writeoff | 28.06.2015 18:26 | Hallo schrauber,
die Datei ist so groß, dass beim Export in CSV gut 400.000 Zeilen verloren gehen. Ich habe jetzt erst mal einen Filter auf Path enthält rpcnet gesetzt. Brauchst Du alle Zeilen, und wenn ja, wie bekommen wir die transportiert?
Hier der Auszug aller Zeilen mit RPCNET im Path:
Beste Grüße
writeoff Code:
Time of Day,"Process Name","PID","Operation","Path","Result","Detail"
19:04:09,0097445,"autochk.exe","352","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Generic Read, Delete, Disposition: Supersede, Options: Write Through, Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, AllocationSize: 0, OpenResult: Created"
19:04:09,0101762,"autochk.exe","352","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:09,0104201,"autochk.exe","352","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:09,0104647,"autochk.exe","352","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Generic Read/Write, Delete, Disposition: Supersede, Options: Write Through, Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, AllocationSize: 0, OpenResult: Superseded"
19:04:09,0107156,"autochk.exe","352","IRP_MJ_WRITE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Offset: 0, Length: 17.408, I/O Flags: Write Through, Priority: Normal"
19:04:09,0108862,"autochk.exe","352","FASTIO_ACQUIRE_FOR_CC_FLUSH","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:09,0108965,"autochk.exe","352","IRP_MJ_WRITE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Offset: 0, Length: 20.480, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal"
19:04:09,0110281,"autochk.exe","352","FASTIO_RELEASE_FOR_CC_FLUSH","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:09,0111669,"autochk.exe","352","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:09,0113771,"autochk.exe","352","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Desired Access: Generic Read, Delete, Disposition: Supersede, Options: Write Through, Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, AllocationSize: 0, OpenResult: Created"
19:04:09,0117469,"autochk.exe","352","IRP_MJ_CLEANUP","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS",""
19:04:09,0118719,"autochk.exe","352","IRP_MJ_CLOSE","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS",""
19:04:09,0119172,"autochk.exe","352","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Desired Access: Generic Read/Write, Delete, Disposition: Supersede, Options: Write Through, Synchronous IO Non-Alert, Attributes: N, ShareMode: Read, Write, AllocationSize: 0, OpenResult: Superseded"
19:04:09,0121649,"autochk.exe","352","IRP_MJ_WRITE","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Offset: 0, Length: 17.408, I/O Flags: Write Through, Priority: Normal"
19:04:09,0125931,"autochk.exe","352","FASTIO_ACQUIRE_FOR_CC_FLUSH","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS",""
19:04:09,0126027,"autochk.exe","352","IRP_MJ_WRITE","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Offset: 0, Length: 20.480, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal"
19:04:09,0127315,"autochk.exe","352","FASTIO_RELEASE_FOR_CC_FLUSH","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS",""
19:04:09,0128660,"autochk.exe","352","IRP_MJ_CLEANUP","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS",""
19:04:09,0129913,"autochk.exe","352","RegCreateKey","HKLM\System\CurrentControlSet\Services\rpcnetp","REPARSE","Desired Access: All Access"
19:04:09,0130026,"autochk.exe","352","RegCreateKey","HKLM\System\CurrentControlSet\Services\rpcnetp","SUCCESS","Desired Access: All Access, Disposition: REG_CREATED_NEW_KEY"
19:04:09,0130670,"autochk.exe","352","RegSetInfoKey","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
19:04:09,0130791,"autochk.exe","352","RegSetValue","HKLM\System\CurrentControlSet\services\rpcnetp\ErrorControl","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
19:04:09,0131396,"autochk.exe","352","RegSetValue","HKLM\System\CurrentControlSet\services\rpcnetp\Start","SUCCESS","Type: REG_DWORD, Length: 4, Data: 2"
19:04:09,0132383,"autochk.exe","352","RegSetValue","HKLM\System\CurrentControlSet\services\rpcnetp\Type","SUCCESS","Type: REG_DWORD, Length: 4, Data: 16"
19:04:09,0133020,"autochk.exe","352","RegQueryKey","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS","Query: HandleTags, HandleTags: 0x400"
19:04:09,0133127,"autochk.exe","352","RegSetValue","HKLM\System\CurrentControlSet\services\rpcnetp\ImagePath","SUCCESS","Type: REG_EXPAND_SZ, Length: 68, Data: %SystemRoot%\System32\rpcnetp.exe"
19:04:09,0134132,"autochk.exe","352","RegQueryKey","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS","Query: HandleTags, HandleTags: 0x400"
19:04:09,0134202,"autochk.exe","352","RegSetValue","HKLM\System\CurrentControlSet\services\rpcnetp\ObjectName","SUCCESS","Type: REG_SZ, Length: 24, Data: LocalSystem"
19:04:09,0134786,"autochk.exe","352","RegSetValue","HKLM\System\CurrentControlSet\services\rpcnetp\(Default)","SUCCESS","Type: REG_BINARY, Length: 128, Data: 00 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00"
19:04:09,0135990,"autochk.exe","352","RegCloseKey","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS",""
19:04:09,4570518,"System","4","IRP_MJ_SET_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: SetEndOfFileInformationFile, EndOfFile: 17.408"
19:04:09,4570568,"System","4","IRP_MJ_SET_INFORMATION","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Type: SetEndOfFileInformationFile, EndOfFile: 17.408"
19:04:09,4570614,"System","4","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","SyncType: SyncTypeOther"
19:04:09,4570635,"System","4","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","SyncType: SyncTypeOther"
19:04:09,4570667,"System","4","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:09,4570702,"System","4","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS",""
19:04:14,3098393,"autochk.exe","352","FASTIO_ACQUIRE_FOR_CC_FLUSH","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:14,3098687,"autochk.exe","352","FASTIO_RELEASE_FOR_CC_FLUSH","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:14,3099019,"autochk.exe","352","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:14,3099239,"autochk.exe","352","FASTIO_ACQUIRE_FOR_CC_FLUSH","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS",""
19:04:14,3099398,"autochk.exe","352","FASTIO_RELEASE_FOR_CC_FLUSH","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS",""
19:04:14,3099614,"autochk.exe","352","IRP_MJ_CLOSE","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS",""
19:04:19,9110192,"services.exe","704","RegOpenKey","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS","Desired Access: Read"
19:04:19,9110365,"services.exe","704","RegQueryValue","HKLM\System\CurrentControlSet\services\rpcnetp\Type","SUCCESS","Type: REG_DWORD, Length: 4, Data: 16"
19:04:19,9110429,"services.exe","704","RegQueryValue","HKLM\System\CurrentControlSet\services\rpcnetp\Start","SUCCESS","Type: REG_DWORD, Length: 4, Data: 2"
19:04:19,9110478,"services.exe","704","RegQueryValue","HKLM\System\CurrentControlSet\services\rpcnetp\ErrorControl","SUCCESS","Type: REG_DWORD, Length: 4, Data: 1"
19:04:19,9110528,"services.exe","704","RegQueryValue","HKLM\System\CurrentControlSet\services\rpcnetp\Tag","NAME NOT FOUND","Length: 16"
19:04:19,9110585,"services.exe","704","RegQueryValue","HKLM\System\CurrentControlSet\services\rpcnetp\Group","NAME NOT FOUND","Length: 268"
19:04:19,9110638,"services.exe","704","RegQueryValue","HKLM\System\CurrentControlSet\services\rpcnetp\DependOnService","NAME NOT FOUND","Length: 268"
19:04:19,9110691,"services.exe","704","RegQueryValue","HKLM\System\CurrentControlSet\services\rpcnetp\DependOnGroup","NAME NOT FOUND","Length: 268"
19:04:19,9110762,"services.exe","704","RegOpenKey","HKLM\System\CurrentControlSet\services\rpcnetp\Security","NAME NOT FOUND","Desired Access: Read"
19:04:19,9110815,"services.exe","704","RegQueryValue","HKLM\System\CurrentControlSet\services\rpcnetp\PreferredNode","NAME NOT FOUND","Length: 14"
19:04:19,9110871,"services.exe","704","RegQueryValue","HKLM\System\CurrentControlSet\services\rpcnetp\DisplayName","NAME NOT FOUND","Length: 268"
19:04:19,9110921,"services.exe","704","RegQueryValue","HKLM\System\CurrentControlSet\services\rpcnetp\DelayedAutostart","NAME NOT FOUND","Length: 16"
19:04:19,9110970,"services.exe","704","RegQueryValue","HKLM\System\CurrentControlSet\services\rpcnetp\ServiceSidType","NAME NOT FOUND","Length: 16"
19:04:19,9111020,"services.exe","704","RegQueryValue","HKLM\System\CurrentControlSet\services\rpcnetp\FailureActionsOnNonCrashFailures","NAME NOT FOUND","Length: 16"
