Code: Select all
10:36:06.1154291 PM firefox.exe 1544 CreateFile C:\Users\golf\Desktop SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
10:36:06.1154591 PM firefox.exe 1544 QueryAttributeTagFile C:\Users\golf\Desktop SUCCESS Attributes: D, ReparseTag: 0x0
10:36:06.1154705 PM firefox.exe 1544 QueryAttributeTagFile C:\Sandbox\golf\firefox\user\current\Desktop SUCCESS Attributes: DNCI, ReparseTag: 0x0
10:36:06.1154828 PM firefox.exe 1544 QueryDirectory C:\Sandbox\golf\firefox\user\current\Desktop\air3-5_win.exe SUCCESS Filter: air3-5_win.exe, 1: air3-5_win.exe
10:36:06.1155014 PM firefox.exe 1544 QueryDirectory C:\Users\golf\Desktop\air3-5_win.exe NO SUCH FILE Filter: air3-5_win.exe