Changeset 1612
- Timestamp:
- 06/10/08 10:42:43 (3 months ago)
- Files:
-
- honeyclient/branches/exp/xkovah-app_whitelists/thirdparty/capture-mod/FileMonitor.exl (modified) (1 diff)
- honeyclient/branches/exp/xkovah-app_whitelists/thirdparty/capture-mod/ProcessMonitor.exl (modified) (1 diff)
- honeyclient/branches/exp/xkovah-app_whitelists/thirdparty/capture-mod/RegistryMonitor.exl (modified) (1 diff)
Legend:
- Unmodified
- Added
- Removed
- Modified
- Copied
- Moved
honeyclient/branches/exp/xkovah-app_whitelists/thirdparty/capture-mod/FileMonitor.exl
r1606 r1612 399 399 + Write System C:\\Documents and Settings\\Administrator\\Recent\\.* 400 400 + Delete System C:\\Documents and Settings\\Administrator\\Recent\\.* 401 402 #### HONEYCLIENT AUTO EXCLUDE SCRIPT 403 #Seems to be valid for WinZip 8.0-11.1 404 + Delete C:\\Program Files\\WinZip\\WINZIP32\.EXE C:\\Documents and Settings\\Administrator\\Local Settings\\Temp\\.+ 405 + Write C:\\Program Files\\WinZip\\WINZIP32\.EXE C:\\Documents and Settings\\Administrator\\Local Settings\\Temp\\.+ 406 + Write C:\\Program Files\\WinZip\\WINZIP32\.EXE C:\\Documents and Settings\\All Users\\Application Data\\WinZip\\.+ 407 + Delete C:\\Program Files\\WinZip\\WINZIP32\.EXE C:\\Documents and Settings\\All Users\\Application Data\\WinZip\\.+ honeyclient/branches/exp/xkovah-app_whitelists/thirdparty/capture-mod/ProcessMonitor.exl
r1606 r1612 62 62 + AcroRd32.exe .* C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AcroRd32.exe 63 63 + AcroRd32Info.exe .* C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AcroRd32Info.exe 64 65 #### HONEYCLIENT AUTO EXCLUDE SCRIPT 66 #Seems to be valid for WinZip 8.0-11.1 67 + WINZIP32.EXE .* C:\\Program Files\\WinZip\\WINZIP32.EXE honeyclient/branches/exp/xkovah-app_whitelists/thirdparty/capture-mod/RegistryMonitor.exl
r1606 r1612 481 481 + DeleteValueKey C:\\Program Files\\Common Files\\Adobe\\Updater5\\AdobeUpdater\.exe HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run 482 482 + DeleteValueKey C:\\Program Files\\Common Files\\Adobe\\Updater5\\AdobeUpdater\.exe HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run 483 484 #### HONEYCLIENT AUTO EXCLUDE SCRIPT 485 #WinXP Builtin Unzip: This was the only action seen when double clicking a zip file with the default builtin WinXP unzip 486 #(to be more specific, this was on a specific "Locked" key which was set to 1, and it's always reproducible) 487 + SetValueKey C:\\WINDOWS\\explorer\.exe HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar 488 489 490 #### HONEYCLIENT AUTO EXCLUDE SCRIPT 491 #Seems to be valid for WinZip 8.0-11.1 492 + SetValueKey C:\\Program Files\\WinZip\\WINZIP32\.EXE HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders 493 + SetValueKey C:\\Program Files\\WinZip\\WINZIP32\.EXE HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders 494 + SetValueKey C:\\Program Files\\WinZip\\WINZIP32\.EXE HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\.+ 495 + SetValueKey C:\\Program Files\\WinZip\\WINZIP32\.EXE HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell 496 + SetValueKey C:\\Program Files\\WinZip\\WINZIP32\.EXE HKCU\\Software\\Nico Mak Computing\\WinZip\\.+ 497 + DeleteValueKey C:\\Program Files\\WinZip\\WINZIP32\.EXE HKCU\\Software\\Nico Mak Computing\\WinZip\\.+ 498 + SetValueKey C:\\Program Files\\WinZip\\WINZIP32\.EXE HKLM\\SOFTWARE\\Nico Mak Computing\\WinZip\\.+ 499 + DeleteValueKey C:\\Program Files\\WinZip\\WINZIP32\.EXE HKLM\\SOFTWARE\\Nico Mak Computing\\WinZip\\.+ 500 + SetValueKey C:\\Program Files\\WinZip\\WINZIP32\.EXE HKCU\\Software\\Nico Mak Computing\\Common\\.+ 501 + DeleteValueKey C:\\Program Files\\WinZip\\WINZIP32\.EXE HKCU\\Software\\Nico Mak Computing\\Common\\.+ 502 + SetValueKey C:\\WINDOWS\\explorer\.exe HKLM\\SOFTWARE\\Classes\\Applications\\winzip32\.exe\\.+