19:04:19,9111190,"services.exe","704","RegQueryValue","HKLM\System\CurrentControlSet\services\rpcnetp\DeleteFlag","NAME NOT FOUND","Length: 16"
19:04:19,9111246,"services.exe","704","RegQueryValue","HKLM\System\CurrentControlSet\services\rpcnetp\RequiredPrivileges","NAME NOT FOUND","Length: 12"
19:04:19,9111307,"services.exe","704","RegCloseKey","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS",""
19:04:20,3486639,"services.exe","704","RegOpenKey","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS","Desired Access: Read"
19:04:20,3486717,"services.exe","704","RegOpenKey","HKLM\System\CurrentControlSet\services\rpcnetp\TriggerInfo","NAME NOT FOUND","Desired Access: Read"
19:04:20,3486784,"services.exe","704","RegCloseKey","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS",""
19:04:20,7057318,"services.exe","704","RegOpenKey","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS","Desired Access: Read"
19:04:20,7057389,"services.exe","704","RegQueryValue","HKLM\System\CurrentControlSet\services\rpcnetp\ObjectName","SUCCESS","Type: REG_SZ, Length: 24, Data: LocalSystem"
19:04:20,7057456,"services.exe","704","RegCloseKey","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS",""
19:04:29,4731458,"services.exe","704","RegOpenKey","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS","Desired Access: Read"
19:04:29,4731610,"services.exe","704","RegOpenKey","HKLM\System\CurrentControlSet\services\rpcnetp\TriggerInfo","NAME NOT FOUND","Desired Access: Read"
19:04:29,4731748,"services.exe","704","RegCloseKey","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS",""
19:04:29,4731975,"services.exe","704","RegOpenKey","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS","Desired Access: Read"
19:04:29,4732106,"services.exe","704","RegOpenKey","HKLM\System\CurrentControlSet\services\rpcnetp\TriggerInfo","NAME NOT FOUND","Desired Access: Read"
19:04:29,4732226,"services.exe","704","RegCloseKey","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS",""
19:04:31,9816028,"services.exe","704","RegOpenKey","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS","Desired Access: Read"
19:04:31,9816198,"services.exe","704","RegQueryValue","HKLM\System\CurrentControlSet\services\rpcnetp\ImagePath","SUCCESS","Type: REG_EXPAND_SZ, Length: 68, Data: %SystemRoot%\System32\rpcnetp.exe"
19:04:31,9816308,"services.exe","704","RegQueryValue","HKLM\System\CurrentControlSet\services\rpcnetp\WOW64","NAME NOT FOUND","Length: 16"
19:04:31,9816389,"services.exe","704","RegCloseKey","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS",""
19:04:31,9816517,"services.exe","704","RegOpenKey","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS","Desired Access: Read"
19:04:31,9816637,"services.exe","704","RegQueryValue","HKLM\System\CurrentControlSet\services\rpcnetp\ObjectName","SUCCESS","Type: REG_SZ, Length: 24, Data: LocalSystem"
19:04:31,9816718,"services.exe","704","RegCloseKey","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS",""
19:04:31,9836814,"services.exe","704","RegOpenKey","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS","Desired Access: Read"
19:04:31,9837061,"services.exe","704","RegQueryValue","HKLM\System\CurrentControlSet\services\rpcnetp\Environment","NAME NOT FOUND","Length: 268"
19:04:31,9837175,"services.exe","704","RegCloseKey","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS",""
19:04:31,9837929,"services.exe","704","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\System32\rpcnetp.exe","FAST IO DISALLOWED",""
19:04:31,9838491,"services.exe","704","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:32,0438885,"services.exe","704","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:04:32,0439006,"services.exe","704","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0439154,"services.exe","704","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0440393,"services.exe","704","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\System32\rpcnetp.exe","FAST IO DISALLOWED",""
19:04:32,0440952,"services.exe","704","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:32,0441257,"services.exe","704","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:04:32,0441373,"services.exe","704","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0441490,"services.exe","704","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0442308,"services.exe","704","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:32,0444176,"AVKWCtlx64.exe","476","IRP_MJ_READ","C:\Windows\System32\rpcnetp.exe","SUCCESS","Offset: 0, Length: 4.096, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
19:04:32,0618413,"System","4","IRP_MJ_READ","C:\Windows\System32\rpcnetp.exe","SUCCESS","Offset: 4.096, Length: 13.312, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
19:04:32,0619000,"services.exe","704","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
19:04:32,0635606,"services.exe","704","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryStandardInformationFile, AllocationSize: 20.480, EndOfFile: 17.408, NumberOfLinks: 1, DeletePending: False, Directory: False"
19:04:32,0635875,"services.exe","704","FASTIO_ACQUIRE_FOR_CC_FLUSH","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0635981,"services.exe","704","FASTIO_RELEASE_FOR_CC_FLUSH","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0636102,"services.exe","704","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0636208,"services.exe","704","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","SyncType: SyncTypeOther"
19:04:32,0636282,"services.exe","704","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0636484,"services.exe","704","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rpcnetp.exe","NAME NOT FOUND","Desired Access: Query Value, Enumerate Sub Keys"
19:04:32,0637436,"services.exe","704","IRP_MJ_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryNameInformationFile, Name: \Windows\System32\rpcnetp.exe"
19:04:32,0638070,"services.exe","704","Process Create","C:\Windows\System32\rpcnetp.exe","SUCCESS","PID: 2592, Command line: C:\Windows\System32\rpcnetp.exe"
19:04:32,0639029,"services.exe","704","IRP_MJ_QUERY_SECURITY","C:\Windows\System32\rpcnetp.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label"
19:04:32,0639170,"services.exe","704","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:04:32,0659301,"services.exe","704","IRP_MJ_DIRECTORY_CONTROL","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryDirectory, Filter: rpcnetp.exe, 2: rpcnetp.exe"
19:04:32,0660370,"services.exe","704","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\System32\rpcnetp.exe","FAST IO DISALLOWED",""
19:04:32,0660869,"services.exe","704","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:32,0661198,"services.exe","704","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:04:32,0661350,"services.exe","704","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0661630,"services.exe","704","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0664935,"services.exe","704","IRP_MJ_DIRECTORY_CONTROL","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryDirectory, Filter: rpcnetp.exe, 2: rpcnetp.exe"
19:04:32,0667052,"services.exe","704","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\C:\Windows\System32\rpcnetp.exe","NAME NOT FOUND","Length: 1.024"
19:04:32,0667593,"services.exe","704","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\rpcnetp.exe","NAME NOT FOUND","Desired Access: Read"
19:04:32,0695507,"services.exe","704","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
19:04:32,0698363,"services.exe","704","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryStandardInformationFile, AllocationSize: 20.480, EndOfFile: 17.408, NumberOfLinks: 1, DeletePending: False, Directory: False"
19:04:32,0698752,"services.exe","704","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryStandardInformationFile, AllocationSize: 20.480, EndOfFile: 17.408, NumberOfLinks: 1, DeletePending: False, Directory: False"
19:04:32,0699014,"services.exe","704","IRP_MJ_READ","C:\Windows\System32\rpcnetp.exe","SUCCESS","Offset: 16.384, Length: 1.024, Priority: Normal"
19:04:32,0699562,"services.exe","704","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0699700,"services.exe","704","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0727309,"services.exe","704","IRP_MJ_QUERY_SECURITY","C:\Windows\System32\rpcnetp.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label"
19:04:32,0727462,"services.exe","704","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:04:32,0727621,"services.exe","704","IRP_MJ_QUERY_SECURITY","C:\Windows\System32\rpcnetp.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label"
