7
cons74
13.12.17
✎
13:29
|
Ответ админа:
Натравил на процесс 1cestrart.exe procmon
Результат во вложении.
порадовали строчки типа:
....
"14:17:42,3253015","1cestart.exe","33432","CreateFile","C:\Users\Администратор\Мои документы","SUCCESS","Desired Access: Synchronize, Disposition: Open, Options: Open By ID, Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: USER, OpenResult: Opened"
"14:17:42,3255658","1cestart.exe","33432","FileSystemControl","C:\Users\Администратор\Мои документы","SUCCESS","Control: FSCTL_GET_REPARSE_POINT"
"14:17:42,3256444","1cestart.exe","33432","CloseFile","C:\Users\Администратор\Мои документы","SUCCESS",""
"14:17:42,3264337","1cestart.exe","33432","CreateFile","C:\Users\Администратор\Documents\Моя музыка","SUCCESS","Desired Access: Synchronize, Disposition: Open, Options: Open By ID, Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: USER, OpenResult: Opened"
"14:17:42,3267011","1cestart.exe","33432","FileSystemControl","C:\Users\Администратор\Documents\Моя музыка","SUCCESS","Control: FSCTL_GET_REPARSE_POINT"
"14:17:42,3267812","1cestart.exe","33432","CloseFile","C:\Users\Администратор\Documents\Моя музыка","SUCCESS",""
"14:17:42,3275654","1cestart.exe","33432","CreateFile","C:\Users\Администратор\Documents\Мои рисунки","SUCCESS","Desired Access: Synchronize, Disposition: Open, Options: Open By ID, Open For Backup, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: USER, OpenResult: Opened"
...
и так по всем профилям пользователей
|
|