time process PID operation path result detail
20:55,3 System 4 CreateFile \Device\HarddiskVolume5 SUCCESS Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
20:55,3 System 4 QueryInformationVolume \Device\HarddiskVolume5 SUCCESS VolumeCreationTime: 20.01.2020 00:53:41, VolumeSerialNumber: F24B-86F1, SupportsObjects: True, VolumeLabel:
20:55,3 System 4 CreateFile \Device\HarddiskVolume2 SUCCESS Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
20:55,3 System 4 QueryInformationVolume \Device\HarddiskVolume2 SUCCESS VolumeCreationTime: 01.01.1601 02:00:00, VolumeSerialNumber: A6D6-F4FB, SupportsObjects: False, VolumeLabel:
20:55,3 System 4 CreateFile I: SUCCESS Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
20:55,3 System 4 QueryInformationVolume I: BUFFER OVERFLOW VolumeCreationTime: 23.06.2012 15:05:21, VolumeSerialNumber: 1245-090F, SupportsObjects: True, VolumeLabel: E a̱
20:55,3 System 4 CreateFile E: SUCCESS Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
20:55,3 System 4 QueryInformationVolume E: BUFFER OVERFLOW VolumeCreationTime: 07.01.2017 21:50:24, VolumeSerialNumber: 6727-E9B3, SupportsObjects: True, VolumeLabel: Meḏ
20:55,3 System 4 CreateFile F: SUCCESS Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
20:55,3 System 4 QueryInformationVolume F: BUFFER OVERFLOW VolumeCreationTime: 07.01.2017 21:50:25, VolumeSerialNumber: 5C22-7675, SupportsObjects: True, VolumeLabel: Viḏ
20:55,3 System 4 CreateFile \Device\HarddiskVolume1 SUCCESS Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
20:55,3 System 4 QueryInformationVolume \Device\HarddiskVolume1 BUFFER OVERFLOW VolumeCreationTime: 19.01.2020 22:48:37, VolumeSerialNumber: 4AD3-54EF, SupportsObjects: True, VolumeLabel: Wie̱
20:55,3 System 4 CreateFile J: SUCCESS Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
20:55,3 System 4 QueryInformationVolume J: BUFFER OVERFLOW VolumeCreationTime: 23.06.2012 17:16:44, VolumeSerialNumber: 7538-9A85, SupportsObjects: True, VolumeLabel: F a̱
20:55,3 System 4 CreateFile D: SUCCESS Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
20:55,3 System 4 QueryInformationVolume D: BUFFER OVERFLOW VolumeCreationTime: 07.01.2017 21:50:23, VolumeSerialNumber: 726C-3111, SupportsObjects: True, VolumeLabel: Spi̱
20:55,3 System 4 CreateFile H: SUCCESS Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
20:55,3 System 4 QueryInformationVolume H: BUFFER OVERFLOW VolumeCreationTime: 23.06.2012 10:33:42, VolumeSerialNumber: 92E6-0BB4, SupportsObjects: True, VolumeLabel: D a̱
20:55,3 System 4 CreateFile G: SUCCESS Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
20:55,3 System 4 QueryInformationVolume G: SUCCESS VolumeCreationTime: 21.06.2019 22:26:17, VolumeSerialNumber: 9C94-EDAA, SupportsObjects: True, VolumeLabel: SSD
20:55,3 System 4 CloseFile \Device\HarddiskVolume5 SUCCESS
20:55,3 System 4 IRP_MJ_CLOSE \Device\HarddiskVolume5 SUCCESS
20:55,3 System 4 CloseFile \Device\HarddiskVolume2 SUCCESS
20:55,3 System 4 IRP_MJ_CLOSE \Device\HarddiskVolume2 SUCCESS
20:55,3 System 4 CloseFile I: SUCCESS
20:55,3 System 4 IRP_MJ_CLOSE I: SUCCESS
20:55,3 System 4 CloseFile E: SUCCESS
20:55,3 System 4 IRP_MJ_CLOSE E: SUCCESS
20:55,3 System 4 CloseFile F: SUCCESS
20:55,3 System 4 IRP_MJ_CLOSE F: SUCCESS
20:55,3 System 4 CloseFile \Device\HarddiskVolume1 SUCCESS
20:55,3 System 4 IRP_MJ_CLOSE \Device\HarddiskVolume1 SUCCESS
20:55,3 System 4 CloseFile J: SUCCESS
20:55,3 System 4 IRP_MJ_CLOSE J: SUCCESS
20:55,3 System 4 CloseFile D: SUCCESS
20:55,3 System 4 IRP_MJ_CLOSE D: SUCCESS
20:55,3 System 4 CloseFile H: SUCCESS
20:55,3 System 4 IRP_MJ_CLOSE H: SUCCESS
20:55,3 System 4 CloseFile G: SUCCESS
