dkindlund/honeyclient

Update Documentation to disable IMAPI

Opened this issue · 3 comments

On WinXP sp2 this service is started by IE and writes temp files to c:\windows\temp

I disabled the service but an exception could also be made.

-Justin

Author: Justin ajwilder@gwu.edu
also add to ProcessMonitor.exl or disable service.

#windows security

  • svchost.exe .* C:\WINDOWS\system32\wscntfy.exe

Author: Justin ajwilder@gwu.edu
CORRECTION:

#windows security + wscntfy.exe .* C:\WINDOWS\system32\svchost.exe

Author: anonymous
adding it to the exclusions file doesn't work for me..
only disabling the service does (windows security center).