Changeset 1612

Show
Ignore:
Timestamp:
06/10/08 10:42:43 (3 months ago)
Author:
xkovah
Message:

Added builtin XP unzip and WinZip whitelist entries

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • honeyclient/branches/exp/xkovah-app_whitelists/thirdparty/capture-mod/FileMonitor.exl

    r1606 r1612  
    399399+   Write   System  C:\\Documents and Settings\\Administrator\\Recent\\.* 
    400400+   Delete  System  C:\\Documents and Settings\\Administrator\\Recent\\.* 
     401 
     402#### HONEYCLIENT AUTO EXCLUDE SCRIPT 
     403#Seems to be valid for WinZip 8.0-11.1 
     404+   Delete  C:\\Program Files\\WinZip\\WINZIP32\.EXE    C:\\Documents and Settings\\Administrator\\Local Settings\\Temp\\.+ 
     405+   Write   C:\\Program Files\\WinZip\\WINZIP32\.EXE    C:\\Documents and Settings\\Administrator\\Local Settings\\Temp\\.+ 
     406+   Write   C:\\Program Files\\WinZip\\WINZIP32\.EXE    C:\\Documents and Settings\\All Users\\Application Data\\WinZip\\.+ 
     407+   Delete  C:\\Program Files\\WinZip\\WINZIP32\.EXE    C:\\Documents and Settings\\All Users\\Application Data\\WinZip\\.+ 
  • honeyclient/branches/exp/xkovah-app_whitelists/thirdparty/capture-mod/ProcessMonitor.exl

    r1606 r1612  
    6262+   AcroRd32.exe    .*  C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AcroRd32.exe 
    6363+   AcroRd32Info.exe    .*  C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AcroRd32Info.exe 
     64 
     65#### HONEYCLIENT AUTO EXCLUDE SCRIPT 
     66#Seems to be valid for WinZip 8.0-11.1 
     67+   WINZIP32.EXE    .*  C:\\Program Files\\WinZip\\WINZIP32.EXE 
  • honeyclient/branches/exp/xkovah-app_whitelists/thirdparty/capture-mod/RegistryMonitor.exl

    r1606 r1612  
    481481+   DeleteValueKey  C:\\Program Files\\Common Files\\Adobe\\Updater5\\AdobeUpdater\.exe HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run 
    482482+   DeleteValueKey  C:\\Program Files\\Common Files\\Adobe\\Updater5\\AdobeUpdater\.exe HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run 
     483 
     484#### HONEYCLIENT AUTO EXCLUDE SCRIPT 
     485#WinXP Builtin Unzip: This was the only action seen when double clicking a zip file with the default builtin WinXP unzip 
     486#(to be more specific, this was on a specific "Locked" key which was set to 1, and it's always reproducible) 
     487+   SetValueKey C:\\WINDOWS\\explorer\.exe  HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar 
     488 
     489 
     490#### HONEYCLIENT AUTO EXCLUDE SCRIPT 
     491#Seems to be valid for WinZip 8.0-11.1 
     492+   SetValueKey C:\\Program Files\\WinZip\\WINZIP32\.EXE    HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders 
     493+   SetValueKey C:\\Program Files\\WinZip\\WINZIP32\.EXE    HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders 
     494+   SetValueKey C:\\Program Files\\WinZip\\WINZIP32\.EXE    HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\.+ 
     495+   SetValueKey C:\\Program Files\\WinZip\\WINZIP32\.EXE    HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell 
     496+   SetValueKey C:\\Program Files\\WinZip\\WINZIP32\.EXE    HKCU\\Software\\Nico Mak Computing\\WinZip\\.+ 
     497+   DeleteValueKey  C:\\Program Files\\WinZip\\WINZIP32\.EXE    HKCU\\Software\\Nico Mak Computing\\WinZip\\.+ 
     498+   SetValueKey C:\\Program Files\\WinZip\\WINZIP32\.EXE    HKLM\\SOFTWARE\\Nico Mak Computing\\WinZip\\.+ 
     499+   DeleteValueKey  C:\\Program Files\\WinZip\\WINZIP32\.EXE    HKLM\\SOFTWARE\\Nico Mak Computing\\WinZip\\.+ 
     500+   SetValueKey C:\\Program Files\\WinZip\\WINZIP32\.EXE    HKCU\\Software\\Nico Mak Computing\\Common\\.+ 
     501+   DeleteValueKey  C:\\Program Files\\WinZip\\WINZIP32\.EXE    HKCU\\Software\\Nico Mak Computing\\Common\\.+ 
     502+   SetValueKey C:\\WINDOWS\\explorer\.exe  HKLM\\SOFTWARE\\Classes\\Applications\\winzip32\.exe\\.+