Changeset 1397

Show
Ignore:
Timestamp:
03/27/08 23:04:05 (5 months ago)
Author:
kindlund
Message:

More false positives for IE7.

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • honeyclient/trunk/thirdparty/capture-mod/FileMonitor.exl

    r1396 r1397  
    265265+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Cookies 
    266266+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Local Settings\\History\\History\.IE5\\MSHist012008032720080328\\index\.dat 
    267 +   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\cygwin\\lib\\perl5\\site_perl\\5\.8\\cygwin\\HTML 
     267+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\cygwin\\lib\\perl5\\.* 
    268268+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Desktop 
    269269+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Desktop\\%USERPROFILE%\\Local Settings\\Application Data\\Microsoft\\Feeds Cache 
     
    277277+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Local Settings\\History\\History\.IE5 
    278278+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Local Settings\\History\\History\.IE5\\index\.dat 
    279 +   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\cygwin\\lib\\perl5\\site_perl\\5\.8\\auto\\Data\\Validate\\URI 
    280279+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Local Settings\\Temporary Internet Files\\Content\.IE5 
    281 +   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\cygwin\\lib\\perl5\\site_perl\\5\.8\\DateTime\\TimeZone 
     280+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\WINDOWS\\system32\\Macromed\\Flash 
     281+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Microsoft\\Feeds Cache 
     282+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\Program Files 
     283+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Favorites 
     284+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\Program Files\\Messenger 
     285+   Write   C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Microsoft\\Feeds Cache\\index\.dat