19:04:32,0727748,"services.exe","704","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:04:32,0728484,"services.exe","704","IRP_MJ_QUERY_SECURITY","C:\Windows\System32\rpcnetp.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label"
19:04:32,0729787,"csrss.exe","528","IRP_MJ_QUERY_SECURITY","C:\Windows\System32\rpcnetp.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label"
19:04:32,0729957,"csrss.exe","528","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:04:32,0734975,"csrss.exe","528","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe.Manifest","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, Impersonating: NT-AUTORITÄT\SYSTEM"
19:04:32,0737601,"csrss.exe","528","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\System32\rpcnetp.exe.Local","FAST IO DISALLOWED",""
19:04:32,0738199,"csrss.exe","528","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe.Local","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: NT-AUTORITÄT\SYSTEM"
19:04:32,0738883,"csrss.exe","528","IRP_MJ_QUERY_SECURITY","C:\Windows\System32\rpcnetp.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label"
19:04:32,0739106,"csrss.exe","528","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:04:32,0741590,"services.exe","704","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Disallow Exclusive, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:32,0744623,"services.exe","704","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\System32\rpcnetp.exe","FAST IO DISALLOWED",""
19:04:32,0745073,"services.exe","704","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:32,0745356,"services.exe","704","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:04:32,0745462,"services.exe","704","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0745596,"services.exe","704","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0746209,"services.exe","704","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Disallow Exclusive, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:32,0748003,"services.exe","704","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
19:04:32,0748148,"services.exe","704","FASTIO_ACQUIRE_FOR_CC_FLUSH","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0748247,"services.exe","704","FASTIO_RELEASE_FOR_CC_FLUSH","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0748343,"services.exe","704","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0748431,"services.exe","704","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","SyncType: SyncTypeOther"
19:04:32,0748502,"services.exe","704","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0748658,"services.exe","704","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0748785,"services.exe","704","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0749033,"services.exe","704","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryStandardInformationFile, AllocationSize: 20.480, EndOfFile: 17.408, NumberOfLinks: 1, DeletePending: False, Directory: False"
19:04:32,0749174,"services.exe","704","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0749288,"services.exe","704","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0750243,"System","4","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: None 0x0, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:32,0750629,"System","4","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0750802,"System","4","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:32,0751036,"rpcnetp.exe","2592","Load Image","C:\Windows\System32\rpcnetp.exe","SUCCESS","Image Base: 0x400000, Image Size: 0x8000"
19:04:32,0842991,"rpcnetp.exe","2592","RegQueryValue","HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Compatibility32\rpcnetp","NAME NOT FOUND","Length: 172"
19:04:32,0865188,"rpcnetp.exe","2592","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Non-Directory File, Open Reparse Point, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:32,0868727,"rpcnetp.exe","2592","IRP_MJ_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Type: QueryAttributeTagFile, Attributes: A, ReparseTag: 0x0"
19:04:32,0868894,"rpcnetp.exe","2592","IRP_MJ_CLEANUP","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS",""
19:04:32,0869018,"rpcnetp.exe","2592","IRP_MJ_CLOSE","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS",""
19:04:32,0869729,"rpcnetp.exe","2592","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Open Reparse Point, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:32,0872082,"rpcnetp.exe","2592","FASTIO_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Type: QueryStandardInformationFile, AllocationSize: 20.480, EndOfFile: 17.408, NumberOfLinks: 1, DeletePending: False, Directory: False"
19:04:32,0872192,"rpcnetp.exe","2592","FASTIO_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:04:32,0872320,"rpcnetp.exe","2592","IRP_MJ_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Type: QueryStreamInformationFile, 1: ::$DATA"
19:04:32,0872497,"rpcnetp.exe","2592","FASTIO_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:04:32,0872596,"rpcnetp.exe","2592","IRP_MJ_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Type: QueryEaInformationFile, EaSize: 0"
19:04:32,0873261,"rpcnetp.exe","2592","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Desired Access: Generic Write, Read Data/List Directory, Read Attributes, Delete, Disposition: OverwriteIf, Options: Sequential Access, Non-Directory File, Attributes: A, ShareMode: None, AllocationSize: 17.408, OpenResult: Created"
19:04:32,2075624,"rpcnetp.exe","2592","IRP_MJ_CLEANUP","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:04:32,2076077,"rpcnetp.exe","2592","IRP_MJ_CLOSE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:04:32,2076771,"rpcnetp.exe","2592","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Desired Access: Generic Write, Read Data/List Directory, Read Attributes, Delete, Disposition: OpenIf, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: A, ShareMode: None, AllocationSize: 17.408, OpenResult: Opened"
19:04:32,2077100,"rpcnetp.exe","2592","IRP_MJ_QUERY_VOLUME_INFORMATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Type: QueryAttributeInformationVolume, FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c00000, MaximumComponentNameLength: 255, FileSystemName: NTFS"
19:04:32,2077228,"rpcnetp.exe","2592","FASTIO_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:32, LastAccessTime: 28.06.2015 19:04:32, LastWriteTime: 28.06.2015 19:04:32, ChangeTime: 28.06.2015 19:04:32, FileAttributes: A"
19:04:32,2077316,"rpcnetp.exe","2592","IRP_MJ_QUERY_VOLUME_INFORMATION","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Type: QueryAttributeInformationVolume, FileSystemAttributes: Case Preserved, Case Sensitive, Unicode, ACLs, Compression, Named Streams, EFS, Object IDs, Reparse Points, Sparse Files, Quotas, Transactions, 0x3c00000, MaximumComponentNameLength: 255, FileSystemName: NTFS"
19:04:32,2077412,"rpcnetp.exe","2592","IRP_MJ_SET_INFORMATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Type: SetEndOfFileInformationFile, EndOfFile: 17.408"
19:04:32,2078774,"rpcnetp.exe","2592","IRP_MJ_READ","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Offset: 0, Length: 17.408, Priority: Normal"
19:04:32,2078997,"rpcnetp.exe","2592","IRP_MJ_READ","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Offset: 0, Length: 17.408, I/O Flags: Non-cached, Paging I/O, Priority: Normal"
19:04:32,2616454,"rpcnetp.exe","2592","IRP_MJ_WRITE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Offset: 0, Length: 17.408, Priority: Normal"
19:04:32,2617219,"rpcnetp.exe","2592","IRP_MJ_SET_INFORMATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Type: SetBasicInformationFile, CreationTime: 01.01.1601 02:00:00, LastAccessTime: 01.01.1601 02:00:00, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: n/a"
19:04:32,2617661,"rpcnetp.exe","2592","IRP_MJ_CLEANUP","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS",""
19:04:32,2617874,"rpcnetp.exe","2592","IRP_MJ_CLEANUP","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:04:32,2618974,"rpcnetp.exe","2592","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Desired Access: Generic Read/Write, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened"
19:04:32,2621760,"rpcnetp.exe","2592","IRP_MJ_WRITE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Offset: 94, Length: 2, Priority: Normal"
19:04:32,2622085,"rpcnetp.exe","2592","IRP_MJ_CLEANUP","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:04:32,2622337,"rpcnetp.exe","2592","IRP_MJ_CLOSE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:04:32,2623129,"rpcnetp.exe","2592","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\SysWOW64\rpcnetp.dll","FAST IO DISALLOWED",""
