1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33
| "12/4/2010 11:30:36.81","process","created","C:\WINDOWS\system32\cmd.exe","C:\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe"
"12/4/2010 11:30:37.222","file","Write","C:\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe","C:\WINDOWS\system32\spoolsvc.exe"
"12/4/2010 11:30:37.222","file","Write","C:\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe","C:\WINDOWS\system32\spoolsvc.exe"
"12/4/2010 11:30:37.222","file","Write","C:\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe","C:\WINDOWS\system32\spoolsvc.exe"
"12/4/2010 11:30:37.222","file","Write","C:\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe","C:\temp\zcbgjy.bat"
"12/4/2010 11:30:37.300","registry","SetValueKey","C:\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass"
"12/4/2010 11:30:37.300","registry","SetValueKey","C:\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName"
"12/4/2010 11:30:37.300","registry","SetValueKey","C:\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet"
"12/4/2010 11:30:37.300","registry","SetValueKey","C:\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass"
"12/4/2010 11:30:37.300","registry","SetValueKey","C:\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName"
"12/4/2010 11:30:37.300","registry","SetValueKey","C:\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet"
"12/4/2010 11:30:37.300","registry","SetValueKey","C:\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache"
"12/4/2010 11:30:37.300","registry","SetValueKey","C:\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cookies"
"12/4/2010 11:30:37.347","process","created","C:\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe","C:\WINDOWS\system32\cmd.exe"
"12/4/2010 11:30:37.378","process","created","C:\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe","C:\WINDOWS\system32\spoolsvc.exe"
"12/4/2010 11:30:37.331","registry","SetValueKey","C:\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3f04edc3-85c6-11de-af20-806d6172696f}\BaseClass"
"12/4/2010 11:30:37.347","registry","SetValueKey","C:\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cb7e6034-4640-11df-b8d9-806d6172696f}\BaseClass"
"12/4/2010 11:30:37.347","registry","SetValueKey","C:\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe","HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3f04edc0-85c6-11de-af20-806d6172696f}\BaseClass"
"12/4/2010 11:30:37.347","file","Write","System","C:\WINDOWS\system32\spoolsvc.exe"
"12/4/2010 11:30:37.362","file","Write","System","C:\WINDOWS\system32\spoolsvc.exe"
"12/4/2010 11:30:37.362","file","Write","System","C:\WINDOWS\system32\spoolsvc.exe"
"12/4/2010 11:30:37.597","process","terminated","C:\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe","C:\WINDOWS\system32\cmd.exe"
"12/4/2010 11:30:37.581","file","Write","C:\WINDOWS\system32\cmd.exe","C:\Program Files\Capture\logs\deleted_files\C\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe"
"12/4/2010 11:30:37.581","file","Write","C:\WINDOWS\system32\cmd.exe","C:\Program Files\Capture\logs\deleted_files\C\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe"
"12/4/2010 11:30:37.581","file","Write","C:\WINDOWS\system32\cmd.exe","C:\Program Files\Capture\logs\deleted_files\C\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe"
"12/4/2010 11:30:37.581","file","Delete","C:\WINDOWS\system32\cmd.exe","C:\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe"
"12/4/2010 11:30:37.581","file","Write","C:\WINDOWS\system32\cmd.exe","C:\Program Files\Capture\logs\deleted_files\C\temp\zcbgjy.bat"
"12/4/2010 11:30:37.597","file","Delete","C:\WINDOWS\system32\cmd.exe","C:\temp\zcbgjy.bat"
"12/4/2010 11:30:38.362","file","Write","System","C:\Program Files\Capture\logs\deleted_files\C\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe"
"12/4/2010 11:30:38.472","file","Write","System","C:\Program Files\Capture\logs\deleted_files\C\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe"
"12/4/2010 11:30:38.487","registry","SetValueKey","C:\WINDOWS\system32\spoolsvc.exe","HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Spooler SubSystem App"
"12/4/2010 11:30:39.472","file","Write","System","C:\Program Files\Capture\logs\deleted_files\C\temp\40033d8063564d1b3e4b41f1d5c9a31f.exe"
"12/4/2010 11:30:39.472","file","Write","System","C:\Program Files\Capture\logs\deleted_files\C\temp\zcbgjy.bat" |