
Or it could have inherited these time stamps from the installation media. The file could have been moved onto this volume from another NTFS volume, causing the modification and born time stamps to be inherited from the original volume (see Figure 4 for time stamp update rules). I suspected regwin.exe hadn't been created on 20080414 because this system wasn't that old. Line one of the timeline data was disconcerting. Within 20 minutes of taking the system offline, I was staring at the following timeline data (see Figure 2): I took the suspect system offline and began gathering time line evidence. I grabbed a copy of Mandiant's Memoryze and collected a memory image from the system and copied it to my laptop for offline analysis using Audit Viewer.Īudit Viewer gave the kids_games.exe process a very high Malware Rating Index (see Figure 1), so I decided there was probably more at play here than kids games. The process id belonged to a process named kids_games.exe. I opened a command prompt on the system, ran netstat and saw an established connection to a host on a different network on port 443. A few minutes later, the user saw a strange pop up message asking to send an error report about regwin.exe to Microsoft. The user said he tried to play the games, but that nothing happened. Date changes are made with knobs on both sides of the unit.At approximately 22:50 CDT on 20101029 I responded to an event involving a user who had received an email from a friend with a link to some kid's games.

Solid brass type wheels provide superior imprint quality. Rugged die-cast case, sturdy lock to prevent tampering. Easy change ribbons advance and reverse automatically. Adjustable stamping force for multi-copy form. Solid-state circuitry assures consistent impression every time. Machines print automatically when paper is inserted. These plates can be used on any -RST machine, thus allowing tellers or other operators to change work stations.

Each user is responsible for his/her plate.

Individualized removable dies are engraved with teller number or other identification. Whether date only (AD-RST-E) or time and date (AR-RST-E) these special units are designed for validating bank documents. Stamping pressure can be increased for offices that need to penetrate through multi part carbon forms Instant heavy duty trigger operation instantly stamps the date 1-3/16" to 2" adjustable throat depth accommodates different size forms Machine comes equipped with lock and key system for added security Optional die plates for text available. The D-3 date stamper comes with a lock and key so only authorized personnel can adjust the settings. Simply insert your document beneath the trigger mechanism and it instantly prints. This model is the perfect companion for offices who need to date high volumes of documents the D-3 date stamps replaces your hand stamping operation. The throat depth can be adjusted and set to print on any designated area. The Widmer D-3 date stamp creates high quality, clean imprints on a wide variety of office documents from letter size paper to small tickets.