19:04:32,2623819,"rpcnetp.exe","2592","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:32,2624081,"rpcnetp.exe","2592","FASTIO_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:32, LastAccessTime: 28.06.2015 19:04:32, LastWriteTime: 28.06.2015 19:04:32, ChangeTime: 28.06.2015 19:04:32, FileAttributes: A"
19:04:32,2624170,"rpcnetp.exe","2592","IRP_MJ_CLEANUP","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:04:32,2624272,"rpcnetp.exe","2592","IRP_MJ_CLOSE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:04:32,2624810,"rpcnetp.exe","2592","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:32,2627121,"rpcnetp.exe","2592","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
19:04:32,2630215,"rpcnetp.exe","2592","FASTIO_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Type: QueryStandardInformationFile, AllocationSize: 20.480, EndOfFile: 17.408, NumberOfLinks: 1, DeletePending: False, Directory: False"
19:04:32,2630395,"rpcnetp.exe","2592","FASTIO_ACQUIRE_FOR_CC_FLUSH","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:04:32,2630523,"rpcnetp.exe","2592","IRP_MJ_WRITE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Offset: 0, Length: 20.480, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal"
19:04:32,2726529,"rpcnetp.exe","2592","FASTIO_RELEASE_FOR_CC_FLUSH","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:04:32,2726639,"rpcnetp.exe","2592","FASTIO_ACQUIRE_FOR_CC_FLUSH","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:04:32,2726717,"rpcnetp.exe","2592","FASTIO_RELEASE_FOR_CC_FLUSH","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:04:32,2726830,"rpcnetp.exe","2592","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:04:32,2726915,"rpcnetp.exe","2592","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","SyncType: SyncTypeOther"
19:04:32,2726975,"rpcnetp.exe","2592","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:04:32,2728002,"System","4","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Desired Access: None 0x0, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:32,2728310,"System","4","IRP_MJ_CLEANUP","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:04:32,2728405,"System","4","IRP_MJ_CLOSE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:04:32,2728922,"rpcnetp.exe","2592","Load Image","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Image Base: 0x360000, Image Size: 0x8000"
19:04:32,2729570,"rpcnetp.exe","2592","IRP_MJ_CLEANUP","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:04:32,2730762,"rpcnetp.exe","2592","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\rpcnetp.dll","NAME NOT FOUND","Length: 1.024"
19:04:32,2745634,"rpcnetp.exe","2592","RegOpenKey","HKLM\System\CurrentControlSet\Services\rpcnetp","REPARSE","Desired Access: Maximum Allowed"
19:04:32,2745800,"rpcnetp.exe","2592","RegOpenKey","HKLM\System\CurrentControlSet\Services\rpcnetp","SUCCESS","Desired Access: Maximum Allowed, Granted Access: All Access"
19:04:32,2746211,"rpcnetp.exe","2592","RegSetInfoKey","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS","KeySetInformationClass: KeySetHandleTagsInformation, Length: 0"
19:04:32,2746296,"rpcnetp.exe","2592","RegQueryValue","HKLM\System\CurrentControlSet\services\rpcnetp\(Default)","SUCCESS","Type: REG_BINARY, Length: 128, Data: 00 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00"
19:04:32,2746448,"rpcnetp.exe","2592","RegEnumValue","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS","Index: 0, Name: ErrorControl, Type: REG_DWORD, Length: 4, Data: 1"
19:04:32,2747959,"rpcnetp.exe","2592","RegDeleteValue","HKLM\System\CurrentControlSet\services\rpcnetp\ErrorControl","SUCCESS",""
19:04:32,2748182,"rpcnetp.exe","2592","RegEnumValue","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS","Index: 0, Name: Start, Type: REG_DWORD, Length: 4, Data: 2"
19:04:32,2748299,"rpcnetp.exe","2592","RegDeleteValue","HKLM\System\CurrentControlSet\services\rpcnetp\Start","SUCCESS",""
19:04:32,2748440,"rpcnetp.exe","2592","RegEnumValue","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS","Index: 0, Name: Type, Type: REG_DWORD, Length: 4, Data: 16"
19:04:32,2748529,"rpcnetp.exe","2592","RegDeleteValue","HKLM\System\CurrentControlSet\services\rpcnetp\Type","SUCCESS",""
19:04:32,2748656,"rpcnetp.exe","2592","RegEnumValue","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS","Index: 0, Name: ImagePath, Type: REG_EXPAND_SZ, Length: 68, Data: %SystemRoot%\System32\rpcnetp.exe"
19:04:32,2748745,"rpcnetp.exe","2592","RegDeleteValue","HKLM\System\CurrentControlSet\services\rpcnetp\ImagePath","SUCCESS",""
19:04:32,2748869,"rpcnetp.exe","2592","RegEnumValue","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS","Index: 0, Name: ObjectName, Type: REG_SZ, Length: 24, Data: LocalSystem"
19:04:32,2749077,"rpcnetp.exe","2592","RegDeleteValue","HKLM\System\CurrentControlSet\services\rpcnetp\ObjectName","SUCCESS",""
19:04:32,2749244,"rpcnetp.exe","2592","RegEnumValue","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS","Index: 0, Name: , Type: REG_BINARY, Length: 128, Data: 00 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00"
19:04:32,2749332,"rpcnetp.exe","2592","RegDeleteValue","HKLM\System\CurrentControlSet\services\rpcnetp\(Default)","SUCCESS",""
19:04:32,2749488,"rpcnetp.exe","2592","RegEnumValue","HKLM\System\CurrentControlSet\services\rpcnetp","NO MORE ENTRIES","Index: 0, Length: 220"
19:04:32,2749591,"rpcnetp.exe","2592","RegCloseKey","HKLM\System\CurrentControlSet\services\rpcnetp","SUCCESS",""
19:04:33,5660272,"svchost.exe","1056","IRP_MJ_CREATE","C:\Windows\Prefetch\RPCNET.EXE-A9AD5918.pf","SUCCESS","Desired Access: Read Attributes, Read Control, Write DAC, Write Owner, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:33,5993117,"svchost.exe","1056","IRP_MJ_QUERY_INFORMATION","C:\Windows\Prefetch\RPCNET.EXE-A9AD5918.pf","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 27.06.2015 14:49:56, LastAccessTime: 27.06.2015 14:49:56, LastWriteTime: 28.06.2015 11:15:15, ChangeTime: 28.06.2015 11:15:15, FileAttributes: ANCI"
19:04:33,5993247,"svchost.exe","1056","IRP_MJ_QUERY_SECURITY","C:\Windows\Prefetch\RPCNET.EXE-A9AD5918.pf","BUFFER OVERFLOW","Information: Owner, Group, DACL, DACL Protected"
19:04:33,5993382,"svchost.exe","1056","IRP_MJ_QUERY_SECURITY","C:\Windows\Prefetch\RPCNET.EXE-A9AD5918.pf","SUCCESS","Information: Owner, Group, DACL, DACL Protected"
19:04:33,5993672,"svchost.exe","1056","IRP_MJ_SET_SECURITY","C:\Windows\Prefetch\RPCNET.EXE-A9AD5918.pf","SUCCESS","Information: Owner, DACL, DACL Protected"
19:04:33,5995421,"svchost.exe","1056","IRP_MJ_CLEANUP","C:\Windows\Prefetch\RPCNET.EXE-A9AD5918.pf","SUCCESS",""
19:04:33,5995746,"svchost.exe","1056","IRP_MJ_CLOSE","C:\Windows\Prefetch\RPCNET.EXE-A9AD5918.pf","SUCCESS",""
19:04:34,0112398,"System","4","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","SyncType: SyncTypeOther"
19:04:34,0112518,"System","4","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS",""
19:04:34,0112606,"System","4","IRP_MJ_SET_INFORMATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Type: SetEndOfFileInformationFile, EndOfFile: 17.408"
19:04:34,0112812,"System","4","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","SyncType: SyncTypeOther"
19:04:34,0112872,"System","4","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:04:36,2070517,"GDFwSvcx64.exe","2788","IRP_MJ_DIRECTORY_CONTROL","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryDirectory, Filter: rpcnetp.exe, 2: rpcnetp.exe"
19:04:36,2071476,"GDFwSvcx64.exe","2788","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\System32\rpcnetp.exe","FAST IO DISALLOWED",""
19:04:36,2071922,"GDFwSvcx64.exe","2788","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:36,2072135,"GDFwSvcx64.exe","2788","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:04:36,2072223,"GDFwSvcx64.exe","2788","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:36,2072322,"GDFwSvcx64.exe","2788","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0291224,"svchost.exe","1116","IRP_MJ_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryNameInformationFile, Name: \Windows\System32\rpcnetp.exe"
19:04:38,0291419,"svchost.exe","1116","IRP_MJ_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryNameInformationFile, Name: \Windows\System32\rpcnetp.exe"
19:04:38,0291794,"svchost.exe","1116","IRP_MN_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","INVALID PARAMETER","Type: QueryNormalizedNameInformationFile"
19:04:38,0292615,"svchost.exe","1116","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\System32\rpcnetp.exe","FAST IO DISALLOWED",""