20:55,3 System 4 IRP_MJ_CLOSE G: SUCCESS
21:55,5 System 4 CreateFile \Device\HarddiskVolume5 SUCCESS Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
21:55,5 System 4 QueryInformationVolume \Device\HarddiskVolume5 SUCCESS VolumeCreationTime: 20.01.2020 00:53:41, VolumeSerialNumber: F24B-86F1, SupportsObjects: True, VolumeLabel:
21:55,5 System 4 CreateFile \Device\HarddiskVolume2 SUCCESS Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
21:55,5 System 4 QueryInformationVolume \Device\HarddiskVolume2 SUCCESS VolumeCreationTime: 01.01.1601 02:00:00, VolumeSerialNumber: A6D6-F4FB, SupportsObjects: False, VolumeLabel:
21:55,5 System 4 CreateFile I: SUCCESS Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
21:55,5 System 4 QueryInformationVolume I: BUFFER OVERFLOW VolumeCreationTime: 23.06.2012 15:05:21, VolumeSerialNumber: 1245-090F, SupportsObjects: True, VolumeLabel: E a̱
21:55,5 System 4 CreateFile E: SUCCESS Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
21:55,5 System 4 QueryInformationVolume E: BUFFER OVERFLOW VolumeCreationTime: 07.01.2017 21:50:24, VolumeSerialNumber: 6727-E9B3, SupportsObjects: True, VolumeLabel: Meḏ
21:55,5 System 4 CreateFile F: SUCCESS Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
21:55,5 System 4 QueryInformationVolume F: BUFFER OVERFLOW VolumeCreationTime: 07.01.2017 21:50:25, VolumeSerialNumber: 5C22-7675, SupportsObjects: True, VolumeLabel: Viḏ
21:55,5 System 4 CreateFile \Device\HarddiskVolume1 SUCCESS Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
21:55,5 System 4 QueryInformationVolume \Device\HarddiskVolume1 BUFFER OVERFLOW VolumeCreationTime: 19.01.2020 22:48:37, VolumeSerialNumber: 4AD3-54EF, SupportsObjects: True, VolumeLabel: Wie̱
21:55,5 System 4 CreateFile J: SUCCESS Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
21:55,5 System 4 QueryInformationVolume J: BUFFER OVERFLOW VolumeCreationTime: 23.06.2012 17:16:44, VolumeSerialNumber: 7538-9A85, SupportsObjects: True, VolumeLabel: F a̱
21:55,5 System 4 CreateFile D: SUCCESS Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
21:55,5 System 4 QueryInformationVolume D: BUFFER OVERFLOW VolumeCreationTime: 07.01.2017 21:50:23, VolumeSerialNumber: 726C-3111, SupportsObjects: True, VolumeLabel: Spi̱
21:55,5 System 4 CreateFile H: SUCCESS Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
21:55,5 System 4 QueryInformationVolume H: BUFFER OVERFLOW VolumeCreationTime: 23.06.2012 10:33:42, VolumeSerialNumber: 92E6-0BB4, SupportsObjects: True, VolumeLabel: D a̱
21:55,5 System 4 CreateFile G: SUCCESS Desired Access: Read Attributes, Write Attributes, Synchronize, Disposition: Open, Options: Complete If Oplocked, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
21:55,5 System 4 QueryInformationVolume G: SUCCESS VolumeCreationTime: 21.06.2019 22:26:17, VolumeSerialNumber: 9C94-EDAA, SupportsObjects: True, VolumeLabel: SSD
21:55,5 System 4 CloseFile \Device\HarddiskVolume5 SUCCESS
21:55,5 System 4 IRP_MJ_CLOSE \Device\HarddiskVolume5 SUCCESS
21:55,5 System 4 CloseFile \Device\HarddiskVolume2 SUCCESS
21:55,5 System 4 IRP_MJ_CLOSE \Device\HarddiskVolume2 SUCCESS
21:55,5 System 4 CloseFile I: SUCCESS
21:55,5 System 4 IRP_MJ_CLOSE I: SUCCESS
21:55,5 System 4 CloseFile E: SUCCESS
21:55,5 System 4 IRP_MJ_CLOSE E: SUCCESS
21:55,5 System 4 CloseFile F: SUCCESS
21:55,5 System 4 IRP_MJ_CLOSE F: SUCCESS
21:55,5 System 4 CloseFile \Device\HarddiskVolume1 SUCCESS
21:55,5 System 4 IRP_MJ_CLOSE \Device\HarddiskVolume1 SUCCESS
21:55,5 System 4 CloseFile J: SUCCESS
21:55,5 System 4 IRP_MJ_CLOSE J: SUCCESS
21:55,5 System 4 CloseFile D: SUCCESS
21:55,5 System 4 IRP_MJ_CLOSE D: SUCCESS
