Windows Log Software - File Copy, Execute, Delete etc

deadevil13

New member
Local time
9:11 PM
Messages
23
Location
South - East of England
Hi

Ok, this has bugged me for a while now. About 3 months ago, with my college computing class we attended a lecture/presentation from the guys at Kapernsky in which they showed us some basic tools for securing, and monitoring your own system. I remember them using programs like OllyDBG - but they also had this little software application (btw they told us all of the utilities they were using in the demonstration were available free online!) that monitored the copying of files, deletion of files, edits to the registry, starting/stopping services, running other exe's and opening new webpages.

In the demonstration they ran a 'malicious' installation package and this little log program ran beside it; once they had finished installing, they brought up the log screen and it showed that some services had been started, and where the virus had been installed.

Just wondering if any of you guys may know what this software is called? Links would be great! :D

Many Thanks
 

My Computer

Computer Manufacturer/Model Number
None - Whitebox
OS
Windows 7 x64 Ultimate
CPU
Intel i5-2500 3.30GHz
Motherboard
MSI P67A-C45 (MS-7673)
Memory
Corsair CMX8GX3M2A1600C9 - 8GB (2x4) @ 1333mhz
Graphics Card(s)
ATi Radeon HD3650
Sound Card
Motherboard OnBoard
Monitor(s) Displays
1x Gateway FPD1960 TFT Display (D-Sub)
Screen Resolution
1280 x 1024
Hard Drives
750GB SATA Seagate Barracuda 7200rpm
75GB SATA WD WDC WD740GD-00FLA1 10000rpm
PSU
Artic Power 500W
Case
Coolermaster CM Stacker
Cooling
Case Fans as stock, Venom Cooler
Keyboard
Logitech Cordless Desktop EX110 - Keyboard
Mouse
Logitech Cordless Desktop EX110 - Mouse
Internet Speed
Virgin Media - 30mbps (2mbps up)
Other Info
Speakers - Hi-Fi
Printer - HP All-In-One Deskjet F2280
Wireless - TPLink N+ Card
ODD - LG DVD-RW
I'm not sure what programs Kaspersky Lab uses in their demonstrations.
I am aware of Sysinternals suit, which has a set of free useful utilities with huge potential to trace viruses and things like that.
I have seen a video of Mark Russinovich (author) using this suit to do that. This guy works for MS now.

Update: In some of the Kaspersky Lab's slides it is possible to see Process Explorer by Sysinternals and another program Wireshark (Linux version).
 
Last edited:

My Computer

Computer type
PC/Desktop
OS
Windows 8.1 ; Windows 7 x86 (Dec2008-Jan2013)
Other Info
"The scale icon at the top right of a post or tutorial is how you can give rep to the member."
Back
Top