19:04:38,0293206,"svchost.exe","1116","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:38,0293514,"svchost.exe","1116","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:04:38,0293613,"svchost.exe","1116","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0293737,"svchost.exe","1116","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0296632,"svchost.exe","1116","IRP_MJ_DIRECTORY_CONTROL","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryDirectory, Filter: rpcnetp.exe, 2: rpcnetp.exe"
19:04:38,0297061,"svchost.exe","1116","IRP_MJ_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryNameInformationFile, Name: \Windows\System32\rpcnetp.exe"
19:04:38,0297160,"svchost.exe","1116","IRP_MJ_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryNameInformationFile, Name: \Windows\System32\rpcnetp.exe"
19:04:38,0297485,"svchost.exe","1116","IRP_MN_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","INVALID PARAMETER","Type: QueryNormalizedNameInformationFile"
19:04:38,0298115,"svchost.exe","1116","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\System32\rpcnetp.exe","FAST IO DISALLOWED",""
19:04:38,0298696,"svchost.exe","1116","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:38,0298968,"svchost.exe","1116","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:04:38,0299071,"svchost.exe","1116","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0299184,"svchost.exe","1116","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0302872,"svchost.exe","1116","IRP_MJ_DIRECTORY_CONTROL","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryDirectory, Filter: rpcnetp.exe, 2: rpcnetp.exe"
19:04:38,0303934,"svchost.exe","1116","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\System32\rpcnetp.exe","FAST IO DISALLOWED",""
19:04:38,0304387,"svchost.exe","1116","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:38,0307236,"svchost.exe","1116","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:04:38,0307370,"svchost.exe","1116","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0307515,"svchost.exe","1116","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0308464,"svchost.exe","1116","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:38,0310442,"svchost.exe","1116","IRP_MJ_QUERY_SECURITY","C:\Windows\System32\rpcnetp.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label"
19:04:38,0310761,"svchost.exe","1116","IRP_MJ_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryFileInternalInformationFile, IndexNumber: 0x3b0000000000271"
19:04:38,0339216,"svchost.exe","1116","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\System32\rpcnetp.exe","FAST IO DISALLOWED",""
19:04:38,0339654,"svchost.exe","1116","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:38,0339920,"svchost.exe","1116","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:04:38,0340008,"svchost.exe","1116","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0340114,"svchost.exe","1116","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0341435,"svchost.exe","1116","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryStandardInformationFile, AllocationSize: 20.480, EndOfFile: 17.408, NumberOfLinks: 1, DeletePending: False, Directory: False"
19:04:38,0341523,"svchost.exe","1116","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
19:04:38,0341587,"svchost.exe","1116","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryStandardInformationFile, AllocationSize: 20.480, EndOfFile: 17.408, NumberOfLinks: 1, DeletePending: False, Directory: False"
19:04:38,0341650,"svchost.exe","1116","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0341714,"svchost.exe","1116","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","SyncType: SyncTypeOther"
19:04:38,0341771,"svchost.exe","1116","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0342390,"svchost.exe","1116","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0342479,"svchost.exe","1116","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0356692,"svchost.exe","1116","IRP_MJ_DIRECTORY_CONTROL","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryDirectory, Filter: rpcnetp.exe, 2: rpcnetp.exe"
19:04:38,0357577,"svchost.exe","1116","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\System32\rpcnetp.exe","FAST IO DISALLOWED",""
19:04:38,0357970,"svchost.exe","1116","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:38,0358196,"svchost.exe","1116","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:04:38,0358281,"svchost.exe","1116","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0358380,"svchost.exe","1116","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0360613,"svchost.exe","1116","IRP_MJ_DIRECTORY_CONTROL","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryDirectory, Filter: rpcnetp.exe, 2: rpcnetp.exe"
19:04:38,0361657,"svchost.exe","1116","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\C:\Windows\System32\rpcnetp.exe","NAME NOT FOUND","Length: 1.024"
19:04:38,0362043,"svchost.exe","1116","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\rpcnetp.exe","NAME NOT FOUND","Desired Access: Read"
19:04:38,0383204,"svchost.exe","1116","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\System32\rpcnetp.exe","FAST IO DISALLOWED",""
19:04:38,0383625,"svchost.exe","1116","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:38,0383869,"svchost.exe","1116","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:04:38,0383961,"svchost.exe","1116","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0384074,"svchost.exe","1116","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0384651,"svchost.exe","1116","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
19:04:38,0386775,"svchost.exe","1116","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
19:04:38,0386899,"svchost.exe","1116","FASTIO_ACQUIRE_FOR_CC_FLUSH","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0386998,"svchost.exe","1116","FASTIO_RELEASE_FOR_CC_FLUSH","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0387072,"svchost.exe","1116","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0387153,"svchost.exe","1116","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","SyncType: SyncTypeOther"
19:04:38,0387217,"svchost.exe","1116","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0387380,"svchost.exe","1116","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0387504,"svchost.exe","1116","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0389599,"svchost.exe","1116","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
19:04:38,0391733,"svchost.exe","1116","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryStandardInformationFile, AllocationSize: 20.480, EndOfFile: 17.408, NumberOfLinks: 1, DeletePending: False, Directory: False"
19:04:38,0391861,"svchost.exe","1116","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
19:04:38,0391960,"svchost.exe","1116","FASTIO_ACQUIRE_FOR_CC_FLUSH","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0392045,"svchost.exe","1116","FASTIO_RELEASE_FOR_CC_FLUSH","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0392115,"svchost.exe","1116","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0392190,"svchost.exe","1116","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","SyncType: SyncTypeOther"
19:04:38,0392253,"svchost.exe","1116","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0392890,"svchost.exe","1116","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: n/a, OpenResult: Opened"
19:04:38,0395064,"svchost.exe","1116","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryStandardInformationFile, AllocationSize: 20.480, EndOfFile: 17.408, NumberOfLinks: 1, DeletePending: False, Directory: False"
19:04:38,0395180,"svchost.exe","1116","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryStandardInformationFile, AllocationSize: 20.480, EndOfFile: 17.408, NumberOfLinks: 1, DeletePending: False, Directory: False"
19:04:38,0395279,"svchost.exe","1116","IRP_MJ_READ","C:\Windows\System32\rpcnetp.exe","SUCCESS","Offset: 16.384, Length: 1.024, Priority: Normal"
19:04:38,0395460,"svchost.exe","1116","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0395580,"svchost.exe","1116","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0395764,"svchost.exe","1116","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0395853,"svchost.exe","1116","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:38,0411945,"svchost.exe","1116","IRP_MJ_QUERY_SECURITY","C:\Windows\System32\rpcnetp.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label"
19:04:38,0412059,"svchost.exe","1116","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:04:38,0412600,"svchost.exe","1116","IRP_MJ_QUERY_SECURITY","C:\Windows\System32\rpcnetp.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label"
