manifest | WindowsShell.Manifest |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Globalization\Sorting\SortDefault.nls | |
13/2/2020 - 1:45:58.450 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Globalization\Sorting\SortDefault.nls | SortDefault.nls |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup | |
13/2/2020 - 1:45:58.450 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup | |
13/2/2020 - 1:45:58.450 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | |
13/2/2020 - 1:45:58.450 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | powershell.exe |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.450 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows | |
13/2/2020 - 1:45:58.450 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell | |
13/2/2020 - 1:45:58.450 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu | |
13/2/2020 - 1:45:58.450 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.450 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\propsys.dll | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\propsys.dll | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches\cversions.1.db | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches\cversions.1.db | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000000.db | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\desktop.ini | |
13/2/2020 - 1:45:58.450 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\desktop.ini | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users | |
13/2/2020 - 1:45:58.450 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot | |
13/2/2020 - 1:45:58.450 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData | |
13/2/2020 - 1:45:58.450 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming | |
13/2/2020 - 1:45:58.450 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\desktop.ini | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft | |
13/2/2020 - 1:45:58.450 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows | |
13/2/2020 - 1:45:58.450 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows | |
13/2/2020 - 1:45:58.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini | |
13/2/2020 - 1:45:58.465 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini | |
13/2/2020 - 1:45:58.465 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\Desktop\desktop.ini | |
13/2/2020 - 1:45:58.465 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\Desktop\desktop.ini | |
13/2/2020 - 1:45:58.465 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\Desktop\desktop.ini | |
13/2/2020 - 1:45:58.465 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs | |
13/2/2020 - 1:45:58.465 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs | |
13/2/2020 - 1:45:58.465 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.465 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.465 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users | |
13/2/2020 - 1:45:58.465 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users | |
13/2/2020 - 1:45:58.465 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot | |
13/2/2020 - 1:45:58.465 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot | |
13/2/2020 - 1:45:58.465 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData | |
13/2/2020 - 1:45:58.465 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData | |
13/2/2020 - 1:45:58.465 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming | |
13/2/2020 - 1:45:58.465 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming | |
13/2/2020 - 1:45:58.465 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft | |
13/2/2020 - 1:45:58.465 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft | |
13/2/2020 - 1:45:58.465 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows | |
13/2/2020 - 1:45:58.465 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows | |
13/2/2020 - 1:45:58.465 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu | |
13/2/2020 - 1:45:58.465 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu | |
13/2/2020 - 1:45:58.465 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini | |
13/2/2020 - 1:45:58.465 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini | |
13/2/2020 - 1:45:58.465 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu | |
13/2/2020 - 1:45:58.465 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu | |
13/2/2020 - 1:45:58.465 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.465 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.465 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData | |
13/2/2020 - 1:45:58.465 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData | |
13/2/2020 - 1:45:58.465 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\desktop.ini | |
13/2/2020 - 1:45:58.465 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft | |
13/2/2020 - 1:45:58.465 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft | |
13/2/2020 - 1:45:58.465 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows | |
13/2/2020 - 1:45:58.465 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows | |
13/2/2020 - 1:45:58.465 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini | |
13/2/2020 - 1:45:58.465 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini | |
13/2/2020 - 1:45:58.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs | |
13/2/2020 - 1:45:58.481 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs | |
13/2/2020 - 1:45:58.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.481 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData | |
13/2/2020 - 1:45:58.481 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData | |
13/2/2020 - 1:45:58.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft | |
13/2/2020 - 1:45:58.481 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft | |
13/2/2020 - 1:45:58.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows | |
13/2/2020 - 1:45:58.481 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows | |
13/2/2020 - 1:45:58.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu | |
13/2/2020 - 1:45:58.481 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu | |
13/2/2020 - 1:45:58.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini | |
13/2/2020 - 1:45:58.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini | |
13/2/2020 - 1:45:58.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\Desktop | |
13/2/2020 - 1:45:58.481 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\Desktop | |
13/2/2020 - 1:45:58.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.481 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users | |
13/2/2020 - 1:45:58.481 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users | |
13/2/2020 - 1:45:58.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot | |
13/2/2020 - 1:45:58.497 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot | |
13/2/2020 - 1:45:58.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Public\Desktop | |
13/2/2020 - 1:45:58.497 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Public\Desktop | |
13/2/2020 - 1:45:58.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.497 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users | |
13/2/2020 - 1:45:58.497 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users | |
13/2/2020 - 1:45:58.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Public\desktop.ini | |
13/2/2020 - 1:45:58.497 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Public\desktop.ini | |
13/2/2020 - 1:45:58.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Public | |
13/2/2020 - 1:45:58.497 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Public | |
13/2/2020 - 1:45:58.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Public\Desktop\desktop.ini | |
13/2/2020 - 1:45:58.497 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Public\Desktop\desktop.ini | |
13/2/2020 - 1:45:58.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\apphelp.dll | |
13/2/2020 - 1:45:58.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\apphelp.dll | |
13/2/2020 - 1:45:58.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\apphelp.dll | |
13/2/2020 - 1:45:58.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\gameux.dll | |
13/2/2020 - 1:45:58.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\AppPatch\sysmain.sdb | |
13/2/2020 - 1:45:58.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:45:58.497 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:45:58.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\gameux.dll | |
13/2/2020 - 1:45:58.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.497 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows | |
13/2/2020 - 1:45:58.497 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows | |
13/2/2020 - 1:45:58.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:45:58.497 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:45:58.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:45:58.497 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:45:58.512 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\gameux.dll | |
13/2/2020 - 1:45:58.512 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\gameux.dll | |
13/2/2020 - 1:45:58.512 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\gameux.dll | |
13/2/2020 - 1:45:58.512 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\gameux.dll | |
13/2/2020 - 1:45:58.512 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\gameux.dll | |
13/2/2020 - 1:45:58.512 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\gameux.dll | |
13/2/2020 - 1:45:58.512 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\gameux.dll | |
13/2/2020 - 1:45:58.512 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\gameux.dll | |
13/2/2020 - 1:45:58.512 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\gameux.dll | |
13/2/2020 - 1:45:58.528 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\gameux.dll | |
13/2/2020 - 1:45:58.528 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\gameux.dll | |
13/2/2020 - 1:45:58.528 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\gameux.dll | |
13/2/2020 - 1:45:58.575 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe.Local | |
13/2/2020 - 1:45:58.575 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d | |
13/2/2020 - 1:45:58.575 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d | |
13/2/2020 - 1:45:58.575 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d | |
13/2/2020 - 1:45:58.575 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe.Local | |
13/2/2020 - 1:45:58.575 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_5c02a2f5a011f9be | |
13/2/2020 - 1:45:58.575 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_5c02a2f5a011f9be | |
13/2/2020 - 1:45:58.575 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_5c02a2f5a011f9be | |
13/2/2020 - 1:45:58.575 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_5c02a2f5a011f9be\GdiPlus.dll | |
13/2/2020 - 1:45:58.575 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.23407_none_5c02a2f5a011f9be\GdiPlus.dll | |
13/2/2020 - 1:45:58.575 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\xmllite.dll | |
13/2/2020 - 1:45:58.575 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\xmllite.dll | |
13/2/2020 - 1:45:58.575 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wer.dll | |
13/2/2020 - 1:45:58.575 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wer.dll | |
13/2/2020 - 1:45:58.590 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\gameux.dll | |
13/2/2020 - 1:45:58.590 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\gameux.dll | |
13/2/2020 - 1:45:58.590 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\gameux.dll | |
13/2/2020 - 1:45:58.590 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\gameux.dll | |
13/2/2020 - 1:45:58.590 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\gameux.dll | |
13/2/2020 - 1:45:58.590 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\gameux.dll | |
13/2/2020 - 1:45:58.590 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\gameux.dll | |
13/2/2020 - 1:45:58.590 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\gameux.dll | |
13/2/2020 - 1:45:58.590 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\gameux.dll | |
13/2/2020 - 1:45:58.606 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\gameux.dll | |
13/2/2020 - 1:45:58.606 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\gameux.dll | |
13/2/2020 - 1:45:58.606 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\gameux.dll | |
13/2/2020 - 1:45:58.606 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned | |
13/2/2020 - 1:45:58.606 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned | |
13/2/2020 - 1:45:58.606 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.606 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.606 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users | |
13/2/2020 - 1:45:58.606 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users | |
13/2/2020 - 1:45:58.606 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot | |
13/2/2020 - 1:45:58.606 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot | |
13/2/2020 - 1:45:58.606 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData | |
13/2/2020 - 1:45:58.606 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData | |
13/2/2020 - 1:45:58.606 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming | |
13/2/2020 - 1:45:58.606 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming | |
13/2/2020 - 1:45:58.606 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft | |
13/2/2020 - 1:45:58.606 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft | |
13/2/2020 - 1:45:58.606 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer | |
13/2/2020 - 1:45:58.606 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer | |
13/2/2020 - 1:45:58.606 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini | |
13/2/2020 - 1:45:58.606 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini | |
13/2/2020 - 1:45:58.606 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch | |
13/2/2020 - 1:45:58.606 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch | |
13/2/2020 - 1:45:58.606 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shdocvw.dll | |
13/2/2020 - 1:45:58.606 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\AppPatch\sysmain.sdb | |
13/2/2020 - 1:45:58.606 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:45:58.606 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:45:58.606 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shdocvw.dll | |
13/2/2020 - 1:45:58.606 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.622 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.622 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows | |
13/2/2020 - 1:45:58.622 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows | |
13/2/2020 - 1:45:58.622 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:45:58.622 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:45:58.622 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:45:58.622 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:45:58.622 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shdocvw.dll | |
13/2/2020 - 1:45:58.622 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shdocvw.dll | |
13/2/2020 - 1:45:58.622 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shdocvw.dll | |
13/2/2020 - 1:45:58.622 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shdocvw.dll | |
13/2/2020 - 1:45:58.622 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shdocvw.dll | |
13/2/2020 - 1:45:58.622 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shdocvw.dll | |
13/2/2020 - 1:45:58.622 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shdocvw.dll | |
13/2/2020 - 1:45:58.622 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shdocvw.dll | |
13/2/2020 - 1:45:58.637 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shdocvw.dll | |
13/2/2020 - 1:45:58.637 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shdocvw.dll | |
13/2/2020 - 1:45:58.637 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shdocvw.dll | |
13/2/2020 - 1:45:58.637 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.637 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.637 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users | |
13/2/2020 - 1:45:58.637 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users | |
13/2/2020 - 1:45:58.637 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot | |
13/2/2020 - 1:45:58.637 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot | |
13/2/2020 - 1:45:58.637 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData | |
13/2/2020 - 1:45:58.637 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData | |
13/2/2020 - 1:45:58.637 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming | |
13/2/2020 - 1:45:58.637 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming | |
13/2/2020 - 1:45:58.637 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft | |
13/2/2020 - 1:45:58.637 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft | |
13/2/2020 - 1:45:58.637 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer | |
13/2/2020 - 1:45:58.637 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer | |
13/2/2020 - 1:45:58.637 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch | |
13/2/2020 - 1:45:58.637 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch | |
13/2/2020 - 1:45:58.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations | |
13/2/2020 - 1:45:58.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | |
13/2/2020 - 1:45:58.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:45:58.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:45:58.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk | |
13/2/2020 - 1:45:58.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk\desktop.ini | |
13/2/2020 - 1:45:58.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk\desktop.ini | |
13/2/2020 - 1:45:58.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.731 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData | |
13/2/2020 - 1:45:58.731 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData | |
13/2/2020 - 1:45:58.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft | |
13/2/2020 - 1:45:58.731 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft | |
13/2/2020 - 1:45:58.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows | |
13/2/2020 - 1:45:58.731 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows | |
13/2/2020 - 1:45:58.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu | |
13/2/2020 - 1:45:58.731 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu | |
13/2/2020 - 1:45:58.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs | |
13/2/2020 - 1:45:58.731 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs | |
13/2/2020 - 1:45:58.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini | |
13/2/2020 - 1:45:58.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini | |
13/2/2020 - 1:45:58.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories | |
13/2/2020 - 1:45:58.731 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories | |
13/2/2020 - 1:45:58.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\desktop.ini | |
13/2/2020 - 1:45:58.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\desktop.ini | |
13/2/2020 - 1:45:58.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell | |
13/2/2020 - 1:45:58.731 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell | |
13/2/2020 - 1:45:58.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\LINKINFO.dll | |
13/2/2020 - 1:45:58.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\linkinfo.dll | |
13/2/2020 - 1:45:58.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\linkinfo.dll | |
13/2/2020 - 1:45:58.747 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.747 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.747 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\ntshrui.dll | |
13/2/2020 - 1:45:58.747 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\ntshrui.dll | |
13/2/2020 - 1:45:58.747 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\ntshrui.dll | |
13/2/2020 - 1:45:58.747 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\srvcli.dll | |
13/2/2020 - 1:45:58.747 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\srvcli.dll | |
13/2/2020 - 1:45:58.747 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\srvcli.dll | |
13/2/2020 - 1:45:58.793 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\cscapi.dll | |
13/2/2020 - 1:45:58.793 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\cscapi.dll | |
13/2/2020 - 1:45:58.793 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\cscapi.dll | |
13/2/2020 - 1:45:58.793 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\slc.dll | |
13/2/2020 - 1:45:58.793 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\slc.dll | |
13/2/2020 - 1:45:58.793 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\slc.dll | |
13/2/2020 - 1:45:58.793 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk | |
13/2/2020 - 1:45:58.856 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell | |
13/2/2020 - 1:45:58.856 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell | |
13/2/2020 - 1:45:58.856 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell | |
13/2/2020 - 1:45:58.856 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell | |
13/2/2020 - 1:45:58.856 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell | |
13/2/2020 - 1:45:58.856 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk | Windows PowerShell.lnk |
13/2/2020 - 1:45:58.856 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.856 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.856 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData | |
13/2/2020 - 1:45:58.856 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData | |
13/2/2020 - 1:45:58.856 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft | |
13/2/2020 - 1:45:58.856 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft | |
13/2/2020 - 1:45:58.856 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows | |
13/2/2020 - 1:45:58.856 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows | |
13/2/2020 - 1:45:58.856 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu | |
13/2/2020 - 1:45:58.856 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu | |
13/2/2020 - 1:45:58.856 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs | |
13/2/2020 - 1:45:58.856 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs | |
13/2/2020 - 1:45:58.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories | |
13/2/2020 - 1:45:58.872 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories | |
13/2/2020 - 1:45:58.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell | |
13/2/2020 - 1:45:58.872 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell | |
13/2/2020 - 1:45:58.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.872 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk | |
13/2/2020 - 1:45:58.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell | |
13/2/2020 - 1:45:58.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell | |
13/2/2020 - 1:45:58.872 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell | |
13/2/2020 - 1:45:58.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell | |
13/2/2020 - 1:45:58.872 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell | |
13/2/2020 - 1:45:58.872 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk | Windows PowerShell.lnk |
13/2/2020 - 1:45:58.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0 | |
13/2/2020 - 1:45:58.872 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0 | |
13/2/2020 - 1:45:58.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.872 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows | |
13/2/2020 - 1:45:58.872 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows | |
13/2/2020 - 1:45:58.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:45:58.872 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:45:58.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell | |
13/2/2020 - 1:45:58.872 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell | |
13/2/2020 - 1:45:58.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0 | |
13/2/2020 - 1:45:58.872 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0 | |
13/2/2020 - 1:45:58.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.872 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell_ise.exe | |
13/2/2020 - 1:45:58.934 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0 | |
13/2/2020 - 1:45:58.934 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0 | |
13/2/2020 - 1:45:58.934 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0 | |
13/2/2020 - 1:45:58.934 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0 | |
13/2/2020 - 1:45:58.934 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0 | |
13/2/2020 - 1:45:58.934 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell_ise.exe | powershell_ise.exe |
13/2/2020 - 1:45:58.934 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.950 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.950 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows | |
13/2/2020 - 1:45:58.950 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows | |
13/2/2020 - 1:45:58.950 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.950 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:45:58.950 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\hh.exe | |
13/2/2020 - 1:45:58.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows | |
13/2/2020 - 1:45:58.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows | |
13/2/2020 - 1:45:58.997 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows | |
13/2/2020 - 1:45:58.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows | |
13/2/2020 - 1:45:58.997 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows | |
13/2/2020 - 1:45:58.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations | |
13/2/2020 - 1:45:58.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\CRYPTSP.dll | |
13/2/2020 - 1:45:58.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\cryptsp.dll | |
13/2/2020 - 1:45:58.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\cryptsp.dll | |
13/2/2020 - 1:45:58.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\rsaenh.dll | |
13/2/2020 - 1:45:58.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\rsaenh.dll | |
13/2/2020 - 1:45:58.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\rsaenh.dll | |
13/2/2020 - 1:45:58.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\rsaenh.dll | |
13/2/2020 - 1:45:58.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\rsaenh.dll | |
13/2/2020 - 1:45:58.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\rsaenh.dll | |
13/2/2020 - 1:45:58.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\rsaenh.dll | |
13/2/2020 - 1:45:58.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\rsaenh.dll | |
13/2/2020 - 1:45:58.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\rsaenh.dll | |
13/2/2020 - 1:45:58.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\rsaenh.dll | |
13/2/2020 - 1:45:59.12 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\rsaenh.dll | |
13/2/2020 - 1:45:59.12 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\rsaenh.dll | |
13/2/2020 - 1:45:59.12 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\CQBOKRJMUVFY9O8WED7G.temp | |
13/2/2020 - 1:45:59.12 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\CQBOKRJMUVFY9O8WED7G.temp | |
13/2/2020 - 1:45:59.12 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\CQBOKRJMUVFY9O8WED7G.temp | CQBOKRJMUVFY9O8WED7G.temp |
13/2/2020 - 1:45:59.12 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\CQBOKRJMUVFY9O8WED7G.temp | CQBOKRJMUVFY9O8WED7G.temp |
13/2/2020 - 1:45:59.12 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\CQBOKRJMUVFY9O8WED7G.temp | CQBOKRJMUVFY9O8WED7G.temp |
13/2/2020 - 1:45:59.12 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\CQBOKRJMUVFY9O8WED7G.temp | CQBOKRJMUVFY9O8WED7G.temp |
13/2/2020 - 1:45:59.12 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | |
13/2/2020 - 1:45:59.12 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\CQBOKRJMUVFY9O8WED7G.temp | |
13/2/2020 - 1:45:59.12 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations | |
13/2/2020 - 1:45:59.12 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\CQBOKRJMUVFY9O8WED7G.temp | CQBOKRJMUVFY9O8WED7G.temp |
13/2/2020 - 1:45:59.12 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations | |
13/2/2020 - 1:45:59.75 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d | |
13/2/2020 - 1:45:59.137 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\mscoree.dll.local | |
13/2/2020 - 1:45:59.137 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727 | |
13/2/2020 - 1:45:59.137 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727 | |
13/2/2020 - 1:45:59.137 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\Upgrades.2.0.50727 | |
13/2/2020 - 1:45:59.137 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\Upgrades.2.0.50727 | |
13/2/2020 - 1:45:59.137 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe.config | |
13/2/2020 - 1:45:59.137 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727 | |
13/2/2020 - 1:45:59.137 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727 | |
13/2/2020 - 1:45:59.137 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll | |
13/2/2020 - 1:45:59.184 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll | |
13/2/2020 - 1:46:0.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll | |
13/2/2020 - 1:46:0.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe.Local | |
13/2/2020 - 1:46:0.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc | |
13/2/2020 - 1:46:0.403 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc | |
13/2/2020 - 1:46:0.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc | |
13/2/2020 - 1:46:0.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll | |
13/2/2020 - 1:46:0.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll | |
13/2/2020 - 1:46:0.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll | |
13/2/2020 - 1:46:0.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:46:0.403 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:46:0.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows | |
13/2/2020 - 1:46:0.403 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows | |
13/2/2020 - 1:46:0.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc | |
13/2/2020 - 1:46:0.403 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc | |
13/2/2020 - 1:46:0.434 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | |
13/2/2020 - 1:46:0.434 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | machine.config |
13/2/2020 - 1:46:0.434 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | machine.config |
13/2/2020 - 1:46:0.434 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | machine.config |
13/2/2020 - 1:46:0.434 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | machine.config |
13/2/2020 - 1:46:0.434 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | machine.config |
13/2/2020 - 1:46:0.434 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | machine.config |
13/2/2020 - 1:46:0.434 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe.config | |
13/2/2020 - 1:46:0.434 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\fusion.localgac | |
13/2/2020 - 1:46:0.434 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config | |
13/2/2020 - 1:46:0.434 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch | |
13/2/2020 - 1:46:0.434 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config | |
13/2/2020 - 1:46:0.434 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch | |
13/2/2020 - 1:46:0.434 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot | |
13/2/2020 - 1:46:0.434 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot | |
13/2/2020 - 1:46:0.434 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot | |
13/2/2020 - 1:46:0.434 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming | |
13/2/2020 - 1:46:0.434 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming | |
13/2/2020 - 1:46:0.434 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming | |
13/2/2020 - 1:46:0.434 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config | |
13/2/2020 - 1:46:0.434 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch | |
13/2/2020 - 1:46:0.434 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\index164.dat | |
13/2/2020 - 1:46:0.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | |
13/2/2020 - 1:46:0.543 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:0.543 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | |
13/2/2020 - 1:46:0.543 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:0.590 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:0.637 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:0.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:0.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:0.778 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:0.825 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:0.872 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:0.918 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:0.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:1.12 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:1.59 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:1.106 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:1.153 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:1.200 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:1.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:1.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:1.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:1.387 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:1.434 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:1.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:1.528 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:1.575 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:1.622 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:1.668 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:1.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:1.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:1.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:1.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:1.903 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:1.997 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:2.43 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:2.137 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:2.184 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:2.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:2.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:2.372 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089 | |
13/2/2020 - 1:46:2.418 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089 | |
13/2/2020 - 1:46:2.465 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089 | |
13/2/2020 - 1:46:2.465 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:2.512 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:2.559 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:2.606 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:2.653 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:2.700 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:2.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:2.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:2.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:2.887 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:2.934 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:2.981 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:3.122 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:3.262 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:3.309 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:3.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:3.403 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:3.450 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:3.590 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:3.637 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:3.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:3.778 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:3.825 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:3.872 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:3.918 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll | |
13/2/2020 - 1:46:3.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:4.12 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:4.59 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:4.106 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:4.153 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:4.200 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:4.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:4.387 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:4.434 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:4.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:4.528 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:4.622 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:4.668 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:4.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:4.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:4.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:4.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:4.903 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:4.950 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:4.997 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:5.43 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:5.90 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:5.137 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:5.184 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:5.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:5.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:5.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:5.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:5.418 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:5.465 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:5.559 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:5.606 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:5.653 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:5.700 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:5.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:5.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:5.887 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:5.934 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:5.981 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:6.28 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:6.75 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:6.122 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:6.168 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:6.262 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:6.309 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:6.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:6.403 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:6.450 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:6.497 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:6.543 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:6.590 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:6.637 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:6.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:6.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:6.778 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:6.825 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:6.872 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:6.918 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\OLEAUT32.dll | |
13/2/2020 - 1:46:6.918 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:7.575 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:7.668 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:7.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:7.856 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Globalization\pt-br.nlp | |
13/2/2020 - 1:46:7.856 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.config | |
13/2/2020 - 1:46:7.856 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\pubpol4.dat | |
13/2/2020 - 1:46:7.856 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC\PublisherPolicy.tme | |
13/2/2020 - 1:46:7.856 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | |
13/2/2020 - 1:46:7.856 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | machine.config |
13/2/2020 - 1:46:7.856 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | |
13/2/2020 - 1:46:7.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | machine.config |
13/2/2020 - 1:46:7.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | machine.config |
13/2/2020 - 1:46:7.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | machine.config |
13/2/2020 - 1:46:7.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | machine.config |
13/2/2020 - 1:46:7.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | machine.config |
13/2/2020 - 1:46:7.950 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:8.184 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:8.184 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll | |
13/2/2020 - 1:46:8.231 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll | Microsoft.PowerShell.ConsoleHost.dll |
13/2/2020 - 1:46:8.231 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll | |
13/2/2020 - 1:46:8.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll | Microsoft.PowerShell.ConsoleHost.dll |
13/2/2020 - 1:46:8.309 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll | Microsoft.PowerShell.ConsoleHost.dll |
13/2/2020 - 1:46:8.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll | Microsoft.PowerShell.ConsoleHost.dll |
13/2/2020 - 1:46:8.403 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll | Microsoft.PowerShell.ConsoleHost.dll |
13/2/2020 - 1:46:8.450 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll | Microsoft.PowerShell.ConsoleHost.dll |
13/2/2020 - 1:46:8.497 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll | Microsoft.PowerShell.ConsoleHost.dll |
13/2/2020 - 1:46:8.543 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll | Microsoft.PowerShell.ConsoleHost.dll |
13/2/2020 - 1:46:8.637 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:8.637 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:8.684 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Management.Automation\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:8.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:8.872 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:8.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | |
13/2/2020 - 1:46:8.918 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:8.918 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | |
13/2/2020 - 1:46:8.918 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:8.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:9.12 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:9.59 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:9.106 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:9.153 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:9.200 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:9.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:9.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:9.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:9.387 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:9.434 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:9.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:9.528 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll | |
13/2/2020 - 1:46:9.528 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll | |
13/2/2020 - 1:46:9.528 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll | Microsoft.PowerShell.ConsoleHost.dll |
13/2/2020 - 1:46:9.528 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll | |
13/2/2020 - 1:46:9.528 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll | Microsoft.PowerShell.ConsoleHost.dll |
13/2/2020 - 1:46:9.528 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll | Microsoft.PowerShell.ConsoleHost.dll |
13/2/2020 - 1:46:9.622 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:9.668 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:9.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:9.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:9.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:10.59 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll | Microsoft.PowerShell.ConsoleHost.dll |
13/2/2020 - 1:46:10.153 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll | |
13/2/2020 - 1:46:10.200 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll | |
13/2/2020 - 1:46:10.387 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll | |
13/2/2020 - 1:46:10.387 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe.Local | |
13/2/2020 - 1:46:10.387 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc | |
13/2/2020 - 1:46:10.387 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc | |
13/2/2020 - 1:46:10.387 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc | |
13/2/2020 - 1:46:10.387 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:10.387 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:10.387 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:10.387 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:10.387 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:10.387 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:10.450 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:10.497 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:10.590 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:10.637 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:10.778 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:10.825 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:10.825 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:10.825 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:10.872 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:10.918 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:10.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:11.12 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:11.59 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:11.106 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:11.153 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:11.200 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:11.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:11.293 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | |
13/2/2020 - 1:46:11.293 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | |
13/2/2020 - 1:46:11.293 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:11.293 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | |
13/2/2020 - 1:46:11.293 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:11.293 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:11.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:11.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:11.387 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:11.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\BVTBin\Tests\installpackage\csilogfile.log | |
13/2/2020 - 1:46:11.528 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:11.575 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:11.622 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:11.668 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:11.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:11.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:11.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:11.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:11.903 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:11.950 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:11.997 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:12.43 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:12.90 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:12.137 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:12.231 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | |
13/2/2020 - 1:46:12.372 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:12.372 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | |
13/2/2020 - 1:46:12.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:12.418 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:12.465 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:12.512 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:12.559 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:12.606 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:12.653 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:12.700 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:12.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:12.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:12.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:12.887 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:12.934 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:12.981 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:13.28 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:13.75 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:13.122 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:13.168 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:13.215 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:13.262 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:13.309 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:13.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:13.403 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:13.450 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:13.497 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:13.543 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089 | |
13/2/2020 - 1:46:13.637 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089 | |
13/2/2020 - 1:46:13.637 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:13.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:13.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:13.778 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:13.825 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:13.872 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:13.918 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:13.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:14.12 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:14.59 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:14.106 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:14.153 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:14.200 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:14.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:14.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:14.387 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:14.434 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:14.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:14.528 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:14.575 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:14.622 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:14.668 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:14.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:14.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:14.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:14.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:14.903 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:14.950 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:14.997 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:15.43 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:15.90 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:15.137 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:15.184 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:15.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:15.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:15.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:15.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:15.418 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:15.465 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:15.512 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:15.559 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:15.606 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:15.653 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:15.700 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:15.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:15.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:15.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:15.887 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:15.934 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:15.981 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:16.28 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:16.75 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:16.122 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:16.168 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | |
13/2/2020 - 1:46:16.168 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:16.168 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\version.dll | |
13/2/2020 - 1:46:16.168 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\version.dll | |
13/2/2020 - 1:46:16.168 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\version.dll | |
13/2/2020 - 1:46:16.168 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | |
13/2/2020 - 1:46:16.168 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:16.168 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:16.215 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:16.262 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | |
13/2/2020 - 1:46:16.262 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:16.262 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:16.309 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:16.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:16.450 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\l_intl.nls | |
13/2/2020 - 1:46:16.543 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\pt-BR\KernelBase.dll.mui | |
13/2/2020 - 1:46:16.543 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:16.590 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:16.637 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:16.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:16.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:16.778 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:16.825 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:16.872 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:16.918 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:16.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:17.12 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:17.59 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:17.106 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:17.153 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:17.200 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:17.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:17.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:17.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:17.387 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:17.434 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:17.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:17.528 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:17.575 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:17.622 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll | |
13/2/2020 - 1:46:17.622 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:17.668 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:17.715 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ntdll.dll | |
13/2/2020 - 1:46:17.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:17.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:17.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:17.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:17.903 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:17.950 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:17.997 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:18.43 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.90 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.137 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.184 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:18.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.278 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089 | |
13/2/2020 - 1:46:18.278 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp | |
13/2/2020 - 1:46:18.278 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp | |
13/2/2020 - 1:46:18.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:18.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:18.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:18.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:18.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:18.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:18.278 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | |
13/2/2020 - 1:46:18.293 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089 | |
13/2/2020 - 1:46:18.293 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089 | |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:18.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:18.309 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.309 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.309 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:18.309 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:18.309 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.309 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:18.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:18.403 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.450 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | |
13/2/2020 - 1:46:18.497 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:18.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | |
13/2/2020 - 1:46:18.497 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:18.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | |
13/2/2020 - 1:46:18.497 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:18.497 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:18.543 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:18.590 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:18.637 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:18.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.778 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.825 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.872 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.918 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:18.965 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:19.59 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:19.59 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll | |
13/2/2020 - 1:46:19.106 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll | Microsoft.PowerShell.Commands.Diagnostics.dll |
13/2/2020 - 1:46:19.106 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll | |
13/2/2020 - 1:46:19.106 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll | Microsoft.PowerShell.Commands.Diagnostics.dll |
13/2/2020 - 1:46:19.153 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll | Microsoft.PowerShell.Commands.Diagnostics.dll |
13/2/2020 - 1:46:19.200 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll | Microsoft.PowerShell.Commands.Diagnostics.dll |
13/2/2020 - 1:46:19.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll | Microsoft.PowerShell.Commands.Diagnostics.dll |
13/2/2020 - 1:46:19.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll | Microsoft.PowerShell.Commands.Diagnostics.dll |
13/2/2020 - 1:46:19.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll | Microsoft.PowerShell.Commands.Diagnostics.dll |
13/2/2020 - 1:46:19.387 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:19.387 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:19.387 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Core\3.5.0.0__b77a5c561934e089 | |
13/2/2020 - 1:46:19.387 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089 | |
13/2/2020 - 1:46:19.481 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089 | |
13/2/2020 - 1:46:19.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll | |
13/2/2020 - 1:46:19.528 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll | System.Core.dll |
13/2/2020 - 1:46:19.528 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll | |
13/2/2020 - 1:46:19.528 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll | System.Core.dll |
13/2/2020 - 1:46:19.575 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll | System.Core.dll |
13/2/2020 - 1:46:19.622 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll | System.Core.dll |
13/2/2020 - 1:46:19.668 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll | System.Core.dll |
13/2/2020 - 1:46:19.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll | System.Core.dll |
13/2/2020 - 1:46:19.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll | System.Core.dll |
13/2/2020 - 1:46:19.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll | System.Core.dll |
13/2/2020 - 1:46:19.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll | System.Core.dll |
13/2/2020 - 1:46:19.903 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll | System.Core.dll |
13/2/2020 - 1:46:19.950 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll | System.Core.dll |
13/2/2020 - 1:46:19.997 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.dll | System.Core.dll |
13/2/2020 - 1:46:20.43 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll | |
13/2/2020 - 1:46:20.43 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll | |
13/2/2020 - 1:46:20.43 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll | Microsoft.PowerShell.Commands.Diagnostics.dll |
13/2/2020 - 1:46:20.43 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll | |
13/2/2020 - 1:46:20.43 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll | Microsoft.PowerShell.Commands.Diagnostics.dll |
13/2/2020 - 1:46:20.43 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Diagnostics\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Diagnostics.dll | Microsoft.PowerShell.Commands.Diagnostics.dll |
13/2/2020 - 1:46:20.43 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:20.90 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:20.137 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\f1fdabccbbc596710f24607662898d06\System.Configuration.Install.ni.dll | |
13/2/2020 - 1:46:20.184 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\f1fdabccbbc596710f24607662898d06\System.Configuration.Install.ni.dll | System.Configuration.Install.ni.dll |
13/2/2020 - 1:46:20.184 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\f1fdabccbbc596710f24607662898d06\System.Configuration.Install.ni.dll | |
13/2/2020 - 1:46:20.184 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\f1fdabccbbc596710f24607662898d06\System.Configuration.Install.ni.dll | System.Configuration.Install.ni.dll |
13/2/2020 - 1:46:20.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\f1fdabccbbc596710f24607662898d06\System.Configuration.Install.ni.dll | System.Configuration.Install.ni.dll |
13/2/2020 - 1:46:20.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\f1fdabccbbc596710f24607662898d06\System.Configuration.Install.ni.dll | System.Configuration.Install.ni.dll |
13/2/2020 - 1:46:20.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\f1fdabccbbc596710f24607662898d06\System.Configuration.Install.ni.dll | System.Configuration.Install.ni.dll |
13/2/2020 - 1:46:20.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\f1fdabccbbc596710f24607662898d06\System.Configuration.Install.ni.dll | System.Configuration.Install.ni.dll |
13/2/2020 - 1:46:20.418 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a | |
13/2/2020 - 1:46:20.465 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a | |
13/2/2020 - 1:46:20.465 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\f1fdabccbbc596710f24607662898d06\System.Configuration.Install.ni.dll | System.Configuration.Install.ni.dll |
13/2/2020 - 1:46:20.512 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\f1fdabccbbc596710f24607662898d06\System.Configuration.Install.ni.dll | System.Configuration.Install.ni.dll |
13/2/2020 - 1:46:20.559 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\f1fdabccbbc596710f24607662898d06\System.Configuration.Install.ni.dll | System.Configuration.Install.ni.dll |
13/2/2020 - 1:46:20.606 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\f1fdabccbbc596710f24607662898d06\System.Configuration.Install.ni.dll | System.Configuration.Install.ni.dll |
13/2/2020 - 1:46:20.653 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:20.700 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\f1fdabccbbc596710f24607662898d06\System.Configuration.Install.ni.dll | System.Configuration.Install.ni.dll |
13/2/2020 - 1:46:20.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:20.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:20.903 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:21.43 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:21.43 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll | |
13/2/2020 - 1:46:21.90 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll | Microsoft.WSMan.Management.dll |
13/2/2020 - 1:46:21.90 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll | |
13/2/2020 - 1:46:21.90 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll | Microsoft.WSMan.Management.dll |
13/2/2020 - 1:46:21.137 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll | Microsoft.WSMan.Management.dll |
13/2/2020 - 1:46:21.184 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll | Microsoft.WSMan.Management.dll |
13/2/2020 - 1:46:21.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll | Microsoft.WSMan.Management.dll |
13/2/2020 - 1:46:21.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll | Microsoft.WSMan.Management.dll |
13/2/2020 - 1:46:21.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll | Microsoft.WSMan.Management.dll |
13/2/2020 - 1:46:21.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll | Microsoft.WSMan.Management.dll |
13/2/2020 - 1:46:21.418 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll | Microsoft.WSMan.Management.dll |
13/2/2020 - 1:46:21.465 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:21.465 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:21.465 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:21.465 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:21.512 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:21.512 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll | |
13/2/2020 - 1:46:21.512 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll | Microsoft.WSMan.Runtime.dll |
13/2/2020 - 1:46:21.512 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll | |
13/2/2020 - 1:46:21.512 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll | Microsoft.WSMan.Runtime.dll |
13/2/2020 - 1:46:21.559 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll | Microsoft.WSMan.Runtime.dll |
13/2/2020 - 1:46:21.606 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll | Microsoft.WSMan.Runtime.dll |
13/2/2020 - 1:46:21.653 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll | |
13/2/2020 - 1:46:21.653 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll | |
13/2/2020 - 1:46:21.653 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll | Microsoft.WSMan.Management.dll |
13/2/2020 - 1:46:21.653 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll | |
13/2/2020 - 1:46:21.653 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll | Microsoft.WSMan.Management.dll |
13/2/2020 - 1:46:21.653 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll | Microsoft.WSMan.Management.dll |
13/2/2020 - 1:46:21.653 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:21.700 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:21.700 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:21.700 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll | |
13/2/2020 - 1:46:21.700 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll | |
13/2/2020 - 1:46:21.700 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll | Microsoft.WSMan.Runtime.dll |
13/2/2020 - 1:46:21.700 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll | |
