You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

2.5 KiB

1_timehostImageCommandLineEventCode
22017-06-26T04:36:54.000+0000we8105deskfsutil.exefsutil usn deletejournal /D1
32017-06-26T04:36:54.000+0000we8105deskcalc.exeC:\Windows\SysWOW64\DllHost.exe /Processid:{1EF75F33-893B-4E8F-9655-C3D602BA4897}1
42017-06-26T04:36:54.000+0000we1149srvcalc.exeC:\Windows\system32\wbem\wmiprvse.exe -Embedding1
52017-06-26T04:36:54.000+0000we1149srvcalc.exeC:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding1
62017-06-26T04:36:54.000+0000we8105deskcalc.exeC:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding1
72017-06-26T04:36:54.000+0000we8105deskcalc.exe"C:\Windows\system32\w32tm.exe" /stripchart /computer:we9041srv.waynecorpinc.local /dataonly /samples:11
82017-06-26T04:36:54.000+0000we8105deskcalc.exe"C:\Windows\system32\PING.EXE" we9041srv.waynecorpinc.local /n 21
92017-06-26T04:36:54.000+0000we8105deskcalc.exe"C:\Windows\system32\w32tm.exe" /query /source1
102017-06-26T04:36:54.000+0000we8105deskcalc.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\BOBSMI~1.WAY\AppData\Local\Temp\RES958E.tmp" "c:\Users\bob.smith.WAYNECORPINC\AppData\Local\Temp\CSC958D.tmp"1
112017-06-26T04:36:54.000+0000we8105deskcalc.exe"C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\bob.smith.WAYNECORPINC\AppData\Local\Temp\l62oeljq.cmdline"1
122017-06-26T04:36:54.000+0000we8105deskcalc.exeC:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding1
132017-06-26T04:36:54.000+0000we8105deskcalc.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\BOBSMI~1.WAY\AppData\Local\Temp\RES93AA.tmp" "c:\Users\bob.smith.WAYNECORPINC\AppData\Local\Temp\CSC93A9.tmp"1
142017-06-26T04:36:54.000+0000we8105deskcalc.exe"C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\bob.smith.WAYNECORPINC\AppData\Local\Temp\m7m1p90n.cmdline"1
152017-06-26T04:36:54.000+0000we8105deskcalc.exeC:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\BOBSMI~1.WAY\AppData\Local\Temp\RES936C.tmp" "c:\Users\bob.smith.WAYNECORPINC\AppData\Local\Temp\CSC936B.tmp"1
162017-06-26T04:36:54.000+0000we8105deskcalc.exe"C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\bob.smith.WAYNECORPINC\AppData\Local\Temp\skj1oiou.cmdline"1