casthemes.blogg.se

Procmon logs
Procmon logs













procmon logs

procmon logs

WinFabric_BuildDestinationCache=C:\MCRoot\BinCache\bins USERPROFILE=D:\Windows\ServiceProfiles\NetworkService TMP=D:\Windows\SERVIC~2\NETWOR~1\AppData\Local\Temp TEMP=D:\Windows\SERVIC~2\NETWOR~1\AppData\Local\Temp PSModulePath=D:\Windows\system32\WindowsPowerShell\v1.0\Modules\ d:\Program Files\Microsoft Security Client\MpProvider\ ProgramFiles(x86)=D:\Program Files (x86) PROCESSOR_IDENTIFIER=Intel64 Family 6 Model 45 Stepping 7, GenuineIntel Path=D:\Windows\system32 D:\Windows D:\Windows\System32\Wbem D:\Windows\System32\WindowsPowerShell\v1.0\ E:\base\圆4 E:\base\x86 D:\Packages\GuestAgent\GuestAgent\LegacyRuntime\圆4 D:\Packages\GuestAgent\GuestAgent\LegacyRuntime\x86 D:\Program Files\Windows Fabric\bin\Fabric\Fabric.Code D:\Program Files\Microsoft Service Fabric\bin\Fabric\Fabric.Code D:\Program Files (x86)\Magellan Toolset 5.2\ ĜommonProgramW6432=D:\Program Files\Common Files ĜommonProgramFiles(x86)=D:\Program Files (x86)\Common Files ĜommonProgramFiles=D:\Program Files\Common Files ĚPPDATA=D:\Windows\ServiceProfiles\NetworkService\AppData\Roaming "Time of Day","Process Name","PID","Operation","Path","Result","Detail" "QueryOpen","D:\Users\testadm\dotnet\host\fxr","ACCESS DENIED","" "CreateFile","D:\Users\testadm\dotnet\dotnet.exe","ACCESS DENIED","Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a"















Procmon logs