Microsoft Windows Vista Professional (6.0.6001) Service Pack 1
A:\ [Removable] (Total:0 Mo/Free:0 Mo)
C:\ [Fixed] - NTFS - (Total:57223 Mo/Free:3811 Mo)
D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
Sun 05/03/2009|19:35
----------------------\\ Processes..
--Locked-- [System Process]
--Locked-- System
---------- \SystemRoot\System32\smss.exe
---------- C:\Windows\system32\csrss.exe
---------- C:\Windows\system32\wininit.exe
---------- C:\Windows\system32\csrss.exe
---------- C:\Program Files\AVG\AVG8\avgrsx.exe
---------- C:\Windows\system32\winlogon.exe
---------- C:\Windows\system32\services.exe
---------- C:\Windows\system32\lsass.exe
---------- C:\Windows\system32\lsm.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\System32\svchost.exe
---------- C:\Windows\system32\Ati2evxx.exe
---------- C:\Windows\System32\svchost.exe
---------- C:\Windows\System32\svchost.exe
---------- C:\Windows\system32\svchost.exe
--Locked-- audiodg.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\SLsvc.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\WLANExt.exe
---------- C:\Windows\System32\spoolsv.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\Ati2evxx.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
---------- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
---------- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
---------- C:\Users\medic\Documents\GMTViewer[1]\GMT Viewer\GMTRemoteControl.exe
---------- C:\Windows\system32\inetsrv\inetinfo.exe
---------- C:\Windows\System32\svchost.exe
---------- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
---------- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
---------- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
---------- C:\Windows\System32\tcpsvcs.exe
---------- C:\Windows\system32\slserv.exe
---------- C:\Windows\System32\snmp.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\PROGRA~1\AVG\AVG8\avgemc.exe
---------- C:\Windows\system32\vssvc.exe
---------- C:\Windows\system32\taskeng.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\taskeng.exe
---------- C:\Windows\system32\Dwm.exe
---------- C:\Program Files\Windows Defender\MSASCui.exe
---------- C:\Windows\RtHDVCpl.exe
---------- C:\Program Files\AVG\AVG8\avgtray.exe
---------- C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
---------- C:\Windows\system32\wuauclt.exe
---------- C:\Windows\WindowsMobile\wmdc.exe
---------- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
---------- C:\Program Files\Windows Sidebar\sidebar.exe
---------- C:\Program Files\Windows Media Player\wmpnscfg.exe
---------- C:\Program Files\Windows Media Player\wmpnetwk.exe
---------- C:\Windows\system32\wbem\unsecapp.exe
---------- C:\Windows\system32\wbem\wmiprvse.exe
---------- C:\Program Files\Windows Sidebar\sidebar.exe
---------- C:\Windows\System32\svchost.exe
---------- C:\Windows\System32\mobsync.exe
---------- C:\Program Files\Trillian\trillian.exe
---------- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
---------- C:\Windows\explorer.exe
---------- C:\Program Files\Internet Explorer\iexplore.exe
---------- C:\Program Files\Internet Explorer\iexplore.exe
---------- C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
---------- C:\Windows\system32\cmd.exe
---------- C:\Rooter$\RK.exe
----------------------\\ Search..
----------------------\\ ROOTKIT !!
1 - "C:\Rooter$\Rooter_1.txt" - Sun 05/03/2009|19:35
----------------------\\ Scan completed at 19:35
OTListIt Extras logfile created on: 5/3/2009 7:38:06 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.3 Folder = C:\Users\medic\Desktop\geeks to go
Windows Vista Business Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 0.78 Gb Available Physical Memory | 38.78% Memory free
4.00 Gb Paging File | 2.67 Gb Available in Paging File | 66.71% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 7.72 Gb Free Space | 13.82% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: MEDICLAP
Current User Name: medic
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox3\firefox.exe (Mozilla Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
Reg Error: Unknown registry data type File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-2869060807-562205752-250988619-1000]
"EnableNotifications" = 1
"EnableNotificationsRef" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
"DisableNotifications" = 0
"EnableFirewall" = 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"DisableNotifications" = 0
"EnableFirewall" = 0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile
"DisableNotifications" = 0
"EnableFirewall" = 0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\GloballyOpenPorts\List
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
{06AB1BB8-E3AF-4388-8693-3448BA46C9A3} = LPORT=5721 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{0A42529F-5A74-4546-BE8E-EA0AC6E1F86E} = LPORT=990 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4001 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{11486F26-2AB7-4BF9-802F-F2268CADD5E5} = LPORT=990 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4001 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{121E19F9-4913-4833-8009-8DC32CA16FE1} = LPORT=5721 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{192BC44A-CC8B-4D42-B5FF-3F2D84EFC02F} = RPORT=5679 | PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4015 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{241C3ECB-7FEE-456C-965A-1CE40499DC2E} = LPORT=26675 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4006 |
{2773B150-9AE9-4121-8E8C-99B5D5C89ABF} = LPORT=26675 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4006 |