19:04:38,0412689,"svchost.exe","1116","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:04:38,0412827,"svchost.exe","1116","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:41,8256376,"System","4","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","SyncType: SyncTypeOther"
19:04:41,8256429,"System","4","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:04:41,8867763,"lpksetup.exe","3112","IRP_MJ_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryNameInformationFile, Name: \Windows\System32\rpcnetp.exe"
19:04:51,4185783,"GDFwSvcx64.exe","2788","FASTIO_NETWORK_QUERY_OPEN","C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\rpcnetp.exe","FAST IO DISALLOWED",""
19:04:51,4186243,"GDFwSvcx64.exe","2788","IRP_MJ_CREATE","C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\rpcnetp.exe","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
19:04:54,4269445,"GDFwSvcx64.exe","2788","FASTIO_NETWORK_QUERY_OPEN","C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\rpcnetp.exe","FAST IO DISALLOWED",""
19:04:54,4269916,"GDFwSvcx64.exe","2788","IRP_MJ_CREATE","C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\rpcnetp.exe","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
19:05:23,4074501,"Explorer.EXE","2092","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:23,4078051,"Explorer.EXE","2092","IRP_MJ_QUERY_SECURITY","C:\Windows\System32\rpcnetp.exe","SUCCESS","Information: Owner, Group, DACL, SACL, Label"
19:05:23,4078189,"Explorer.EXE","2092","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:05:23,4078606,"Explorer.EXE","2092","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\rpcnetp.exe","NAME NOT FOUND","Desired Access: Query Value"
19:05:23,4153736,"Explorer.EXE","2092","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:23,4157792,"Explorer.EXE","2092","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
19:05:23,4157944,"Explorer.EXE","2092","FASTIO_ACQUIRE_FOR_CC_FLUSH","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4158170,"Explorer.EXE","2092","FASTIO_RELEASE_FOR_CC_FLUSH","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4158284,"Explorer.EXE","2092","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4158400,"Explorer.EXE","2092","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","SyncType: SyncTypeOther"
19:05:23,4158489,"Explorer.EXE","2092","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4161731,"Explorer.EXE","2092","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe.Manifest","NAME NOT FOUND","Desired Access: Generic Read/Execute, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a"
19:05:23,4162152,"Explorer.EXE","2092","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4164229,"Explorer.EXE","2092","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:23,4169935,"Explorer.EXE","2092","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\System32\rpcnetp.exe","FAST IO DISALLOWED",""
19:05:23,4170603,"Explorer.EXE","2092","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:23,4170954,"Explorer.EXE","2092","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:05:23,4171092,"Explorer.EXE","2092","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4171244,"Explorer.EXE","2092","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4172646,"Explorer.EXE","2092","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:23,4176355,"Explorer.EXE","2092","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","SyncType: SyncTypeOther"
19:05:23,4176549,"Explorer.EXE","2092","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4176691,"Explorer.EXE","2092","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4176857,"Explorer.EXE","2092","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
19:05:23,4177374,"Explorer.EXE","2092","FASTIO_ACQUIRE_FOR_CC_FLUSH","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4177512,"Explorer.EXE","2092","FASTIO_RELEASE_FOR_CC_FLUSH","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4177611,"Explorer.EXE","2092","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4177724,"Explorer.EXE","2092","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","SyncType: SyncTypeOther"
19:05:23,4177816,"Explorer.EXE","2092","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4178050,"Explorer.EXE","2092","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4178800,"Explorer.EXE","2092","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryStandardInformationFile, AllocationSize: 20.480, EndOfFile: 17.408, NumberOfLinks: 1, DeletePending: False, Directory: False"
19:05:23,4179005,"Explorer.EXE","2092","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4179745,"Explorer.EXE","2092","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4179929,"Explorer.EXE","2092","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4180276,"Explorer.EXE","2092","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4182053,"Explorer.EXE","2092","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\System32\rpcnetp.exe","FAST IO DISALLOWED",""
19:05:23,4183288,"Explorer.EXE","2092","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:23,4183691,"Explorer.EXE","2092","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:05:23,4183836,"Explorer.EXE","2092","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4183921,"Explorer.EXE","2092","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:23,4184003,"Explorer.EXE","2092","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4184293,"Explorer.EXE","2092","IRP_MJ_QUERY_SECURITY","C:\Windows\System32\rpcnetp.exe","BUFFER OVERFLOW","Information: Owner, DACL"
19:05:23,4184965,"Explorer.EXE","2092","IRP_MJ_QUERY_SECURITY","C:\Windows\System32\rpcnetp.exe","SUCCESS","Information: Owner, DACL"
19:05:23,4185086,"Explorer.EXE","2092","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4185210,"Explorer.EXE","2092","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4185379,"Explorer.EXE","2092","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\System32\rpcnetp.exe","FAST IO DISALLOWED",""
19:05:23,4187871,"Explorer.EXE","2092","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\System32\rpcnetp.exe","FAST IO DISALLOWED",""
19:05:23,4188182,"Explorer.EXE","2092","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:23,4189081,"Explorer.EXE","2092","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:23,4189361,"Explorer.EXE","2092","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:05:23,4189485,"Explorer.EXE","2092","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4189616,"Explorer.EXE","2092","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4189800,"Explorer.EXE","2092","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:05:23,4190026,"Explorer.EXE","2092","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4190193,"Explorer.EXE","2092","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4194907,"Explorer.EXE","2092","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\System32\rpcnetp.exe","FAST IO DISALLOWED",""
19:05:23,4195749,"Explorer.EXE","2092","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\System32\rpcnetp.exe","FAST IO DISALLOWED",""
19:05:23,4196765,"Explorer.EXE","2092","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:23,4197175,"Explorer.EXE","2092","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:05:23,4197331,"Explorer.EXE","2092","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4197349,"Explorer.EXE","2092","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:23,4197487,"Explorer.EXE","2092","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4197699,"Explorer.EXE","2092","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:05:23,4197813,"Explorer.EXE","2092","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4197940,"Explorer.EXE","2092","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4198938,"Explorer.EXE","2092","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:23,4202509,"Explorer.EXE","2092","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","SyncType: SyncTypeOther"
19:05:23,4202728,"Explorer.EXE","2092","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4202874,"Explorer.EXE","2092","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4203036,"Explorer.EXE","2092","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
19:05:23,4203153,"Explorer.EXE","2092","FASTIO_ACQUIRE_FOR_CC_FLUSH","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4203256,"Explorer.EXE","2092","FASTIO_RELEASE_FOR_CC_FLUSH","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4203341,"Explorer.EXE","2092","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4203443,"Explorer.EXE","2092","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","SyncType: SyncTypeOther"