21:55,5 System 4 CloseFile H: SUCCESS
21:55,5 System 4 IRP_MJ_CLOSE H: SUCCESS
21:55,5 System 4 CloseFile G: SUCCESS
21:55,5 System 4 IRP_MJ_CLOSE G: SUCCESS
21:55,7 svchost.exe 8268 CreateFile \Device\Harddisk0\DR0 SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: S, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: SMART_GET_VERSION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: SMART_GET_VERSION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_DISK_GET_CACHE_INFORMATION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_DISK_GET_CACHE_INFORMATION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 DEVICE FEATURE NOT SUPPORTED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 CloseFile \Device\Harddisk0\DR0 SUCCESS
21:55,7 svchost.exe 8268 IRP_MJ_CLOSE \Device\Harddisk0\DR0 SUCCESS
21:55,7 svchost.exe 8268 CreateFile \Device\Harddisk0\DR0 SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: S, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: SMART_GET_VERSION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: SMART_GET_VERSION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_DISK_GET_CACHE_INFORMATION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_DISK_GET_CACHE_INFORMATION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 DEVICE FEATURE NOT SUPPORTED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 CloseFile \Device\Harddisk0\DR0 SUCCESS
21:55,7 svchost.exe 8268 IRP_MJ_CLOSE \Device\Harddisk0\DR0 SUCCESS
21:55,7 svchost.exe 8268 CreateFile \Device\Harddisk0\DR0 SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: S, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: SMART_GET_VERSION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: SMART_GET_VERSION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_DISK_GET_CACHE_INFORMATION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_DISK_GET_CACHE_INFORMATION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 DEVICE FEATURE NOT SUPPORTED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 CloseFile \Device\Harddisk0\DR0 SUCCESS
21:55,7 svchost.exe 8268 IRP_MJ_CLOSE \Device\Harddisk0\DR0 SUCCESS
21:55,7 svchost.exe 8268 CreateFile \Device\Harddisk0\DR0 SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: S, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: SMART_GET_VERSION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: SMART_GET_VERSION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_DISK_GET_CACHE_INFORMATION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_DISK_GET_CACHE_INFORMATION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 DEVICE FEATURE NOT SUPPORTED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 CloseFile \Device\Harddisk0\DR0 SUCCESS
21:55,7 svchost.exe 8268 IRP_MJ_CLOSE \Device\Harddisk0\DR0 SUCCESS
21:55,7 svchost.exe 8268 CreateFile \Device\Harddisk0\DR0 SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: S, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: SMART_GET_VERSION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: SMART_GET_VERSION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_DISK_GET_CACHE_INFORMATION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_DISK_GET_CACHE_INFORMATION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 DEVICE FEATURE NOT SUPPORTED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 CloseFile \Device\Harddisk0\DR0 SUCCESS
21:55,7 svchost.exe 8268 IRP_MJ_CLOSE \Device\Harddisk0\DR0 SUCCESS
