Changeset 1487
- Timestamp:
- 04/08/08 15:12:53 (5 months ago)
- Files:
Legend:
- Unmodified
- Added
- Removed
- Modified
- Copied
- Moved
honeyclient/branches/exp/kindlund-simpler_agent/thirdparty/capture-mod/FileMonitor.exl
r1469 r1487 51 51 + Write C:\\WINDOWS\\system32\\services\.exe C:\\WINDOWS\\system32\\config\\SecEvent\.Evt 52 52 #Mapping 53 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\WINDOWS\\system32\\wbem \\.+53 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\WINDOWS\\system32\\wbem.* 54 54 #Cataloging 55 55 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\WINDOWS\\system32\\CatRoot2\\.+ … … 273 273 + Write C:\\WINDOWS\\system32\\WgaTray\.exe C:\\Documents and Settings\\.+\\Local Settings\\History\\History.IE5.* 274 274 + Delete C:\\WINDOWS\\system32\\WgaTray\.exe C:\\Documents and Settings\\.+\\Local Settings\\History\\History.IE5.* 275 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\cygwin \\.*275 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\cygwin.* 276 276 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Desktop 277 277 + Write C:\\WINDOWS\\system32\\svchost\.exe C:\\Documents and Settings\\Administrator\\Desktop\\%USERPROFILE%\\Local Settings\\Application Data\\Microsoft\\Feeds Cache
