"12/4/2010 11:30:36.81","process","created","C:\\WINDOWS\\system32\\cmd.exe","C:\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe" "12/4/2010 11:30:37.222","file","Write","C:\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe","C:\\WINDOWS\\system32\\spoolsvc.exe" "12/4/2010 11:30:37.222","file","Write","C:\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe","C:\\WINDOWS\\system32\\spoolsvc.exe" "12/4/2010 11:30:37.222","file","Write","C:\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe","C:\\WINDOWS\\system32\\spoolsvc.exe" "12/4/2010 11:30:37.222","file","Write","C:\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe","C:\\temp\\zcbgjy.bat" "12/4/2010 11:30:37.300","registry","SetValueKey","C:\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe","HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass" "12/4/2010 11:30:37.300","registry","SetValueKey","C:\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe","HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName" "12/4/2010 11:30:37.300","registry","SetValueKey","C:\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe","HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet" "12/4/2010 11:30:37.300","registry","SetValueKey","C:\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe","HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass" "12/4/2010 11:30:37.300","registry","SetValueKey","C:\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe","HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName" "12/4/2010 11:30:37.300","registry","SetValueKey","C:\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe","HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet" "12/4/2010 11:30:37.300","registry","SetValueKey","C:\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe","HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Cache" "12/4/2010 11:30:37.300","registry","SetValueKey","C:\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe","HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\Cookies" "12/4/2010 11:30:37.347","process","created","C:\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe","C:\\WINDOWS\\system32\\cmd.exe" "12/4/2010 11:30:37.378","process","created","C:\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe","C:\\WINDOWS\\system32\\spoolsvc.exe" "12/4/2010 11:30:37.331","registry","SetValueKey","C:\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe","HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{3f04edc3-85c6-11de-af20-806d6172696f}\\BaseClass" "12/4/2010 11:30:37.347","registry","SetValueKey","C:\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe","HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{cb7e6034-4640-11df-b8d9-806d6172696f}\\BaseClass" "12/4/2010 11:30:37.347","registry","SetValueKey","C:\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe","HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{3f04edc0-85c6-11de-af20-806d6172696f}\\BaseClass" "12/4/2010 11:30:37.347","file","Write","System","C:\\WINDOWS\\system32\\spoolsvc.exe" "12/4/2010 11:30:37.362","file","Write","System","C:\\WINDOWS\\system32\\spoolsvc.exe" "12/4/2010 11:30:37.362","file","Write","System","C:\\WINDOWS\\system32\\spoolsvc.exe" "12/4/2010 11:30:37.597","process","terminated","C:\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe","C:\\WINDOWS\\system32\\cmd.exe" "12/4/2010 11:30:37.581","file","Write","C:\\WINDOWS\\system32\\cmd.exe","C:\\Program Files\\Capture\\logs\\deleted\_files\\C\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe" "12/4/2010 11:30:37.581","file","Write","C:\\WINDOWS\\system32\\cmd.exe","C:\\Program Files\\Capture\\logs\\deleted\_files\\C\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe" "12/4/2010 11:30:37.581","file","Write","C:\\WINDOWS\\system32\\cmd.exe","C:\\Program Files\\Capture\\logs\\deleted\_files\\C\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe" "12/4/2010 11:30:37.581","file","Delete","C:\\WINDOWS\\system32\\cmd.exe","C:\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe" "12/4/2010 11:30:37.581","file","Write","C:\\WINDOWS\\system32\\cmd.exe","C:\\Program Files\\Capture\\logs\\deleted\_files\\C\\temp\\zcbgjy.bat" "12/4/2010 11:30:37.597","file","Delete","C:\\WINDOWS\\system32\\cmd.exe","C:\\temp\\zcbgjy.bat" "12/4/2010 11:30:38.362","file","Write","System","C:\\Program Files\\Capture\\logs\\deleted\_files\\C\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe" "12/4/2010 11:30:38.472","file","Write","System","C:\\Program Files\\Capture\\logs\\deleted\_files\\C\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe" "12/4/2010 11:30:38.487","registry","SetValueKey","C:\\WINDOWS\\system32\\spoolsvc.exe","HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\Spooler SubSystem App" "12/4/2010 11:30:39.472","file","Write","System","C:\\Program Files\\Capture\\logs\\deleted\_files\\C\\temp\\40033d8063564d1b3e4b41f1d5c9a31f.exe" "12/4/2010 11:30:39.472","file","Write","System","C:\\Program Files\\Capture\\logs\\deleted\_files\\C\\temp\\zcbgjy.bat"