- Thread Author
- #1
Hello
In Windows 10 Enterprise 22 H2, a strange path in TargetFilename sometimes appears in Sysmon logs:
TargetFilename: C:\Users\P310C~1.ZNO\AppData\Local\Temp\7b542cd6-d613-4e52-bfdf-b80fe911ff30.tmp
And in the next event, the path is normal:
TargetFilename: C:\Users\p.znosko\AppData\Local\Temp\7b542cd6-d613-4e52-bfdf-b80fe911ff30.tmp
When I go to this directory, I will be taken to my user's folder C:\Users\p .znosko\
fsutil hardlink list C:\Users\P310C~1.ZNO\
NTFSLinksView.exe in C:\Users\ does not see links
I would like to understand what kind of a strange path this is C:\Users\P310C ~1.ZNO\
In Windows 10 Enterprise 22 H2, a strange path in TargetFilename sometimes appears in Sysmon logs:
TargetFilename: C:\Users\P310C~1.ZNO\AppData\Local\Temp\7b542cd6-d613-4e52-bfdf-b80fe911ff30.tmp
And in the next event, the path is normal:
TargetFilename: C:\Users\p.znosko\AppData\Local\Temp\7b542cd6-d613-4e52-bfdf-b80fe911ff30.tmp
When I go to this directory, I will be taken to my user's folder C:\Users\p .znosko\
fsutil hardlink list C:\Users\P310C~1.ZNO\
NTFSLinksView.exe in C:\Users\ does not see links
I would like to understand what kind of a strange path this is C:\Users\P310C ~1.ZNO\