Changeset 1681
- Timestamp:
- 07/10/08 16:07:37 (5 months ago)
- Files:
-
- honeyclient/branches/exp/kindlund-selenium/thirdparty/capture-mod/FileMonitor.exl (modified) (2 diffs)
- honeyclient/branches/exp/kindlund-selenium/thirdparty/capture-mod/ProcessMonitor.exl (modified) (1 diff)
- honeyclient/branches/exp/kindlund-selenium/thirdparty/capture-mod/RegistryMonitor.exl (modified) (2 diffs)
Legend:
- Unmodified
- Added
- Removed
- Modified
- Copied
- Moved
honeyclient/branches/exp/kindlund-selenium/thirdparty/capture-mod/FileMonitor.exl
r1672 r1681 97 97 + Write C:\\Program Files\\Messenger\\msmsgs\.exe C:\\Documents and Settings\\.+\\NTUSER.DAT.LOG 98 98 + Delete C:\\Program Files\\Messenger\\msmsgs\.exe C:\\Documents and Settings\\.+\\NTUSER.DAT.LOG 99 + Write C:\\Program Files\\Messenger\\msmsgs\.exe C:\\Documents and Settings\\.+\\NTUSER.DAT 99 100 + Write C:\\WINDOWS\\system32\\wbem\\wmiprvse\.exe E:\\\$LogFile 100 101 + Write C:\\WINDOWS\\system32\\wbem\\wmiprvse\.exe E:\\\$Directory … … 345 346 + Write C:\\Program Files\\Internet Explorer\\iexplore\.exe C:\\WINDOWS\\.+html 346 347 + Delete C:\\Program Files\\Internet Explorer\\iexplore\.exe C:\\WINDOWS\\.+tmp 348 + Write C:\\Program Files\\Internet Explorer\\iexplore\.exe C:\\WINDOWS\\.+tmp 347 349 348 350 # System Log Files - IE7 349 351 + Write C:\\WINDOWS\\system32\\services\.exe C:\\WINDOWS\\Debug\\UserMode\\userenv\.log 352 353 # IE6 Crashing 354 + Write C:\\WINDOWS\\system32\\drwtsn32\.exe C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Dr Watson\\.* 350 355 351 356 # IE6 - Selenium Support honeyclient/branches/exp/kindlund-selenium/thirdparty/capture-mod/ProcessMonitor.exl
r1672 r1681 55 55 + drwtsn32.exe .* C:\\WINDOWS\\system32\\drwtsn32\.exe 56 56 57 # IE - MSN Messenger Autostart 58 + msmsgs.exe .* C:\\Program Files\\Messenger\\msmsgs\.exe 59 57 60 # IE6 - Selenium Support 58 61 + cmd.exe .* C:\\WINDOWS\\system32\\cmd\.exe honeyclient/branches/exp/kindlund-selenium/thirdparty/capture-mod/RegistryMonitor.exl
r1676 r1681 290 290 + SetValueKey C:\\Program Files\\Windows Media Player\\wmplayer\.exe HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap 291 291 #### HONEYCLIENT AUTO EXCLUDE SCRIPT 292 + SetValueKey C:\\Program Files\\Internet Explorer\\iexplore\.exe HKCU\\Software\\Macromedia\\FlashPlayerUpdate 292 293 + DeleteValueKey C:\\Program Files\\Internet Explorer\\iexplore\.exe HKCU\\Software\\Macromedia\\FlashPlayer 293 294 + SetValueKey C:\\Program Files\\Internet Explorer\\iexplore\.exe HKLM\\SOFTWARE\\Macromedia\\FlashPlayer … … 408 409 + SetValueKey C:\\Program Files\\Internet Explorer\\iexplore\.exe HKLM\\SOFTWARE\\Microsoft\\PCHealth\\ErrorReporting\\.* 409 410 411 # IE - Dr Watson IE 6 Crashing 412 + DeleteValueKey C:\\Program Files\\Internet Explorer\\iexplore\.exe HKLM\\SOFTWARE\\Microsoft\\PCHealth\\ErrorReporting\\.* 413 + SetValueKey C:\\WINDOWS\\system32\\drwtsn32\.exe HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders.* 414 + SetValueKey C:\\WINDOWS\\system32\\drwtsn32\.exe HKLM\\SOFTWARE\\Microsoft\\DrWatson.* 415 416 # Benign Explorer Activity 417 + SetValueKey C:\\WINDOWS\\explorer\.exe HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar.* 418 + SetValueKey C:\\WINDOWS\\explorer\.exe HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings.* 419 410 420 # IE6 - Selenium Support 411 421 + SetValueKey C:\\Program Files\\Internet Explorer\\iexplore\.exe HKCR\\CLSID\\.*