13/2/2020 - 1:46:21.700 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll | Microsoft.WSMan.Runtime.dll |
13/2/2020 - 1:46:21.700 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Runtime\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Runtime.dll | Microsoft.WSMan.Runtime.dll |
13/2/2020 - 1:46:21.700 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:21.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:21.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:21.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:21.887 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:21.934 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:21.981 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:22.28 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:22.75 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:22.122 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:22.168 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:22.215 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:22.262 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:22.309 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:22.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:22.403 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:22.450 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:22.497 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:22.543 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:22.590 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:22.637 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:22.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:22.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:22.778 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:22.825 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:22.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | |
13/2/2020 - 1:46:22.965 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | System.Transactions.ni.dll |
13/2/2020 - 1:46:22.965 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | |
13/2/2020 - 1:46:22.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | System.Transactions.ni.dll |
13/2/2020 - 1:46:23.12 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | System.Transactions.ni.dll |
13/2/2020 - 1:46:23.59 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | System.Transactions.ni.dll |
13/2/2020 - 1:46:23.106 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | System.Transactions.ni.dll |
13/2/2020 - 1:46:23.153 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | System.Transactions.ni.dll |
13/2/2020 - 1:46:23.200 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | System.Transactions.ni.dll |
13/2/2020 - 1:46:23.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | System.Transactions.ni.dll |
13/2/2020 - 1:46:23.293 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089 | |
13/2/2020 - 1:46:23.293 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089 | |
13/2/2020 - 1:46:23.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | System.Transactions.ni.dll |
13/2/2020 - 1:46:23.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | System.Transactions.ni.dll |
13/2/2020 - 1:46:23.387 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | System.Transactions.ni.dll |
13/2/2020 - 1:46:23.434 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | System.Transactions.ni.dll |
13/2/2020 - 1:46:23.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll | |
13/2/2020 - 1:46:23.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll | System.Transactions.dll |
13/2/2020 - 1:46:23.528 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll | System.Transactions.dll |
13/2/2020 - 1:46:23.575 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll | System.Transactions.dll |
13/2/2020 - 1:46:23.622 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll | |
13/2/2020 - 1:46:23.622 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll | |
13/2/2020 - 1:46:23.622 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll | System.Transactions.dll |
13/2/2020 - 1:46:23.622 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll | |
13/2/2020 - 1:46:23.668 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll | System.Transactions.dll |
13/2/2020 - 1:46:23.668 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll | System.Transactions.dll |
13/2/2020 - 1:46:23.715 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll | |
13/2/2020 - 1:46:23.715 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll | System.Transactions.dll |
13/2/2020 - 1:46:23.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll | System.Transactions.dll |
13/2/2020 - 1:46:23.715 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe.Local | |
13/2/2020 - 1:46:23.715 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc | |
13/2/2020 - 1:46:23.715 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc | |
13/2/2020 - 1:46:23.715 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc | |
13/2/2020 - 1:46:23.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll | System.Transactions.dll |
13/2/2020 - 1:46:23.715 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll | |
13/2/2020 - 1:46:23.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll | System.Transactions.dll |
13/2/2020 - 1:46:23.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll | System.Transactions.dll |
13/2/2020 - 1:46:23.715 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll | System.Transactions.dll |
13/2/2020 - 1:46:23.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | System.Transactions.ni.dll |
13/2/2020 - 1:46:23.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | System.Transactions.ni.dll |
13/2/2020 - 1:46:23.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | System.Transactions.ni.dll |
13/2/2020 - 1:46:23.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | System.Transactions.ni.dll |
13/2/2020 - 1:46:23.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | System.Transactions.ni.dll |
13/2/2020 - 1:46:23.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:23.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:23.731 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:23.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | |
13/2/2020 - 1:46:23.731 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:23.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | |
13/2/2020 - 1:46:23.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:23.778 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:23.825 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:23.872 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:23.918 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:23.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:24.12 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:24.59 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:24.106 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:24.153 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:24.200 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:24.247 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:24.247 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:24.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:24.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:24.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | |
13/2/2020 - 1:46:24.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | |
13/2/2020 - 1:46:24.340 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:24.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | |
13/2/2020 - 1:46:24.340 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:24.340 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:24.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:24.387 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:24.434 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:24.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:24.528 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:24.575 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:24.622 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:24.622 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll | |
13/2/2020 - 1:46:24.622 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll | Microsoft.PowerShell.Commands.Management.dll |
13/2/2020 - 1:46:24.622 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll | |
13/2/2020 - 1:46:24.622 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll | Microsoft.PowerShell.Commands.Management.dll |
13/2/2020 - 1:46:24.668 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll | Microsoft.PowerShell.Commands.Management.dll |
13/2/2020 - 1:46:24.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll | Microsoft.PowerShell.Commands.Management.dll |
13/2/2020 - 1:46:24.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll | Microsoft.PowerShell.Commands.Management.dll |
13/2/2020 - 1:46:24.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll | Microsoft.PowerShell.Commands.Management.dll |
13/2/2020 - 1:46:24.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll | Microsoft.PowerShell.Commands.Management.dll |
13/2/2020 - 1:46:24.903 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll | Microsoft.PowerShell.Commands.Management.dll |
13/2/2020 - 1:46:24.950 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll | Microsoft.PowerShell.Commands.Management.dll |
13/2/2020 - 1:46:24.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:24.997 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:24.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll | |
13/2/2020 - 1:46:24.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll | |
13/2/2020 - 1:46:24.997 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll | Microsoft.PowerShell.Commands.Management.dll |
13/2/2020 - 1:46:24.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll | |
13/2/2020 - 1:46:24.997 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll | Microsoft.PowerShell.Commands.Management.dll |
13/2/2020 - 1:46:24.997 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll | Microsoft.PowerShell.Commands.Management.dll |
13/2/2020 - 1:46:24.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | |
13/2/2020 - 1:46:25.137 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:25.137 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | |
13/2/2020 - 1:46:25.137 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:25.184 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:25.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:25.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:25.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:25.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:25.418 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:25.465 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:25.512 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a | |
13/2/2020 - 1:46:25.559 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a | |
13/2/2020 - 1:46:25.559 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:25.606 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:25.653 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:25.700 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:25.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:25.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:25.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:25.887 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:25.981 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:26.28 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e24fa73a85564123eeb3755544d8cefc\System.ServiceProcess.ni.dll | |
13/2/2020 - 1:46:26.122 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e24fa73a85564123eeb3755544d8cefc\System.ServiceProcess.ni.dll | System.ServiceProcess.ni.dll |
13/2/2020 - 1:46:26.122 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e24fa73a85564123eeb3755544d8cefc\System.ServiceProcess.ni.dll | |
13/2/2020 - 1:46:26.122 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e24fa73a85564123eeb3755544d8cefc\System.ServiceProcess.ni.dll | System.ServiceProcess.ni.dll |
13/2/2020 - 1:46:26.168 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e24fa73a85564123eeb3755544d8cefc\System.ServiceProcess.ni.dll | System.ServiceProcess.ni.dll |
13/2/2020 - 1:46:26.215 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e24fa73a85564123eeb3755544d8cefc\System.ServiceProcess.ni.dll | System.ServiceProcess.ni.dll |
13/2/2020 - 1:46:26.262 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e24fa73a85564123eeb3755544d8cefc\System.ServiceProcess.ni.dll | System.ServiceProcess.ni.dll |
13/2/2020 - 1:46:26.309 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e24fa73a85564123eeb3755544d8cefc\System.ServiceProcess.ni.dll | System.ServiceProcess.ni.dll |
13/2/2020 - 1:46:26.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e24fa73a85564123eeb3755544d8cefc\System.ServiceProcess.ni.dll | System.ServiceProcess.ni.dll |
13/2/2020 - 1:46:26.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a | |
13/2/2020 - 1:46:26.497 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a | |
13/2/2020 - 1:46:26.497 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e24fa73a85564123eeb3755544d8cefc\System.ServiceProcess.ni.dll | System.ServiceProcess.ni.dll |
13/2/2020 - 1:46:26.543 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e24fa73a85564123eeb3755544d8cefc\System.ServiceProcess.ni.dll | System.ServiceProcess.ni.dll |
13/2/2020 - 1:46:26.590 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e24fa73a85564123eeb3755544d8cefc\System.ServiceProcess.ni.dll | System.ServiceProcess.ni.dll |
13/2/2020 - 1:46:26.637 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e24fa73a85564123eeb3755544d8cefc\System.ServiceProcess.ni.dll | System.ServiceProcess.ni.dll |
13/2/2020 - 1:46:26.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e24fa73a85564123eeb3755544d8cefc\System.ServiceProcess.ni.dll | System.ServiceProcess.ni.dll |
13/2/2020 - 1:46:26.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:26.778 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:26.778 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll | |
13/2/2020 - 1:46:26.825 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll | Microsoft.PowerShell.Security.dll |
13/2/2020 - 1:46:26.825 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll | |
13/2/2020 - 1:46:26.825 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll | Microsoft.PowerShell.Security.dll |
13/2/2020 - 1:46:26.872 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll | Microsoft.PowerShell.Security.dll |
13/2/2020 - 1:46:26.918 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll | Microsoft.PowerShell.Security.dll |
13/2/2020 - 1:46:26.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll | Microsoft.PowerShell.Security.dll |
13/2/2020 - 1:46:27.12 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll | Microsoft.PowerShell.Security.dll |
13/2/2020 - 1:46:27.59 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:27.59 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35 | |
13/2/2020 - 1:46:27.59 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll | |
13/2/2020 - 1:46:27.59 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll | |
13/2/2020 - 1:46:27.59 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll | Microsoft.PowerShell.Security.dll |
13/2/2020 - 1:46:27.59 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll | |
13/2/2020 - 1:46:27.59 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll | Microsoft.PowerShell.Security.dll |
13/2/2020 - 1:46:27.59 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll | Microsoft.PowerShell.Security.dll |
13/2/2020 - 1:46:27.59 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:27.106 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:27.200 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:27.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:27.293 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Globalization\en.nlp | |
13/2/2020 - 1:46:27.293 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.config | |
13/2/2020 - 1:46:27.293 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\Microsoft.PowerShell.ConsoleHost.resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:46:27.293 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:46:27.293 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:46:27.293 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll | |
13/2/2020 - 1:46:27.293 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll | Microsoft.PowerShell.ConsoleHost.Resources.dll |
13/2/2020 - 1:46:27.293 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll | |
13/2/2020 - 1:46:27.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll | Microsoft.PowerShell.ConsoleHost.Resources.dll |
13/2/2020 - 1:46:27.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll | Microsoft.PowerShell.ConsoleHost.Resources.dll |
13/2/2020 - 1:46:27.387 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll | Microsoft.PowerShell.ConsoleHost.Resources.dll |
13/2/2020 - 1:46:27.465 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll | Microsoft.PowerShell.ConsoleHost.Resources.dll |
13/2/2020 - 1:46:27.512 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:46:27.512 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:46:27.512 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll | |
13/2/2020 - 1:46:27.512 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll | |
13/2/2020 - 1:46:27.512 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll | Microsoft.PowerShell.ConsoleHost.Resources.dll |
13/2/2020 - 1:46:27.512 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll | |
13/2/2020 - 1:46:27.512 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll | Microsoft.PowerShell.ConsoleHost.Resources.dll |
13/2/2020 - 1:46:27.512 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.Resources.dll | Microsoft.PowerShell.ConsoleHost.Resources.dll |
13/2/2020 - 1:46:27.512 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:27.559 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:27.606 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:27.653 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll | Microsoft.PowerShell.ConsoleHost.dll |
13/2/2020 - 1:46:27.700 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:27.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:27.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:27.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:27.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:27.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:27.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:27.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:27.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:27.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:27.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:27.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:27.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:27.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:27.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:27.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:27.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:27.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:27.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:27.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:27.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:27.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:27.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:27.903 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:27.950 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:27.997 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:28.43 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:28.90 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:28.137 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:28.184 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:28.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:28.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:28.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:28.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:28.418 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:28.465 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:28.512 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:28.559 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:28.606 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:28.653 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:28.700 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:28.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:28.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:28.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:28.903 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:28.950 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:28.997 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:29.43 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:29.90 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:29.137 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:29.184 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:29.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:29.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:29.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:29.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:29.418 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:29.465 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:29.512 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:29.559 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:29.559 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:29.559 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:29.637 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:29.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:29.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:29.778 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:29.825 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:29.872 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:29.918 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:29.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:30.12 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:30.59 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:30.106 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:30.153 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:30.200 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:30.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:30.293 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | |
13/2/2020 - 1:46:30.434 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:30.434 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | |
13/2/2020 - 1:46:30.434 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:30.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:30.528 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:30.575 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:30.622 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:30.668 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:30.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:30.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:30.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:30.856 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a | |
13/2/2020 - 1:46:30.950 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a | |
13/2/2020 - 1:46:30.950 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:30.997 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:31.43 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:31.90 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:31.137 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:31.184 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:31.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:31.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:31.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:31.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:31.418 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:31.465 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:31.512 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:31.512 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:31.512 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:31.559 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Management.Automation.resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:46:31.559 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:46:31.606 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:46:31.606 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll | |
13/2/2020 - 1:46:31.653 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll | System.Management.Automation.Resources.dll |
13/2/2020 - 1:46:31.653 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll | |
13/2/2020 - 1:46:31.653 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll | System.Management.Automation.Resources.dll |
13/2/2020 - 1:46:31.700 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll | System.Management.Automation.Resources.dll |
13/2/2020 - 1:46:31.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll | System.Management.Automation.Resources.dll |
13/2/2020 - 1:46:31.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll | System.Management.Automation.Resources.dll |
13/2/2020 - 1:46:31.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll | System.Management.Automation.Resources.dll |
13/2/2020 - 1:46:31.887 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll | System.Management.Automation.Resources.dll |
13/2/2020 - 1:46:31.934 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:46:31.934 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:46:31.934 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll | |
13/2/2020 - 1:46:31.934 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll | |
13/2/2020 - 1:46:31.934 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll | System.Management.Automation.Resources.dll |
13/2/2020 - 1:46:31.934 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll | |
13/2/2020 - 1:46:31.934 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll | System.Management.Automation.Resources.dll |
13/2/2020 - 1:46:31.934 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll | System.Management.Automation.Resources.dll |
13/2/2020 - 1:46:31.934 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll | System.Management.Automation.Resources.dll |
13/2/2020 - 1:46:31.981 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:32.28 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:32.75 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\shfolder.dll | |
13/2/2020 - 1:46:32.75 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shfolder.dll | |
13/2/2020 - 1:46:32.75 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shfolder.dll | |
13/2/2020 - 1:46:32.309 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\Documents | |
13/2/2020 - 1:46:32.309 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\Documents | |
13/2/2020 - 1:46:32.309 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:32.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:32.403 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:32.450 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:32.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0 | |
13/2/2020 - 1:46:32.497 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0 | |
13/2/2020 - 1:46:32.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\getevent.types.ps1xml | |
13/2/2020 - 1:46:32.543 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\getevent.types.ps1xml | getevent.types.ps1xml |
13/2/2020 - 1:46:32.543 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | |
13/2/2020 - 1:46:32.590 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:32.590 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:32.637 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:32.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:32.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:32.778 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:32.825 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:32.872 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:32.918 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:32.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:33.12 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:33.59 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:33.106 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:33.153 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:33.200 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:33.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:33.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:33.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\getevent.types.ps1xml | |
13/2/2020 - 1:46:33.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\getevent.types.ps1xml | getevent.types.ps1xml |
13/2/2020 - 1:46:33.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\getevent.types.ps1xml | getevent.types.ps1xml |
13/2/2020 - 1:46:33.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\getevent.types.ps1xml | getevent.types.ps1xml |
13/2/2020 - 1:46:33.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\getevent.types.ps1xml | getevent.types.ps1xml |
13/2/2020 - 1:46:33.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\getevent.types.ps1xml | getevent.types.ps1xml |
13/2/2020 - 1:46:33.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\getevent.types.ps1xml | getevent.types.ps1xml |
13/2/2020 - 1:46:33.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\getevent.types.ps1xml | getevent.types.ps1xml |
13/2/2020 - 1:46:33.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\getevent.types.ps1xml | |
13/2/2020 - 1:46:33.340 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\getevent.types.ps1xml | getevent.types.ps1xml |
13/2/2020 - 1:46:33.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:33.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:33.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:33.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:33.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:33.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:33.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:33.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:33.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:33.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:33.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:33.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:33.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:33.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:33.403 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:33.497 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:33.543 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:33.590 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:33.637 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:33.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:33.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:33.778 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:33.825 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:33.965 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:33.965 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | |
13/2/2020 - 1:46:33.965 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\types.ps1xml | types.ps1xml |
13/2/2020 - 1:46:34.43 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:34.137 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:34.184 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:34.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:34.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:34.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:34.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:34.465 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:34.512 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:34.559 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:34.653 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:34.700 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:34.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:34.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:34.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:34.981 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:35.28 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:35.90 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:35.137 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:35.184 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:35.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:35.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:35.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:35.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:35.418 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:35.465 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:35.512 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:35.559 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:35.606 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:35.653 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:35.700 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:35.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:35.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:35.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:35.887 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:35.934 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:35.981 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:36.28 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:36.75 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:36.122 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:36.168 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:36.215 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:36.262 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:36.309 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | System.Transactions.ni.dll |
13/2/2020 - 1:46:36.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:36.403 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:36.450 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e24fa73a85564123eeb3755544d8cefc\System.ServiceProcess.ni.dll | System.ServiceProcess.ni.dll |
13/2/2020 - 1:46:36.497 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:36.543 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:36.590 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:36.637 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:36.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:36.747 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0 | |
13/2/2020 - 1:46:36.747 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0 | |
13/2/2020 - 1:46:36.747 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml | |
13/2/2020 - 1:46:36.793 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml | Diagnostics.Format.ps1xml |
13/2/2020 - 1:46:36.793 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\WSMan.Format.ps1xml | |
13/2/2020 - 1:46:36.840 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\WSMan.Format.ps1xml | WSMan.Format.ps1xml |
13/2/2020 - 1:46:36.840 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Certificate.format.ps1xml | |
13/2/2020 - 1:46:36.887 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Certificate.format.ps1xml | Certificate.format.ps1xml |
13/2/2020 - 1:46:36.887 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | |
13/2/2020 - 1:46:36.887 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:36.887 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\FileSystem.format.ps1xml | |
13/2/2020 - 1:46:36.887 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\FileSystem.format.ps1xml | FileSystem.format.ps1xml |
13/2/2020 - 1:46:36.887 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | |
13/2/2020 - 1:46:36.934 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:36.934 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | |
13/2/2020 - 1:46:36.981 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:36.981 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml | |
13/2/2020 - 1:46:37.28 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml | PowerShellTrace.format.ps1xml |
13/2/2020 - 1:46:37.28 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Registry.format.ps1xml | |
13/2/2020 - 1:46:37.28 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Registry.format.ps1xml | Registry.format.ps1xml |
13/2/2020 - 1:46:37.28 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:37.75 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\tzres.dll | |
13/2/2020 - 1:46:37.75 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\tzres.dll | |
13/2/2020 - 1:46:37.75 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\tzres.dll | |
13/2/2020 - 1:46:37.75 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\tzres.dll | |
13/2/2020 - 1:46:37.90 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:37.137 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml | |
13/2/2020 - 1:46:37.137 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml | Diagnostics.Format.ps1xml |
13/2/2020 - 1:46:37.137 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml | Diagnostics.Format.ps1xml |
13/2/2020 - 1:46:37.184 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:37.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml | Diagnostics.Format.ps1xml |
13/2/2020 - 1:46:37.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml | Diagnostics.Format.ps1xml |
13/2/2020 - 1:46:37.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml | Diagnostics.Format.ps1xml |
13/2/2020 - 1:46:37.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml | Diagnostics.Format.ps1xml |
13/2/2020 - 1:46:37.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml | Diagnostics.Format.ps1xml |
13/2/2020 - 1:46:37.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml | Diagnostics.Format.ps1xml |
13/2/2020 - 1:46:37.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml | Diagnostics.Format.ps1xml |
13/2/2020 - 1:46:37.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml | Diagnostics.Format.ps1xml |
13/2/2020 - 1:46:37.231 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml | |
13/2/2020 - 1:46:37.231 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Diagnostics.Format.ps1xml | Diagnostics.Format.ps1xml |
13/2/2020 - 1:46:37.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:37.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:37.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:37.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:37.418 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:37.465 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:37.512 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:37.559 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:37.668 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\WSMan.Format.ps1xml | |
13/2/2020 - 1:46:37.668 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\WSMan.Format.ps1xml | WSMan.Format.ps1xml |
13/2/2020 - 1:46:37.668 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\WSMan.Format.ps1xml | WSMan.Format.ps1xml |
13/2/2020 - 1:46:37.668 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\WSMan.Format.ps1xml | WSMan.Format.ps1xml |
13/2/2020 - 1:46:37.668 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\WSMan.Format.ps1xml | WSMan.Format.ps1xml |
13/2/2020 - 1:46:37.668 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\WSMan.Format.ps1xml | WSMan.Format.ps1xml |
13/2/2020 - 1:46:37.668 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\WSMan.Format.ps1xml | WSMan.Format.ps1xml |
13/2/2020 - 1:46:37.668 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\WSMan.Format.ps1xml | WSMan.Format.ps1xml |
13/2/2020 - 1:46:37.668 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\WSMan.Format.ps1xml | WSMan.Format.ps1xml |
13/2/2020 - 1:46:37.668 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\WSMan.Format.ps1xml | WSMan.Format.ps1xml |
13/2/2020 - 1:46:37.668 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\WSMan.Format.ps1xml | |
13/2/2020 - 1:46:37.668 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\WSMan.Format.ps1xml | WSMan.Format.ps1xml |
13/2/2020 - 1:46:37.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ef4a32979d02a76972d22c8161778f10\System.Xml.ni.dll | System.Xml.ni.dll |
13/2/2020 - 1:46:37.684 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Certificate.format.ps1xml | |
13/2/2020 - 1:46:37.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Certificate.format.ps1xml | Certificate.format.ps1xml |
13/2/2020 - 1:46:37.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Certificate.format.ps1xml | Certificate.format.ps1xml |
13/2/2020 - 1:46:37.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Certificate.format.ps1xml | Certificate.format.ps1xml |
13/2/2020 - 1:46:37.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Certificate.format.ps1xml | Certificate.format.ps1xml |
13/2/2020 - 1:46:37.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Certificate.format.ps1xml | Certificate.format.ps1xml |
13/2/2020 - 1:46:37.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Certificate.format.ps1xml | Certificate.format.ps1xml |
13/2/2020 - 1:46:37.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Certificate.format.ps1xml | Certificate.format.ps1xml |
13/2/2020 - 1:46:37.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Certificate.format.ps1xml | Certificate.format.ps1xml |
13/2/2020 - 1:46:37.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Certificate.format.ps1xml | Certificate.format.ps1xml |
13/2/2020 - 1:46:37.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Certificate.format.ps1xml | Certificate.format.ps1xml |
13/2/2020 - 1:46:37.684 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Certificate.format.ps1xml | |
13/2/2020 - 1:46:37.684 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Certificate.format.ps1xml | Certificate.format.ps1xml |
13/2/2020 - 1:46:37.700 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | System.Transactions.ni.dll |
13/2/2020 - 1:46:37.700 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\fdef4c991303c17ece877574f240249f\System.Management.ni.dll | System.Management.ni.dll |
13/2/2020 - 1:46:37.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll | System.Management.Automation.Resources.dll |
13/2/2020 - 1:46:37.715 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | |
13/2/2020 - 1:46:37.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:37.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:37.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:37.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | |
13/2/2020 - 1:46:37.731 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\DotNetTypes.format.ps1xml | DotNetTypes.format.ps1xml |
13/2/2020 - 1:46:37.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\FileSystem.format.ps1xml | |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\FileSystem.format.ps1xml | FileSystem.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\FileSystem.format.ps1xml | FileSystem.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\FileSystem.format.ps1xml | FileSystem.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\FileSystem.format.ps1xml | FileSystem.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\FileSystem.format.ps1xml | FileSystem.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\FileSystem.format.ps1xml | FileSystem.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\FileSystem.format.ps1xml | FileSystem.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\FileSystem.format.ps1xml | FileSystem.format.ps1xml |
13/2/2020 - 1:46:37.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\FileSystem.format.ps1xml | FileSystem.format.ps1xml |
13/2/2020 - 1:46:37.747 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\FileSystem.format.ps1xml | |
13/2/2020 - 1:46:37.747 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\FileSystem.format.ps1xml | FileSystem.format.ps1xml |
13/2/2020 - 1:46:37.747 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.762 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | |
13/2/2020 - 1:46:37.762 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Help.format.ps1xml | Help.format.ps1xml |
13/2/2020 - 1:46:37.778 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll | System.Management.Automation.Resources.dll |
13/2/2020 - 1:46:37.793 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.793 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | |
13/2/2020 - 1:46:37.793 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellCore.format.ps1xml | PowerShellCore.format.ps1xml |
13/2/2020 - 1:46:37.809 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml | |
13/2/2020 - 1:46:37.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml | PowerShellTrace.format.ps1xml |
13/2/2020 - 1:46:37.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml | PowerShellTrace.format.ps1xml |
13/2/2020 - 1:46:37.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml | PowerShellTrace.format.ps1xml |
13/2/2020 - 1:46:37.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml | PowerShellTrace.format.ps1xml |
13/2/2020 - 1:46:37.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml | PowerShellTrace.format.ps1xml |
13/2/2020 - 1:46:37.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml | PowerShellTrace.format.ps1xml |
13/2/2020 - 1:46:37.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml | PowerShellTrace.format.ps1xml |
13/2/2020 - 1:46:37.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml | PowerShellTrace.format.ps1xml |
