@Tom I ran procmon as instructed and have a .csv file of when the secteer command was started. The file is about 6MB. How can I send this to you?
Here is some info from the file:
![0_1549303710471_9b918d37-215f-43a0-9ea3-b45c0b5c3844-image.png](Uploading 100%)
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 15320 CreateFile C:\Windows SUCCESS Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 15320 CreateFile C:\Windows\System32\wow64log.dll NAME NOT FOUND Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 15320 CreateFile C:\Windows SUCCESS Desired Access: Read Attributes, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 15320 QueryNameInformationFile C:\Windows SUCCESS Name: \Windows
46:27.7 secteer.exe 15320 CloseFile C:\Windows SUCCESS
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 15320 CreateFile C:\Program Files (x86)\SecTeer VulnDetect SUCCESS Desired Access: Execute/Traverse, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Attributes: n/a, ShareMode: Read, Write, AllocationSize: n/a, OpenResult: Opened
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 15320 CreateFile C:\Windows\SysWOW64\apphelp.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, OpenResult: Opened
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 15320 QueryBasicInformationFile C:\Windows\SysWOW64\apphelp.dll SUCCESS CreationTime: 2019-01-22 8:49:48 PM, LastAccessTime: 2019-01-22 8:49:48 PM, LastWriteTime: 2019-01-22 8:49:48 PM, ChangeTime: 2019-01-22 9:06:55 PM, FileAttributes: A
46:27.7 secteer.exe 15320 CloseFile C:\Windows\SysWOW64\apphelp.dll SUCCESS
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 15320 CreateFile C:\Windows\SysWOW64\apphelp.dll SUCCESS Desired Access: Read Data/List Directory, Execute/Traverse, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, OpenResult: Opened
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 15320 CreateFileMapping C:\Windows\SysWOW64\apphelp.dll FILE LOCKED WITH ONLY READERS SyncType: SyncTypeCreateSection, PageProtection: PAGE_EXECUTE|PAGE_NOCACHE
46:27.7 secteer.exe 15320 CreateFileMapping C:\Windows\SysWOW64\apphelp.dll SUCCESS SyncType: SyncTypeOther
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES
46:27.7 secteer.exe 15320 CloseFile C:\Windows\SysWOW64\apphelp.dll SUCCESS
46:27.7 secteer.exe 10620 QueryDirectory E:\ NO MORE FILES