Changeset 1397
- Timestamp:
- 03/27/08 23:04:05 (5 months ago)
- Files:
Legend:
- Unmodified
- Added
- Removed
- Modified
- Copied
- Moved
honeyclient/trunk/thirdparty/capture-mod/FileMonitor.exl
r1396 r1397 265 265 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Cookies 266 266 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Local Settings\\History\\History\.IE5\\MSHist012008032720080328\\index\.dat 267 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\cygwin\\lib\\perl5\\ site_perl\\5\.8\\cygwin\\HTML267 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\cygwin\\lib\\perl5\\.* 268 268 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Desktop 269 269 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Desktop\\%USERPROFILE%\\Local Settings\\Application Data\\Microsoft\\Feeds Cache … … 277 277 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Local Settings\\History\\History\.IE5 278 278 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Local Settings\\History\\History\.IE5\\index\.dat 279 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\cygwin\\lib\\perl5\\site_perl\\5\.8\\auto\\Data\\Validate\\URI280 279 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Local Settings\\Temporary Internet Files\\Content\.IE5 281 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\cygwin\\lib\\perl5\\site_perl\\5\.8\\DateTime\\TimeZone 280 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\WINDOWS\\system32\\Macromed\\Flash 281 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Microsoft\\Feeds Cache 282 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\Program Files 283 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Favorites 284 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\Program Files\\Messenger 285 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Local Settings\\Application Data\\Microsoft\\Feeds Cache\\index\.dat