13/2/2020 - 1:46:37.809 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml | |
13/2/2020 - 1:46:37.809 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShellTrace.format.ps1xml | PowerShellTrace.format.ps1xml |
13/2/2020 - 1:46:37.809 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Registry.format.ps1xml | |
13/2/2020 - 1:46:37.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Registry.format.ps1xml | Registry.format.ps1xml |
13/2/2020 - 1:46:37.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Registry.format.ps1xml | Registry.format.ps1xml |
13/2/2020 - 1:46:37.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Registry.format.ps1xml | Registry.format.ps1xml |
13/2/2020 - 1:46:37.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Registry.format.ps1xml | Registry.format.ps1xml |
13/2/2020 - 1:46:37.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Registry.format.ps1xml | Registry.format.ps1xml |
13/2/2020 - 1:46:37.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Registry.format.ps1xml | Registry.format.ps1xml |
13/2/2020 - 1:46:37.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Registry.format.ps1xml | Registry.format.ps1xml |
13/2/2020 - 1:46:37.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Registry.format.ps1xml | Registry.format.ps1xml |
13/2/2020 - 1:46:37.809 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Registry.format.ps1xml | |
13/2/2020 - 1:46:37.809 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Registry.format.ps1xml | Registry.format.ps1xml |
13/2/2020 - 1:46:37.825 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:37.825 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management\1.0.0.0__31bf3856ad364e35\Microsoft.WSMan.Management.dll | Microsoft.WSMan.Management.dll |
13/2/2020 - 1:46:37.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | System.Transactions.ni.dll |
13/2/2020 - 1:46:37.840 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\Microsoft.WSMan.Management.resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:46:37.840 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:46:37.840 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:46:37.840 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll | |
13/2/2020 - 1:46:37.840 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll | Microsoft.WSMan.Management.resources.dll |
13/2/2020 - 1:46:37.840 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll | |
13/2/2020 - 1:46:37.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll | Microsoft.WSMan.Management.resources.dll |
13/2/2020 - 1:46:37.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll | Microsoft.WSMan.Management.resources.dll |
13/2/2020 - 1:46:37.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll | Microsoft.WSMan.Management.resources.dll |
13/2/2020 - 1:46:37.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll | Microsoft.WSMan.Management.resources.dll |
13/2/2020 - 1:46:37.840 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:46:37.840 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:46:37.840 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll | |
13/2/2020 - 1:46:37.840 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll | |
13/2/2020 - 1:46:37.856 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll | Microsoft.WSMan.Management.resources.dll |
13/2/2020 - 1:46:37.856 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll | |
13/2/2020 - 1:46:37.856 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll | Microsoft.WSMan.Management.resources.dll |
13/2/2020 - 1:46:37.856 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.WSMan.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.WSMan.Management.resources.dll | Microsoft.WSMan.Management.resources.dll |
13/2/2020 - 1:46:37.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:37.872 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:37.872 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:37.872 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:37.872 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:37.872 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:37.872 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:37.934 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:37.981 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\secur32.dll | |
13/2/2020 - 1:46:37.981 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\secur32.dll | |
13/2/2020 - 1:46:37.981 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\secur32.dll | |
13/2/2020 - 1:46:37.981 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\secur32.dll | |
13/2/2020 - 1:46:37.981 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:38.28 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll | System.Management.Automation.Resources.dll |
13/2/2020 - 1:46:38.75 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:38.122 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:38.262 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:38.309 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:38.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:38.684 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot | |
13/2/2020 - 1:46:38.684 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot | |
13/2/2020 - 1:46:38.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:38.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:38.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:38.684 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:46:38.684 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:46:38.684 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:46:38.684 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:46:38.684 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:46:38.684 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:46:38.684 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:46:38.684 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:46:38.684 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:46:38.684 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:46:38.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\a954c94bbb596ac943bb9ff6096e256c\System.Transactions.ni.dll | System.Transactions.ni.dll |
13/2/2020 - 1:46:38.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll | System.Management.Automation.Resources.dll |
13/2/2020 - 1:46:38.778 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll | System.Management.Automation.Resources.dll |
13/2/2020 - 1:46:38.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\Microsoft.PowerShell.Security.resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:46:38.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:46:38.872 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:46:38.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dll | |
13/2/2020 - 1:46:38.872 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dll | Microsoft.PowerShell.Security.Resources.dll |
13/2/2020 - 1:46:38.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dll | |
13/2/2020 - 1:46:38.872 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dll | Microsoft.PowerShell.Security.Resources.dll |
13/2/2020 - 1:46:38.872 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dll | Microsoft.PowerShell.Security.Resources.dll |
13/2/2020 - 1:46:38.872 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dll | Microsoft.PowerShell.Security.Resources.dll |
13/2/2020 - 1:46:38.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:46:38.872 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:46:38.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dll | |
13/2/2020 - 1:46:38.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dll | |
13/2/2020 - 1:46:38.872 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dll | Microsoft.PowerShell.Security.Resources.dll |
13/2/2020 - 1:46:38.872 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dll | |
13/2/2020 - 1:46:38.872 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dll | Microsoft.PowerShell.Security.Resources.dll |
13/2/2020 - 1:46:38.872 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Security.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Security.Resources.dll | Microsoft.PowerShell.Security.Resources.dll |
13/2/2020 - 1:46:39.28 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor | |
13/2/2020 - 1:46:39.28 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor | |
13/2/2020 - 1:46:39.28 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor | |
13/2/2020 - 1:46:39.28 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor | |
13/2/2020 - 1:46:39.43 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:46:39.43 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:46:39.43 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:46:39.43 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:46:39.43 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor | |
13/2/2020 - 1:46:39.43 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor | |
13/2/2020 - 1:46:39.43 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor | |
13/2/2020 - 1:46:39.43 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor | |
13/2/2020 - 1:46:39.43 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor | |
13/2/2020 - 1:46:39.43 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor | |
13/2/2020 - 1:46:39.43 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor | |
13/2/2020 - 1:46:39.43 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor | |
13/2/2020 - 1:46:39.43 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:39.90 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor | |
13/2/2020 - 1:46:39.90 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor | |
13/2/2020 - 1:46:39.153 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:39.153 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:39.153 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:39.153 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:39.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:39.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\068ae883ce93f6d9e7600b99f7677943\System.DirectoryServices.ni.dll | System.DirectoryServices.ni.dll |
13/2/2020 - 1:46:39.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:39.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:39.434 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:39.497 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | |
13/2/2020 - 1:46:39.653 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:39.653 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | |
13/2/2020 - 1:46:39.653 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:39.700 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:39.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:39.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:39.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:39.887 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:39.934 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:39.981 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:40.28 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:40.75 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:40.122 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:40.168 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:40.215 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:40.262 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:40.309 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:40.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:40.403 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:40.450 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:40.497 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:40.543 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089 | |
13/2/2020 - 1:46:40.590 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089 | |
13/2/2020 - 1:46:40.590 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:40.637 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:40.684 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:40.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:40.778 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:40.825 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll | |
13/2/2020 - 1:46:40.872 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll | System.Data.dll |
13/2/2020 - 1:46:40.918 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll | System.Data.dll |
13/2/2020 - 1:46:40.965 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll | System.Data.dll |
13/2/2020 - 1:46:41.12 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll | System.Data.dll |
13/2/2020 - 1:46:41.59 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll | System.Data.dll |
13/2/2020 - 1:46:41.106 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll | System.Data.dll |
13/2/2020 - 1:46:41.153 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll | System.Data.dll |
13/2/2020 - 1:46:41.200 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll | |
13/2/2020 - 1:46:41.200 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll | |
13/2/2020 - 1:46:41.200 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll | System.Data.dll |
13/2/2020 - 1:46:41.200 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll | |
13/2/2020 - 1:46:41.200 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll | System.Data.dll |
13/2/2020 - 1:46:41.200 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll | System.Data.dll |
13/2/2020 - 1:46:41.247 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll | |
13/2/2020 - 1:46:41.247 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll | System.Data.dll |
13/2/2020 - 1:46:41.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll | System.Data.dll |
13/2/2020 - 1:46:41.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll | System.Data.dll |
13/2/2020 - 1:46:41.247 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe.Local | |
13/2/2020 - 1:46:41.247 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc | |
13/2/2020 - 1:46:41.247 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc | |
13/2/2020 - 1:46:41.247 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc | |
13/2/2020 - 1:46:41.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll | System.Data.dll |
13/2/2020 - 1:46:41.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll | System.Data.dll |
13/2/2020 - 1:46:41.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll | System.Data.dll |
13/2/2020 - 1:46:41.247 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll | System.Data.dll |
13/2/2020 - 1:46:41.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.262 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:41.262 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:41.262 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:41.262 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:41.262 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:41.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.418 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.465 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.512 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.559 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.606 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.653 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.700 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.887 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.934 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:41.981 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:42.28 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:42.75 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:42.122 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:42.168 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:42.231 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\profile.ps1 | |
13/2/2020 - 1:46:42.231 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Microsoft.PowerShell_profile.ps1 | |
13/2/2020 - 1:46:42.231 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\Documents\WindowsPowerShell\profile.ps1 | |
13/2/2020 - 1:46:42.231 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1 | |
13/2/2020 - 1:46:42.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:42.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:42.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:42.528 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:42.653 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Globalization\en-us.nlp | |
13/2/2020 - 1:46:42.653 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089 | |
13/2/2020 - 1:46:42.653 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089 | |
13/2/2020 - 1:46:42.747 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089 | |
13/2/2020 - 1:46:42.747 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll | |
13/2/2020 - 1:46:42.840 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll | mscorlib.resources.dll |
13/2/2020 - 1:46:42.840 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll | |
13/2/2020 - 1:46:42.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll | mscorlib.resources.dll |
13/2/2020 - 1:46:42.887 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll | mscorlib.resources.dll |
13/2/2020 - 1:46:42.934 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll | mscorlib.resources.dll |
13/2/2020 - 1:46:42.981 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll | mscorlib.resources.dll |
13/2/2020 - 1:46:43.28 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll | mscorlib.resources.dll |
13/2/2020 - 1:46:43.75 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089 | |
13/2/2020 - 1:46:43.75 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089 | |
13/2/2020 - 1:46:43.75 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll | |
13/2/2020 - 1:46:43.75 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll | |
13/2/2020 - 1:46:43.75 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll | mscorlib.resources.dll |
13/2/2020 - 1:46:43.75 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll | |
13/2/2020 - 1:46:43.75 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll | mscorlib.resources.dll |
13/2/2020 - 1:46:43.75 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll | mscorlib.resources.dll |
13/2/2020 - 1:46:43.75 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll | mscorlib.resources.dll |
13/2/2020 - 1:46:43.184 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:43.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:43.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:43.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:43.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:43.418 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:43.465 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:43.512 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:43.559 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:43.606 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:43.653 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:43.700 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:43.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:43.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:43.903 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:43.950 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:43.997 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:44.43 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:44.90 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:46:44.200 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:44.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:44.309 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll | Microsoft.PowerShell.Commands.Management.dll |
13/2/2020 - 1:46:44.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:44.418 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep | |
13/2/2020 - 1:46:44.418 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep | |
13/2/2020 - 1:46:44.418 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep | |
13/2/2020 - 1:46:44.418 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep | |
13/2/2020 - 1:46:44.418 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep | |
13/2/2020 - 1:46:44.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:44.606 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:44.653 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:44.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:44.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:44.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\8687e43ef23de4f9262530d943886112\System.Data.ni.dll | System.Data.ni.dll |
13/2/2020 - 1:46:44.997 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:45.43 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep | |
13/2/2020 - 1:46:45.43 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep | |
13/2/2020 - 1:46:45.43 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:45.168 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:45.215 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:45.215 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:45.215 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:45.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\1.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll | Microsoft.PowerShell.Commands.Utility.dll |
13/2/2020 - 1:46:45.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:45.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:45.293 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:45.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:45.387 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:45.434 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:45.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:45.528 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:45.575 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:45.622 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:45.668 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:45.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:45.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:45.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:45.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:45.903 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:45.950 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | |
13/2/2020 - 1:46:45.997 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:45.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | |
13/2/2020 - 1:46:45.997 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:46.43 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:46.90 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:46.137 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:46.184 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:46.231 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:46.278 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:46.325 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a | |