21:55,7 svchost.exe 8268 CreateFile \Device\Harddisk0\DR0 SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: S, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: SMART_GET_VERSION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: SMART_GET_VERSION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_DISK_GET_CACHE_INFORMATION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_DISK_GET_CACHE_INFORMATION
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 DeviceIoControl \Device\Harddisk0\DR0 DEVICE FEATURE NOT SUPPORTED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:55,7 svchost.exe 8268 CloseFile \Device\Harddisk0\DR0 SUCCESS
21:55,7 svchost.exe 8268 IRP_MJ_CLOSE \Device\Harddisk0\DR0 SUCCESS
21:56,0 wmiprvse.exe 4604 CreateFile \Device\Harddisk1\DR1 SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, Impersonating: NT-AUTORITÄT\SYSTEM, OpenResult: Opened
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk1\DR1 FAST IO DISALLOWED Control: IOCTL_STORAGE_GET_DEVICE_NUMBER
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk1\DR1 SUCCESS Control: IOCTL_STORAGE_GET_DEVICE_NUMBER
21:56,0 wmiprvse.exe 4604 CreateFile \Device\Harddisk1\DR1 SUCCESS Desired Access: Generic Read/Write, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, Impersonating: NT-AUTORITÄT\SYSTEM, OpenResult: Opened
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk1\DR1 FAST IO DISALLOWED Control: SMART_GET_VERSION
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk1\DR1 SUCCESS Control: SMART_GET_VERSION
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk1\DR1 FAST IO DISALLOWED Control: SMART_SEND_DRIVE_COMMAND
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk1\DR1 SUCCESS Control: SMART_SEND_DRIVE_COMMAND
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk1\DR1 FAST IO DISALLOWED Control: SMART_RCV_DRIVE_DATA
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk1\DR1 SUCCESS Control: SMART_RCV_DRIVE_DATA
21:56,0 wmiprvse.exe 4604 CloseFile \Device\Harddisk1\DR1 SUCCESS
21:56,0 wmiprvse.exe 4604 IRP_MJ_CLOSE \Device\Harddisk1\DR1 SUCCESS
21:56,0 wmiprvse.exe 4604 CloseFile \Device\Harddisk1\DR1 SUCCESS
21:56,0 wmiprvse.exe 4604 IRP_MJ_CLOSE \Device\Harddisk1\DR1 SUCCESS
21:56,0 wmiprvse.exe 4604 CreateFile \Device\Harddisk3\DR3 SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, Impersonating: NT-AUTORITÄT\SYSTEM, OpenResult: Opened
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk3\DR3 FAST IO DISALLOWED Control: IOCTL_STORAGE_GET_DEVICE_NUMBER
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk3\DR3 SUCCESS Control: IOCTL_STORAGE_GET_DEVICE_NUMBER
21:56,0 wmiprvse.exe 4604 CreateFile \Device\Harddisk3\DR3 SUCCESS Desired Access: Generic Read/Write, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, Impersonating: NT-AUTORITÄT\SYSTEM, OpenResult: Opened
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk3\DR3 FAST IO DISALLOWED Control: SMART_GET_VERSION
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk3\DR3 0x80000011 Control: SMART_GET_VERSION
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk3\DR3 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk3\DR3 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:56,0 wmiprvse.exe 4604 CloseFile \Device\Harddisk3\DR3 SUCCESS
21:56,0 wmiprvse.exe 4604 IRP_MJ_CLOSE \Device\Harddisk3\DR3 SUCCESS
21:56,0 wmiprvse.exe 4604 CloseFile \Device\Harddisk3\DR3 SUCCESS
21:56,0 wmiprvse.exe 4604 IRP_MJ_CLOSE \Device\Harddisk3\DR3 SUCCESS
21:56,0 wmiprvse.exe 4604 CreateFile \Device\Harddisk2\DR2 SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, Impersonating: NT-AUTORITÄT\SYSTEM, OpenResult: Opened
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk2\DR2 FAST IO DISALLOWED Control: IOCTL_STORAGE_GET_DEVICE_NUMBER