19:05:23,4203528,"Explorer.EXE","2092","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4203776,"Explorer.EXE","2092","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4204218,"Explorer.EXE","2092","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:23,4204725,"Explorer.EXE","2092","IRP_MJ_QUERY_SECURITY","C:\Windows\System32\rpcnetp.exe","BUFFER OVERFLOW","Information: Owner, DACL"
19:05:23,4204887,"Explorer.EXE","2092","IRP_MJ_QUERY_SECURITY","C:\Windows\System32\rpcnetp.exe","SUCCESS","Information: Owner, DACL"
19:05:23,4205050,"Explorer.EXE","2092","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4205277,"Explorer.EXE","2092","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4510055,"Explorer.EXE","2092","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\System32\rpcnetp.exe","FAST IO DISALLOWED",""
19:05:23,4513025,"Explorer.EXE","2092","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:23,4513428,"Explorer.EXE","2092","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:05:23,4513555,"Explorer.EXE","2092","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4513708,"Explorer.EXE","2092","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4520843,"Explorer.EXE","2092","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\System32\rpcnetp.exe","FAST IO DISALLOWED",""
19:05:23,4521752,"Explorer.EXE","2092","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:23,4522272,"Explorer.EXE","2092","FASTIO_QUERY_INFORMATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:05:23,4522471,"Explorer.EXE","2092","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4522587,"Explorer.EXE","2092","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4529613,"Explorer.EXE","2092","IRP_MJ_CREATE","C:\Windows\System32\rpcnetp.exe","SUCCESS","Desired Access: Read Attributes, Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:23,4529945,"Explorer.EXE","2092","IRP_MJ_QUERY_SECURITY","C:\Windows\System32\rpcnetp.exe","BUFFER OVERFLOW","Information: Owner, DACL"
19:05:23,4530051,"Explorer.EXE","2092","IRP_MJ_QUERY_SECURITY","C:\Windows\System32\rpcnetp.exe","SUCCESS","Information: Owner, DACL"
19:05:23,4530147,"Explorer.EXE","2092","IRP_MJ_CLEANUP","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:23,4530257,"Explorer.EXE","2092","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:25,0099005,"System","4","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS","SyncType: SyncTypeOther"
19:05:25,0099126,"System","4","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:25,0099225,"System","4","IRP_MJ_CLOSE","C:\Windows\System32\rpcnetp.exe","SUCCESS",""
19:05:32,6377211,"rpcnetp.exe","2592","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Open Reparse Point, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:32,6379880,"rpcnetp.exe","2592","IRP_MJ_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Type: QueryAttributeTagFile, Attributes: A, ReparseTag: 0x0"
19:05:32,6380018,"rpcnetp.exe","2592","FASTIO_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Type: QueryStandardInformationFile, AllocationSize: 20.480, EndOfFile: 17.408, NumberOfLinks: 1, DeletePending: False, Directory: False"
19:05:32,6380092,"rpcnetp.exe","2592","FASTIO_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:05:32,6380184,"rpcnetp.exe","2592","IRP_MJ_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Type: QueryStreamInformationFile, 1: ::$DATA"
19:05:32,6380287,"rpcnetp.exe","2592","FASTIO_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:09, LastAccessTime: 28.06.2015 19:04:09, LastWriteTime: 28.06.2015 19:04:09, ChangeTime: 28.06.2015 19:04:09, FileAttributes: A"
19:05:32,6380365,"rpcnetp.exe","2592","IRP_MJ_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS","Type: QueryEaInformationFile, EaSize: 0"
19:05:32,6383755,"rpcnetp.exe","2592","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.dll","SHARING VIOLATION","Desired Access: Generic Write, Read Data/List Directory, Read Attributes, Delete, Disposition: OverwriteIf, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: A, ShareMode: None, AllocationSize: 17.408"
19:05:32,6384767,"rpcnetp.exe","2592","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.dll","SHARING VIOLATION","Desired Access: Generic Write, Read Attributes, Delete, Disposition: OverwriteIf, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: A, ShareMode: None, AllocationSize: 17.408"
19:05:32,6385645,"rpcnetp.exe","2592","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.dll","SHARING VIOLATION","Desired Access: Generic Write, Read Data/List Directory, Read Attributes, Delete, Disposition: OverwriteIf, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: A, ShareMode: Read, Write, AllocationSize: 17.408"
19:05:32,6386399,"rpcnetp.exe","2592","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.dll","SHARING VIOLATION","Desired Access: Generic Write, Read Attributes, Delete, Disposition: OverwriteIf, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: A, ShareMode: Read, Write, AllocationSize: 17.408"
19:05:32,6387202,"rpcnetp.exe","2592","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.dll","SHARING VIOLATION","Desired Access: Generic Write, Read Data/List Directory, Read Attributes, Disposition: OverwriteIf, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: A, ShareMode: Read, Write, AllocationSize: 17.408"
19:05:32,6388052,"rpcnetp.exe","2592","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.dll","SHARING VIOLATION","Desired Access: Generic Write, Read Attributes, Disposition: OverwriteIf, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: A, ShareMode: Read, Write, AllocationSize: 17.408"
19:05:32,6388505,"rpcnetp.exe","2592","IRP_MJ_CLEANUP","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS",""
19:05:32,6388622,"rpcnetp.exe","2592","IRP_MJ_CLOSE","C:\Windows\SysWOW64\rpcnetp.exe","SUCCESS",""
19:05:32,7405193,"svchost.exe","5024","IRP_MJ_CREATE","C:\Windows\SysWOW64\RPCNET.DLL","NAME NOT FOUND","Desired Access: Read Data/List Directory, Execute/Traverse, Read Attributes, Disposition: Open, Options: Non-Directory File, Complete If Oplocked, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a"
19:05:32,7428562,"svchost.exe","5024","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Read Attributes, Disposition: Open, Options: Non-Directory File, Complete If Oplocked, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:32,7428796,"svchost.exe","5024","IRP_MJ_SET_INFORMATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Type: SetBasicInformationFile, CreationTime: 01.01.1601 01:59:59, LastAccessTime: 01.01.1601 01:59:59, LastWriteTime: 01.01.1601 01:59:59, ChangeTime: 01.01.1601 01:59:59, FileAttributes: n/a"
19:05:32,7428884,"svchost.exe","5024","IRP_MJ_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Type: QueryAttributeTagFile, Attributes: A, ReparseTag: 0x0"
19:05:32,7429058,"svchost.exe","5024","IRP_MJ_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Type: QueryFileInternalInformationFile, IndexNumber: 0x3a0000000009e7"
19:05:32,7429132,"svchost.exe","5024","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
19:05:32,7429196,"svchost.exe","5024","FASTIO_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Type: QueryStandardInformationFile, AllocationSize: 20.480, EndOfFile: 17.408, NumberOfLinks: 1, DeletePending: False, Directory: False"
19:05:32,7429263,"svchost.exe","5024","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:32,7429326,"svchost.exe","5024","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","SyncType: SyncTypeOther"
19:05:32,7429383,"svchost.exe","5024","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:32,7739566,"svchost.exe","5024","IRP_MJ_CREATE","C:\Windows\SysWOW64\RPCNET.DLL","NAME NOT FOUND","Desired Access: Read Data/List Directory, Execute/Traverse, Read Attributes, Disposition: Open, Options: Non-Directory File, Complete If Oplocked, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a"
19:05:32,7751040,"svchost.exe","5024","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
19:05:32,7751521,"svchost.exe","5024","FASTIO_ACQUIRE_FOR_CC_FLUSH","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:32,7751691,"svchost.exe","5024","FASTIO_RELEASE_FOR_CC_FLUSH","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:32,7751748,"svchost.exe","5024","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:32,7751811,"svchost.exe","5024","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","SyncType: SyncTypeOther"