13/2/2020 - 1:46:46.325 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a | |
13/2/2020 - 1:46:46.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:46.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:46.418 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:46.465 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:46.512 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:46.559 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:46.606 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:46.653 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:46.700 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:46.747 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:46.793 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:46.840 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:46.887 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:46.934 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | |
13/2/2020 - 1:46:46.934 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | machine.config |
13/2/2020 - 1:46:46.934 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | |
13/2/2020 - 1:46:46.934 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | machine.config |
13/2/2020 - 1:46:46.934 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | |
13/2/2020 - 1:46:46.934 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | machine.config |
13/2/2020 - 1:46:46.934 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | machine.config |
13/2/2020 - 1:46:46.934 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | machine.config |
13/2/2020 - 1:46:46.934 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | machine.config |
13/2/2020 - 1:46:46.934 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | machine.config |
13/2/2020 - 1:46:46.934 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | machine.config |
13/2/2020 - 1:46:46.934 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | machine.config |
13/2/2020 - 1:46:46.934 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\CONFIG\machine.config | machine.config |
13/2/2020 - 1:46:46.934 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:46.981 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.config | |
13/2/2020 - 1:46:46.981 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.config | |
13/2/2020 - 1:46:46.981 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:47.28 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:47.75 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:47.122 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep\vNmJP.zip | |
13/2/2020 - 1:46:47.122 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:47.168 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:47.215 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:47.262 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:47.309 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:47.356 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\rasapi32.dll | |
13/2/2020 - 1:46:47.356 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\rasapi32.dll | |
13/2/2020 - 1:46:47.356 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\rasapi32.dll | |
13/2/2020 - 1:46:47.356 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\rasapi32.dll | |
13/2/2020 - 1:46:47.637 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\rasman.dll | |
13/2/2020 - 1:46:47.637 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\rasman.dll | |
13/2/2020 - 1:46:47.637 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\rasman.dll | |
13/2/2020 - 1:46:48.12 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\rtutils.dll | |
13/2/2020 - 1:46:48.12 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\rtutils.dll | |
13/2/2020 - 1:46:48.59 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\rtutils.dll | |
13/2/2020 - 1:46:48.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:48.387 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ws2_32.dll | |
13/2/2020 - 1:46:48.387 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\mswsock.dll | |
13/2/2020 - 1:46:48.387 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\mswsock.dll | |
13/2/2020 - 1:46:48.387 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WSHTCPIP.DLL | |
13/2/2020 - 1:46:48.387 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WSHTCPIP.DLL | |
13/2/2020 - 1:46:48.387 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wship6.dll | |
13/2/2020 - 1:46:48.387 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wship6.dll | |
13/2/2020 - 1:46:48.387 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\c8b82d8b2e7e18c7caf27b8017c6c615\System.Configuration.ni.dll | System.Configuration.ni.dll |
13/2/2020 - 1:46:48.434 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:48.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:48.528 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:48.575 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:48.622 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:48.668 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:48.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:48.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:48.856 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:48.903 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:48.903 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:48.903 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:46:48.903 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:48.903 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:48.918 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\winhttp.dll | |
13/2/2020 - 1:46:48.918 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\winhttp.dll | |
13/2/2020 - 1:46:48.918 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\winhttp.dll | |
13/2/2020 - 1:46:48.918 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\winhttp.dll | |
13/2/2020 - 1:46:48.918 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\webio.dll | |
13/2/2020 - 1:46:48.918 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\webio.dll | |
13/2/2020 - 1:46:48.918 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\webio.dll | |
13/2/2020 - 1:46:48.918 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:48.918 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\credssp.dll | |
13/2/2020 - 1:46:48.918 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\credssp.dll | |
13/2/2020 - 1:46:48.918 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\credssp.dll | |
13/2/2020 - 1:46:48.918 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:48.918 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:48.918 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\IPHLPAPI.DLL | |
13/2/2020 - 1:46:48.918 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\IPHLPAPI.DLL | |
13/2/2020 - 1:46:48.918 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\IPHLPAPI.DLL | |
13/2/2020 - 1:46:48.918 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\WINNSI.DLL | |
13/2/2020 - 1:46:48.918 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\winnsi.dll | |
13/2/2020 - 1:46:48.918 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\winnsi.dll | |
13/2/2020 - 1:46:48.918 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\dhcpcsvc6.DLL | |
13/2/2020 - 1:46:48.918 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\dhcpcsvc6.dll | |
13/2/2020 - 1:46:48.918 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\dhcpcsvc6.dll | dhcpcsvc6.dll |
13/2/2020 - 1:46:48.918 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\dhcpcsvc6.dll | |
13/2/2020 - 1:46:48.918 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\dhcpcsvc6.dll | dhcpcsvc6.dll |
13/2/2020 - 1:46:48.981 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\dhcpcsvc.DLL | |
13/2/2020 - 1:46:48.981 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\dhcpcsvc.dll | |
13/2/2020 - 1:46:48.981 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\dhcpcsvc.dll | |
13/2/2020 - 1:46:49.122 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:49.168 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\iphlpapi.dll | |
13/2/2020 - 1:46:49.215 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:46:49.262 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:47:10.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:47:10.325 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\System.resources\2.0.0.0_pt-BR_b77a5c561934e089 | |
13/2/2020 - 1:47:10.325 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pt-BR_b77a5c561934e089 | |
13/2/2020 - 1:47:10.325 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pt-BR_b77a5c561934e089 | |
13/2/2020 - 1:47:10.325 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pt-BR_b77a5c561934e089\system.resources.dll | |
13/2/2020 - 1:47:10.325 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pt-BR_b77a5c561934e089\system.resources.dll | system.resources.dll |
13/2/2020 - 1:47:10.325 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pt-BR_b77a5c561934e089\system.resources.dll | |
13/2/2020 - 1:47:10.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pt-BR_b77a5c561934e089\system.resources.dll | system.resources.dll |
13/2/2020 - 1:47:10.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pt-BR_b77a5c561934e089\system.resources.dll | system.resources.dll |
13/2/2020 - 1:47:10.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pt-BR_b77a5c561934e089\system.resources.dll | system.resources.dll |
13/2/2020 - 1:47:10.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pt-BR_b77a5c561934e089\system.resources.dll | system.resources.dll |
13/2/2020 - 1:47:10.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pt-BR_b77a5c561934e089\system.resources.dll | system.resources.dll |
13/2/2020 - 1:47:10.325 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pt-BR_b77a5c561934e089 | |
13/2/2020 - 1:47:10.325 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pt-BR_b77a5c561934e089 | |
13/2/2020 - 1:47:10.325 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pt-BR_b77a5c561934e089\system.resources.dll | |
13/2/2020 - 1:47:10.325 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pt-BR_b77a5c561934e089\system.resources.dll | |
13/2/2020 - 1:47:10.325 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pt-BR_b77a5c561934e089\system.resources.dll | system.resources.dll |
13/2/2020 - 1:47:10.325 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pt-BR_b77a5c561934e089\system.resources.dll | |
13/2/2020 - 1:47:10.325 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pt-BR_b77a5c561934e089\system.resources.dll | system.resources.dll |
13/2/2020 - 1:47:10.325 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pt-BR_b77a5c561934e089\system.resources.dll | system.resources.dll |
13/2/2020 - 1:47:10.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pt-BR_b77a5c561934e089\system.resources.dll | system.resources.dll |
13/2/2020 - 1:47:10.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:47:10.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:47:10.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:47:10.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pt-BR_b77a5c561934e089\system.resources.dll | system.resources.dll |
13/2/2020 - 1:47:10.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_pt-BR_b77a5c561934e089\system.resources.dll | system.resources.dll |
13/2/2020 - 1:47:10.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:47:10.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:47:10.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:47:10.325 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:47:10.325 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep\vNmJP.zip | |
13/2/2020 - 1:47:10.325 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\Files\DeletedFiles | |
13/2/2020 - 1:47:10.325 | Delete | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep\vNmJP.zip | |
13/2/2020 - 1:47:10.325 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep\vNmJP.zip | |
13/2/2020 - 1:47:10.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:47:10.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | |
13/2/2020 - 1:47:10.340 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | diasymreader.dll |
13/2/2020 - 1:47:10.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | |
13/2/2020 - 1:47:10.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | diasymreader.dll |
13/2/2020 - 1:47:10.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | diasymreader.dll |
13/2/2020 - 1:47:10.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | diasymreader.dll |
13/2/2020 - 1:47:10.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | diasymreader.dll |
13/2/2020 - 1:47:10.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | diasymreader.dll |
13/2/2020 - 1:47:10.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | |
13/2/2020 - 1:47:10.340 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | diasymreader.dll |
13/2/2020 - 1:47:10.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | diasymreader.dll |
13/2/2020 - 1:47:10.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | diasymreader.dll |
13/2/2020 - 1:47:10.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe.Local | |
13/2/2020 - 1:47:10.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc | |
13/2/2020 - 1:47:10.340 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc | |
13/2/2020 - 1:47:10.340 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc | |
13/2/2020 - 1:47:10.340 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | diasymreader.dll |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | diasymreader.dll |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | diasymreader.dll |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | diasymreader.dll |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | diasymreader.dll |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | diasymreader.dll |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | diasymreader.dll |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | diasymreader.dll |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | diasymreader.dll |
13/2/2020 - 1:47:10.356 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | diasymreader.dll |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.dll | System.Management.Automation.dll |
13/2/2020 - 1:47:10.356 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\System.Management.Automation.pdb | |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll | diasymreader.dll |
13/2/2020 - 1:47:10.356 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\symbols\dll\System.Management.Automation.pdb | |
13/2/2020 - 1:47:10.356 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\dll\System.Management.Automation.pdb | |
13/2/2020 - 1:47:10.356 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\System.Management.Automation.pdb | |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll | mscorlib.resources.dll |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:47:10.356 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll | |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll | |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll | |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll | |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll | |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll | |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll | |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll | |
13/2/2020 - 1:47:10.356 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.pdb | |
13/2/2020 - 1:47:10.356 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\symbols\dll\System.pdb | |
13/2/2020 - 1:47:10.356 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\dll\System.pdb | |
13/2/2020 - 1:47:10.356 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\System.pdb | |
13/2/2020 - 1:47:10.356 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:47:10.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:47:10.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:47:10.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:47:10.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:47:10.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:47:10.372 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:47:10.403 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\System.Management.Automation.Resources.dll | System.Management.Automation.Resources.dll |
13/2/2020 - 1:47:10.403 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll | mscorlib.resources.dll |
13/2/2020 - 1:47:10.403 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pt-BR_b77a5c561934e089\mscorlib.resources.dll | mscorlib.resources.dll |
13/2/2020 - 1:47:10.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\sxs.dll | |
13/2/2020 - 1:47:10.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\sxs.dll | |
13/2/2020 - 1:47:10.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\sxs.dll | |
13/2/2020 - 1:47:10.575 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\RpcRtRemote.dll | |
13/2/2020 - 1:47:10.575 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\RpcRtRemote.dll | |
13/2/2020 - 1:47:10.575 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\RpcRtRemote.dll | RpcRtRemote.dll |
13/2/2020 - 1:47:10.575 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\RpcRtRemote.dll | |
13/2/2020 - 1:47:10.575 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\RpcRtRemote.dll | RpcRtRemote.dll |
13/2/2020 - 1:47:10.762 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.762 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\shell32.dll | |
13/2/2020 - 1:47:10.809 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:47:10.872 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:47:10.887 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:47:10.887 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:47:10.887 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:47:10.887 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:47:10.887 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep | |
13/2/2020 - 1:47:10.887 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep | |
13/2/2020 - 1:47:10.887 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep\vNmJP.zip | |
13/2/2020 - 1:47:10.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep\file1.tmp | |
13/2/2020 - 1:47:10.997 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep\file1.tmp | |
13/2/2020 - 1:47:11.59 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\Microsoft.PowerShell.Commands.Management.resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:47:11.59 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:47:11.106 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:47:11.106 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.Resources.dll | |
13/2/2020 - 1:47:11.106 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.Resources.dll | Microsoft.PowerShell.Commands.Management.Resources.dll |
13/2/2020 - 1:47:11.106 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.Resources.dll | |
13/2/2020 - 1:47:11.106 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.Resources.dll | Microsoft.PowerShell.Commands.Management.Resources.dll |
13/2/2020 - 1:47:11.153 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.Resources.dll | Microsoft.PowerShell.Commands.Management.Resources.dll |
13/2/2020 - 1:47:11.200 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.Resources.dll | Microsoft.PowerShell.Commands.Management.Resources.dll |
13/2/2020 - 1:47:11.247 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.Resources.dll | Microsoft.PowerShell.Commands.Management.Resources.dll |
13/2/2020 - 1:47:11.293 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:47:11.293 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:47:11.293 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.Resources.dll | |
13/2/2020 - 1:47:11.293 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.Resources.dll | |
13/2/2020 - 1:47:11.293 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.Resources.dll | Microsoft.PowerShell.Commands.Management.Resources.dll |
13/2/2020 - 1:47:11.293 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.Resources.dll | |
13/2/2020 - 1:47:11.293 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.Resources.dll | Microsoft.PowerShell.Commands.Management.Resources.dll |
13/2/2020 - 1:47:11.293 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.Resources.dll | Microsoft.PowerShell.Commands.Management.Resources.dll |
13/2/2020 - 1:47:11.372 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep\file2.tmp | |
13/2/2020 - 1:47:11.372 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep\file2.tmp | |
13/2/2020 - 1:47:11.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_32\Microsoft.PowerShell.Commands.Utility.resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:47:11.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:47:11.403 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:47:11.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.Resources.dll | |
13/2/2020 - 1:47:11.403 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.Resources.dll | Microsoft.PowerShell.Commands.Utility.Resources.dll |
13/2/2020 - 1:47:11.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.Resources.dll | |
13/2/2020 - 1:47:11.403 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.Resources.dll | Microsoft.PowerShell.Commands.Utility.Resources.dll |
13/2/2020 - 1:47:11.403 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.Resources.dll | Microsoft.PowerShell.Commands.Utility.Resources.dll |
13/2/2020 - 1:47:11.403 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.Resources.dll | Microsoft.PowerShell.Commands.Utility.Resources.dll |
13/2/2020 - 1:47:11.403 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.Resources.dll | Microsoft.PowerShell.Commands.Utility.Resources.dll |
13/2/2020 - 1:47:11.403 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.Resources.dll | Microsoft.PowerShell.Commands.Utility.Resources.dll |
13/2/2020 - 1:47:11.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:47:11.403 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility.Resources\1.0.0.0_pt-BR_31bf3856ad364e35 | |
13/2/2020 - 1:47:11.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.Resources.dll | |
13/2/2020 - 1:47:11.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.Resources.dll | |
13/2/2020 - 1:47:11.403 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.Resources.dll | Microsoft.PowerShell.Commands.Utility.Resources.dll |
13/2/2020 - 1:47:11.403 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.Resources.dll | |
13/2/2020 - 1:47:11.403 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.Resources.dll | Microsoft.PowerShell.Commands.Utility.Resources.dll |