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk2\DR2 SUCCESS Control: IOCTL_STORAGE_GET_DEVICE_NUMBER
21:56,0 wmiprvse.exe 4604 CreateFile \Device\Harddisk2\DR2 SUCCESS Desired Access: Generic Read/Write, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, Impersonating: NT-AUTORITÄT\SYSTEM, OpenResult: Opened
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk2\DR2 FAST IO DISALLOWED Control: SMART_GET_VERSION
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk2\DR2 0x80000011 Control: SMART_GET_VERSION
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk2\DR2 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk2\DR2 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:56,0 wmiprvse.exe 4604 CloseFile \Device\Harddisk2\DR2 SUCCESS
21:56,0 wmiprvse.exe 4604 IRP_MJ_CLOSE \Device\Harddisk2\DR2 SUCCESS
21:56,0 wmiprvse.exe 4604 CloseFile \Device\Harddisk2\DR2 SUCCESS
21:56,0 wmiprvse.exe 4604 IRP_MJ_CLOSE \Device\Harddisk2\DR2 SUCCESS
21:56,0 wmiprvse.exe 4604 CreateFile \Device\Harddisk4\DR4 SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, Impersonating: NT-AUTORITÄT\SYSTEM, OpenResult: Opened
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk4\DR4 FAST IO DISALLOWED Control: IOCTL_STORAGE_GET_DEVICE_NUMBER
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk4\DR4 SUCCESS Control: IOCTL_STORAGE_GET_DEVICE_NUMBER
21:56,0 wmiprvse.exe 4604 CreateFile \Device\Harddisk4\DR4 SUCCESS Desired Access: Generic Read/Write, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, Impersonating: NT-AUTORITÄT\SYSTEM, OpenResult: Opened
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk4\DR4 FAST IO DISALLOWED Control: SMART_GET_VERSION
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk4\DR4 0x80000011 Control: SMART_GET_VERSION
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk4\DR4 FAST IO DISALLOWED Control: IOCTL_STORAGE_QUERY_PROPERTY
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk4\DR4 SUCCESS Control: IOCTL_STORAGE_QUERY_PROPERTY
21:56,0 wmiprvse.exe 4604 CloseFile \Device\Harddisk4\DR4 SUCCESS
21:56,0 wmiprvse.exe 4604 IRP_MJ_CLOSE \Device\Harddisk4\DR4 SUCCESS
21:56,0 wmiprvse.exe 4604 CloseFile \Device\Harddisk4\DR4 SUCCESS
21:56,0 wmiprvse.exe 4604 IRP_MJ_CLOSE \Device\Harddisk4\DR4 SUCCESS
21:56,0 wmiprvse.exe 4604 CreateFile \Device\Harddisk0\DR0 SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, Impersonating: NT-AUTORITÄT\SYSTEM, OpenResult: Opened
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: IOCTL_STORAGE_GET_DEVICE_NUMBER
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: IOCTL_STORAGE_GET_DEVICE_NUMBER
21:56,0 wmiprvse.exe 4604 CreateFile \Device\Harddisk0\DR0 SUCCESS Desired Access: Generic Read/Write, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Write, AllocationSize: n/a, Impersonating: NT-AUTORITÄT\SYSTEM, OpenResult: Opened
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: SMART_GET_VERSION
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: SMART_GET_VERSION
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: SMART_SEND_DRIVE_COMMAND
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: SMART_SEND_DRIVE_COMMAND
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk0\DR0 FAST IO DISALLOWED Control: SMART_RCV_DRIVE_DATA
21:56,0 wmiprvse.exe 4604 DeviceIoControl \Device\Harddisk0\DR0 SUCCESS Control: SMART_RCV_DRIVE_DATA
21:56,0 wmiprvse.exe 4604 CloseFile \Device\Harddisk0\DR0 SUCCESS
21:56,0 wmiprvse.exe 4604 IRP_MJ_CLOSE \Device\Harddisk0\DR0 SUCCESS
21:56,0 wmiprvse.exe 4604 CloseFile \Device\Harddisk0\DR0 SUCCESS
21:56,0 wmiprvse.exe 4604 IRP_MJ_CLOSE \Device\Harddisk0\DR0 SUCCESS