Changeset 1366

Show
Ignore:
Timestamp:
03/24/08 20:54:57 (5 months ago)
Author:
kindlund
Message:

More false positives, related to wmiprvse.exe (31fd1a012f1caca021feb94c08)

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • honeyclient/trunk/thirdparty/capture-mod/FileMonitor.exl

    r1361 r1366  
    178178+   Write   C:\\WINDOWS\\system32\\wbem\\wmiprvse\.exe  C:\\WINDOWS\\system32\\config 
    179179+   Write   C:\\WINDOWS\\system32\\wbem\\wmiprvse\.exe  C:\\WINDOWS\\system32\\wbem 
     180+   Write   C:\\WINDOWS\\system32\\wbem\\wmiprvse\.exe  C:\\WINDOWS\\system32\\wbem\\Repository\\FS 
    180181+   Write   C:\\WINDOWS\\system32\\wbem\\wmiprvse\.exe  C:\\WINDOWS\\system32\\Prefetch 
    181182+   Write   C:\\WINDOWS\\system32\\wbem\\wmiprvse\.exe  C:\\WINDOWS\\PCHEALTH\\HELPCTR