13/2/2020 - 1:47:11.403 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility.Resources\1.0.0.0_pt-BR_31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.Resources.dll | Microsoft.PowerShell.Commands.Utility.Resources.dll |
13/2/2020 - 1:47:11.418 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\LogPRO | |
13/2/2020 - 1:47:11.418 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\LogPRO | |
13/2/2020 - 1:47:11.418 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\LogPRO | |
13/2/2020 - 1:47:11.418 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\LogPRO | |
13/2/2020 - 1:47:11.434 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.434 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.434 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\mpr.dll | |
13/2/2020 - 1:47:11.434 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\mpr.dll | |
13/2/2020 - 1:47:11.434 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\scrrun.dll | |
13/2/2020 - 1:47:11.434 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\scrrun.dll | |
13/2/2020 - 1:47:11.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.481 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\wshom.ocx | |
13/2/2020 - 1:47:11.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vNmJP.lnk | |
13/2/2020 - 1:47:11.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vNmJP.lnk\desktop.ini | |
13/2/2020 - 1:47:11.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vNmJP.lnk\desktop.ini | |
13/2/2020 - 1:47:11.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:47:11.481 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:47:11.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep | |
13/2/2020 - 1:47:11.481 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep | |
13/2/2020 - 1:47:11.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep\vNmJP.exe | |
13/2/2020 - 1:47:11.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:47:11.481 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:47:11.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep\vNmJP.exe | |
13/2/2020 - 1:47:11.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vNmJP.lnk | |
13/2/2020 - 1:47:11.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\SysxGVep\vNmJP.exe | |
13/2/2020 - 1:47:11.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vNmJP.lnk | |
13/2/2020 - 1:47:11.481 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vNmJP.lnk | |
13/2/2020 - 1:47:11.497 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\vNmJP.lnk | |
13/2/2020 - 1:47:11.512 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\%SystemRoot%\system32\WindowsPowerShell\v1.0\ | |
13/2/2020 - 1:47:11.512 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll | mscorlib.ni.dll |
13/2/2020 - 1:47:11.559 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\%SystemRoot%\system32\WindowsPowerShell\v1.0\ | |
13/2/2020 - 1:47:11.559 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\%SystemRoot%\system32\WindowsPowerShell\v1.0\ | |
13/2/2020 - 1:47:11.559 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\%SystemRoot%\system32\WindowsPowerShell\v1.0\ | |
13/2/2020 - 1:47:11.559 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\%SystemRoot%\system32\WindowsPowerShell\v1.0\ | |
13/2/2020 - 1:47:11.559 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\%SystemRoot%\system32\WindowsPowerShell\v1.0\ | |
13/2/2020 - 1:47:11.559 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\%SystemRoot%\system32\WindowsPowerShell\v1.0\ | |
13/2/2020 - 1:47:11.559 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\%SystemRoot%\system32\WindowsPowerShell\v1.0\ | |
13/2/2020 - 1:47:11.559 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\%SystemRoot%\system32\WindowsPowerShell\v1.0\ | |
13/2/2020 - 1:47:11.559 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\%SystemRoot%\system32\WindowsPowerShell\v1.0\ | |
13/2/2020 - 1:47:11.559 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\%SystemRoot%\system32\WindowsPowerShell\v1.0\ | |
13/2/2020 - 1:47:11.559 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\%SystemRoot%\system32\WindowsPowerShell\v1.0\ | |
13/2/2020 - 1:47:11.559 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\%SystemRoot%\system32\WindowsPowerShell\v1.0\ | |
13/2/2020 - 1:47:11.559 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\%SystemRoot%\system32\WindowsPowerShell\v1.0\ | |
13/2/2020 - 1:47:11.559 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor\%SystemRoot%\system32\WindowsPowerShell\v1.0\ | |
13/2/2020 - 1:47:11.559 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:47:11.559 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:47:11.559 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:47:11.559 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:47:11.559 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:47:11.559 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:47:11.559 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:47:11.559 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:47:11.559 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:47:11.559 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:47:11.559 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\cmd.exe | |
13/2/2020 - 1:47:11.622 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\GAC_MSIL\System.Management.Automation\1.0.0.0__31bf3856ad364e35\shell32.dll | |
13/2/2020 - 1:47:11.622 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\cmd.exe | |
13/2/2020 - 1:47:11.715 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor | |
13/2/2020 - 1:47:11.715 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Monitor | |
13/2/2020 - 1:47:11.715 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\cmd.exe | |
13/2/2020 - 1:47:11.715 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\cmd.exe | |
13/2/2020 - 1:47:11.715 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\cmd.exe | |
13/2/2020 - 1:47:11.715 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\AppPatch\sysmain.sdb | |
13/2/2020 - 1:47:11.715 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:47:11.715 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:47:11.715 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\cmd.exe | |
13/2/2020 - 1:47:11.715 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:47:11.715 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\ | |
13/2/2020 - 1:47:11.715 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows | |
13/2/2020 - 1:47:11.715 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows | |
13/2/2020 - 1:47:11.715 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:47:11.715 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:47:11.715 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:47:11.715 | Unknown | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:47:11.715 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\cmd.exe | |
13/2/2020 - 1:47:11.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\cmd.exe | |
13/2/2020 - 1:47:11.715 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\cmd.exe | |
13/2/2020 - 1:47:11.715 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\ui\SwDRM.dll | |
13/2/2020 - 1:47:11.731 | Read | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\assembly\NativeImages_v2.0.50727_32\System\67c97ffbe01458a63ecb518c7444c1f1\System.ni.dll | System.ni.dll |
13/2/2020 - 1:47:11.731 | Open | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | C:\Windows\SysWOW64\cmd.exe | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\Prefetch\CMD.EXE-AC113AA8.pf | |
13/2/2020 - 1:47:11.778 | Read | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\Prefetch\CMD.EXE-AC113AA8.pf | CMD.EXE-AC113AA8.pf |
13/2/2020 - 1:47:11.778 | Read | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\Prefetch\CMD.EXE-AC113AA8.pf | CMD.EXE-AC113AA8.pf |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | \Device\HarddiskVolume2 | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\AppPatch | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\AppPatch | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\AppPatch | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\Globalization | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\Globalization | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\Globalization | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\Globalization\Sorting | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\Globalization\Sorting | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\Globalization\Sorting | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32 | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32 | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32 | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64 | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\Temp | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\Temp | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\Temp | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\ntdll.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\ntdll.dll | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\wow64.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\wow64.dll | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\wow64win.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\wow64win.dll | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\wow64cpu.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\wow64cpu.dll | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\kernel32.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\kernel32.dll | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\kernel32.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\kernel32.dll | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\user32.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\user32.dll | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\ntdll.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\ntdll.dll | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\apisetschema.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\apisetschema.dll | apisetschema.dll |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\KernelBase.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\KernelBase.dll | KernelBase.dll |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\locale.nls | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\locale.nls | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\cmd.exe | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\cmd.exe | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\msvcrt.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\msvcrt.dll | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\winbrand.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\winbrand.dll | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\user32.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\user32.dll | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\gdi32.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\gdi32.dll | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\lpk.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\lpk.dll | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\usp10.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\usp10.dll | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\advapi32.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\advapi32.dll | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\sechost.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\sechost.dll | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\rpcrt4.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\rpcrt4.dll | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\sspicli.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\sspicli.dll | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\cryptbase.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\cryptbase.dll | cryptbase.dll |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\imm32.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\imm32.dll | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\msctf.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\msctf.dll | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\Globalization\Sorting\SortDefault.nls | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\Globalization\Sorting\SortDefault.nls | SortDefault.nls |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\apphelp.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\apphelp.dll | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\BOOTSECT.EXE | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\AppPatch\sysmain.sdb | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\AppPatch\sysmain.sdb | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\Temp\TMP000000032EDF9B37C5E17B29 | |
13/2/2020 - 1:47:11.778 | Read | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\cmd.exe | |
13/2/2020 - 1:47:11.778 | Read | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\winbrand.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\locale.nls | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\Globalization\Sorting\SortDefault.nls | SortDefault.nls |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\AppPatch\sysmain.sdb | |
13/2/2020 - 1:47:11.778 | Read | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\winbrand.dll | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\BOOTSECT.EXE | |
13/2/2020 - 1:47:11.778 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\Temp\TMP000000032EDF9B37C5E17B29 | |
13/2/2020 - 1:47:11.778 | Read | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\winbrand.dll | |
13/2/2020 - 1:47:11.778 | Read | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\winbrand.dll | |
13/2/2020 - 1:47:11.778 | Read | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\winbrand.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\ntdll.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\wow64.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\wow64win.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\wow64cpu.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\kernel32.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\kernel32.dll | |
13/2/2020 - 1:47:11.778 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\user32.dll | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\ntdll.dll | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\apisetschema.dll | apisetschema.dll |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\KernelBase.dll | KernelBase.dll |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\cmd.exe | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\msvcrt.dll | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\user32.dll | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\gdi32.dll | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\lpk.dll | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\usp10.dll | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\advapi32.dll | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\sechost.dll | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\rpcrt4.dll | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\sspicli.dll | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\cryptbase.dll | cryptbase.dll |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\imm32.dll | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\msctf.dll | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\apphelp.dll | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | \Device\HarddiskVolume2 | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\wow64.dll | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\wow64.dll | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\wow64win.dll | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\wow64win.dll | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\wow64cpu.dll | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\wow64cpu.dll | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\System32\wow64log.dll | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Monitor | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\winbrand.dll | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\winbrand.dll | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\sechost.dll | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\sechost.dll | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\imm32.dll | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\imm32.dll | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\imm32.dll | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\imm32.dll | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\imm32.dll | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Windows\SysWOW64\imm32.dll | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Monitor | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Monitor | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\ | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\ | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Monitor | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\Monitor | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\ | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\ | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\SysxGVep | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\SysxGVep | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\SysxGVep | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\SysxGVep | |
13/2/2020 - 1:47:11.793 | Open | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\SysxGVep | |
13/2/2020 - 1:47:11.793 | Unknown | 1096 | C:\Windows\SysWOW64\cmd.exe | C:\SysxGVep |
Process
Trace
13/2/2020 - 1:45:58.106 | Create | 1480 | C:\malware.exe | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
13/2/2020 - 1:47:11.715 | Create | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | 1096 | C:\Windows\SysWOW64\cmd.exe |
Analysis
Reason
Timeout
Status
Sucessfully Executed
Results
1
Registry
Trace
13/2/2020 - 1:45:57.887 | Write | 1480 | C:\malware.exe | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap | ProxyBypass |
13/2/2020 - 1:45:57.887 | Write | 1480 | C:\malware.exe | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap | IntranetName |
13/2/2020 - 1:45:57.887 | Write | 1480 | C:\malware.exe | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap | UNCAsIntranet |
13/2/2020 - 1:45:57.887 | Write | 1480 | C:\malware.exe | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap | AutoDetect |
13/2/2020 - 1:45:57.887 | Write | 1480 | C:\malware.exe | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap | ProxyBypass |
13/2/2020 - 1:45:57.887 | Write | 1480 | C:\malware.exe | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap | IntranetName |
13/2/2020 - 1:45:57.887 | Write | 1480 | C:\malware.exe | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap | UNCAsIntranet |
13/2/2020 - 1:45:57.887 | Write | 1480 | C:\malware.exe | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap | AutoDetect |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.465 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.481 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.590 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.590 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.590 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.590 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.590 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.590 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.590 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.590 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.590 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.606 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.606 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.606 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.606 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.606 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.637 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:45:58.637 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | HKCU\Local Settings\MuiCache\5\96383CDB | LanguageList |
13/2/2020 - 1:46:48.340 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32 | EnableFileTracing |
13/2/2020 - 1:46:48.340 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32 | EnableConsoleTracing |
13/2/2020 - 1:46:48.340 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32 | FileTracingMask |
13/2/2020 - 1:46:48.340 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32 | ConsoleTracingMask |
13/2/2020 - 1:46:48.340 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32 | MaxFileSize |
13/2/2020 - 1:46:48.340 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASAPI32 | FileDirectory |
13/2/2020 - 1:46:48.903 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS | EnableFileTracing |
13/2/2020 - 1:46:48.903 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS | EnableConsoleTracing |
13/2/2020 - 1:46:48.903 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS | FileTracingMask |
13/2/2020 - 1:46:48.903 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS | ConsoleTracingMask |
13/2/2020 - 1:46:48.903 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS | MaxFileSize |
13/2/2020 - 1:46:48.903 | Write | 2412 | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | \REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\powershell_RASMANCS | FileDirectory |
File Summary
Created
Identified: True check_circle
Deleted
Identified: True check_circle
Process Summary
Created
Identified: True check_circle
Deleted
Identified: False cancel
Registry Summary
Proxy
Identified: False cancel
AutoRun
Identified: False cancel
Created
Identified: True check_circle
Deleted
Identified: False cancel
Browsers
Identified: False cancel
Internet
Identified: True check_circle
Loading...
DNS
Query
computer localhost arrow_forward computer gateway:50273 code dns.msftncsi.com. computer localhost arrow_forward computer gateway:DNS code dns.msftncsi.com.
Response
computer gateway:DNS arrow_forward computer localhost code dns.msftncsi.com. reply_all 131.107.255.255
TCP
Info
computer localhost:65191 arrow_forward 45.32.121.105:80
UDP
Info
computer localhost:50273 arrow_forward computer localhost:53computer localhost:53 arrow_forward computer localhost:50273
HTTP
Info
Summary
DNS
True check_circle
TCP
True check_circle
UDP
True check_circle
HTTP
False cancel
Results
BINARY
KNN (K=3, NFS-BRMalware)
confidence: 66.67%suspicious: False cancel
Decision Tree (NFS-BRMalware)
confidence: 100.00%suspicious: False cancel
SVC (Kernel=Linear, NFS-BRMalware)
confidence: 96.86%suspicious: False cancel
MalConv (Ember: Raw Bytes, Threshold=0.5)
confidence: 67.83%suspicious: False cancel
Random Forest (100 estimators, NFS-BRMalware)
confidence: 71.00%suspicious: False cancel
Non-Negative MalConv (Ember: Raw Bytes, Threshold=0.35)
confidence: 42.59%suspicious: True check_circle
LightGDM (Ember: File Characteristics, Threshold=0.8336)
confidence: 99.98%suspicious: False cancel