19:05:32,7751868,"svchost.exe","5024","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:32,8231138,"svchost.exe","5024","IRP_MJ_CLEANUP","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:32,8302912,"svchost.exe","5024","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\SysWOW64\rpcnetp.dll","FAST IO DISALLOWED",""
19:05:32,8303319,"svchost.exe","5024","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:32,8303546,"svchost.exe","5024","FASTIO_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:32, LastAccessTime: 28.06.2015 19:04:32, LastWriteTime: 28.06.2015 19:04:32, ChangeTime: 28.06.2015 19:04:32, FileAttributes: A"
19:05:32,8303620,"svchost.exe","5024","IRP_MJ_CLEANUP","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:32,8303723,"svchost.exe","5024","IRP_MJ_CLOSE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:32,8304204,"svchost.exe","5024","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:32,8306703,"svchost.exe","5024","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
19:05:32,8311293,"svchost.exe","5024","FASTIO_ACQUIRE_FOR_CC_FLUSH","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:32,8311406,"svchost.exe","5024","FASTIO_RELEASE_FOR_CC_FLUSH","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:32,8311473,"svchost.exe","5024","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:32,8311544,"svchost.exe","5024","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","SyncType: SyncTypeOther"
19:05:32,8311597,"svchost.exe","5024","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:32,8312631,"System","4","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Desired Access: None 0x0, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:32,8312886,"System","4","IRP_MJ_CLEANUP","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:32,8312963,"System","4","IRP_MJ_CLOSE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:32,8313462,"svchost.exe","5024","Load Image","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Image Base: 0x400000, Image Size: 0x8000"
19:05:32,8313756,"svchost.exe","5024","IRP_MJ_CLEANUP","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:32,8314581,"svchost.exe","5024","IRP_MJ_CLOSE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:33,0151343,"System","4","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","SyncType: SyncTypeOther"
19:05:33,0151470,"System","4","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:33,0151544,"System","4","IRP_MJ_CLOSE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:33,0582306,"iexplore.exe","5052","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Read Attributes, Disposition: Open, Options: Non-Directory File, Complete If Oplocked, Attributes: N, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:33,0582526,"iexplore.exe","5052","IRP_MJ_SET_INFORMATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Type: SetBasicInformationFile, CreationTime: 01.01.1601 01:59:59, LastAccessTime: 01.01.1601 01:59:59, LastWriteTime: 01.01.1601 01:59:59, ChangeTime: 01.01.1601 01:59:59, FileAttributes: n/a"
19:05:33,0582614,"iexplore.exe","5052","IRP_MJ_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Type: QueryAttributeTagFile, Attributes: A, ReparseTag: 0x0"
19:05:33,0582685,"iexplore.exe","5052","IRP_MJ_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Type: QueryFileInternalInformationFile, IndexNumber: 0x3a0000000009e7"
19:05:33,0582752,"iexplore.exe","5052","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
19:05:33,0582813,"iexplore.exe","5052","FASTIO_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Type: QueryStandardInformationFile, AllocationSize: 20.480, EndOfFile: 17.408, NumberOfLinks: 1, DeletePending: False, Directory: False"
19:05:33,0582876,"iexplore.exe","5052","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:33,0582936,"iexplore.exe","5052","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","SyncType: SyncTypeOther"
19:05:33,0582990,"iexplore.exe","5052","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:33,5715834,"iexplore.exe","5052","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
19:05:33,5717982,"iexplore.exe","5052","FASTIO_ACQUIRE_FOR_CC_FLUSH","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:33,5718060,"iexplore.exe","5052","FASTIO_RELEASE_FOR_CC_FLUSH","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:33,5718124,"iexplore.exe","5052","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:33,5718194,"iexplore.exe","5052","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","SyncType: SyncTypeOther"
19:05:33,5718255,"iexplore.exe","5052","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:34,1424620,"iexplore.exe","5052","IRP_MJ_CLEANUP","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:34,1625269,"iexplore.exe","5052","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\SysWOW64\rpcnetp.dll","FAST IO DISALLOWED",""
19:05:34,1625719,"iexplore.exe","5052","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:34,1626257,"iexplore.exe","5052","FASTIO_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:32, LastAccessTime: 28.06.2015 19:04:32, LastWriteTime: 28.06.2015 19:04:32, ChangeTime: 28.06.2015 19:04:32, FileAttributes: A"
19:05:34,1626349,"iexplore.exe","5052","IRP_MJ_CLEANUP","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:34,1626462,"iexplore.exe","5052","IRP_MJ_CLOSE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:34,1626993,"iexplore.exe","5052","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:34,1630773,"iexplore.exe","5052","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","FILE LOCKED WITH ONLY READERS","SyncType: SyncTypeCreateSection, PageProtection: "
19:05:34,1637925,"iexplore.exe","5052","FASTIO_ACQUIRE_FOR_CC_FLUSH","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:34,1638039,"iexplore.exe","5052","FASTIO_RELEASE_FOR_CC_FLUSH","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:34,1638117,"iexplore.exe","5052","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:34,1638202,"iexplore.exe","5052","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","SyncType: SyncTypeOther"
19:05:34,1638262,"iexplore.exe","5052","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:34,1639405,"System","4","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Desired Access: None 0x0, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:34,1639769,"System","4","IRP_MJ_CLEANUP","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:34,1639847,"System","4","IRP_MJ_CLOSE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:34,1640343,"iexplore.exe","5052","Load Image","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Image Base: 0xb0000, Image Size: 0x8000"
19:05:34,1640874,"iexplore.exe","5052","IRP_MJ_CLEANUP","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:34,1641688,"iexplore.exe","5052","IRP_MJ_CLOSE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:34,1669672,"iexplore.exe","5052","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\rpcnetp.dll","NAME NOT FOUND","Length: 1.024"
19:05:35,0094316,"System","4","FASTIO_ACQUIRE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","SyncType: SyncTypeOther"
19:05:35,0094397,"System","4","FASTIO_RELEASE_FOR_SECTION_SYNCHRONIZATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:35,0094451,"System","4","IRP_MJ_CLOSE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:39,7926989,"AVKWCtlx64.exe","476","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\SysWOW64\rpcnetp.dll","FAST IO DISALLOWED",""
19:05:39,7927375,"AVKWCtlx64.exe","476","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:39,7927549,"AVKWCtlx64.exe","476","FASTIO_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:32, LastAccessTime: 28.06.2015 19:04:32, LastWriteTime: 28.06.2015 19:04:32, ChangeTime: 28.06.2015 19:04:32, FileAttributes: A"
19:05:39,7927630,"AVKWCtlx64.exe","476","IRP_MJ_CLEANUP","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:39,7927729,"AVKWCtlx64.exe","476","IRP_MJ_CLOSE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:39,7984271,"AVKWCtlx64.exe","476","FASTIO_NETWORK_QUERY_OPEN","C:\Windows\SysWOW64\rpcnetp.dll","FAST IO DISALLOWED",""
19:05:39,7984703,"AVKWCtlx64.exe","476","IRP_MJ_CREATE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened"
19:05:39,7984869,"AVKWCtlx64.exe","476","FASTIO_QUERY_INFORMATION","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","Type: QueryBasicInformationFile, CreationTime: 28.06.2015 19:04:32, LastAccessTime: 28.06.2015 19:04:32, LastWriteTime: 28.06.2015 19:04:32, ChangeTime: 28.06.2015 19:04:32, FileAttributes: A"
19:05:39,7984947,"AVKWCtlx64.exe","476","IRP_MJ_CLEANUP","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS",""
19:05:39,7985053,"AVKWCtlx64.exe","476","IRP_MJ_CLOSE","C:\Windows\SysWOW64\rpcnetp.dll","SUCCESS","" |