{28A54847-968D-4137-9A2A-671B480D0EC1} = LPORT=5721 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{2C44961C-C0FF-4DC5-9BEE-B2A02A418888} = LPORT=990 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4001 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{346A3207-1D74-40EE-A0C4-CF57D2EB385F} = LPORT=990 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4001 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{3AB56B6D-7729-4F27-B282-AB07E2BE4411} = LPORT=5678 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4004 | APP=%SYSTEMROOT%\WINDOWSMOBILE\WMDHOST.EXE |
{3B3F2709-F947-4D44-BDBC-5726B7EEEC37} = LPORT=999 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4005 | APP=%SYSTEMROOT%\WINDOWSMOBILE\WMDHOST.EXE |
{40D7BFD4-542A-4F6D-94A0-9A2C4E04D973} = LPORT=990 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4001 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{4288B0AB-9878-40DE-BAA2-91987AEE38E9} = RPORT=5679 | PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4015 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{4780F4DF-A3C1-4257-B8A6-28E9D787B504} = LPORT=990 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4001 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{5328A543-59A1-4A63-841B-2E78E41FFA08} = RPORT=5679 | PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4015 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{5429318D-B010-4FB4-8900-4A11159963C0} = LPORT=5721 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{551767C8-96C6-4442-845E-C22D09E78497} = LPORT=990 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4001 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{58C2C4A8-51C1-4314-8EB8-DCA16FBB499A} = RPORT=5679 | PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4015 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{5C8D0519-6252-43A1-9A8C-647B0E0DC89C} = LPORT=5721 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{67072E33-A659-46B1-8DEB-9B577C386960} = LPORT=3389 | PROFILE=DOMAIN | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | [email protected],-28753 | APP=SYSTEM |
{759BBDF9-2693-4331-902F-B75F591A39AA} = LPORT=999 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4005 | APP=%SYSTEMROOT%\WINDOWSMOBILE\WMDHOST.EXE |
{78B7E213-1C29-47C2-BAE2-79EEC886E9DD} = LPORT=990 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4001 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{7DA3F4E2-4133-44AB-8BA7-BECB4CFACE75} = LPORT=990 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4001 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{91F4FA59-A357-4FDD-B989-5F46A90DECDC} = LPORT=5678 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4004 | APP=%SYSTEMROOT%\WINDOWSMOBILE\WMDHOST.EXE |
{974359D3-6C9C-4C9D-9E5B-C6022E6854BD} = RPORT=5679 | PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4015 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{985B0C97-4083-44C2-9F4A-0E387FD2B621} = RPORT=5679 | PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4015 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{99B77499-3B71-49B6-ABE0-2C7CB3F1E198} = RPORT=5679 | PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4015 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{A928E309-645A-4134-98B9-BF0B7F47B47F} = RPORT=5679 | PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4015 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{AC32BD96-0C63-4B23-9342-B28AB760BEFD} = LPORT=5721 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{B9DDAAD9-301B-42AB-8BFE-264C982EEB52} = RPORT=5679 | PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4015 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{B9E2FF16-79AF-4126-A76C-5CA3E55C6112} = LPORT=5721 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{C2E9EB7F-A8BC-4F1B-BFAD-84EFB39AD534} = LPORT=5721 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{C5B9C3B7-0058-4BA3-BBDA-BD62B78B1BE6} = LPORT=5721 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{C9884480-6371-4963-B2C2-0EEEE125C344} = LPORT=990 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4001 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{EA845EE6-1C7A-47AE-BD35-BD3C703BE90A} = LPORT=5721 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{EDD3628D-485A-4B7C-A09D-28C9B9DACC38} = RPORT=5679 | PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4015 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{FE8B8F29-9255-427A-A705-444D4C8B1AAC} = LPORT=6004 | PROFILE=PUBLIC | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=MICROSOFT OFFICE OUTLOOK | APP=C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\OUTLOOK.EXE |
========== Vista Active Application Exception List ==========
{016904C1-12BB-4DC3-BF5C-C14A84C085E5} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{01E5F4EB-736B-4275-AFAF-2410D0D61489} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{071DFED1-5B24-4357-B675-2131B39B6D0B} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{077BCB3D-944A-4028-8EE1-A7360FB97F6E} = DIR=IN | ACTION=ALLOW | NAME=SKYPE | APP=C:\PROGRAM FILES\SKYPE\PHONE\SKYPE.EXE |
{079E3560-D15C-4342-871B-35457DD90D8E} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{09226954-4A4E-47C6-9502-49D5FA7674E7} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{0A7D61FC-BE44-4B25-A510-0EF3B36C47C9} = PROFILE=PRIVATE | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=YAHOO! FT SERVER | APP=C:\PROGRAM FILES\YAHOO!\MESSENGER\YSERVER.EXE |
{1042B434-882C-49B4-A9C5-681B20683158} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{11FCD6D4-806E-4AE2-95AC-446B7DA1C519} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{12690B66-81D3-4F51-A2B6-25DFBB9DE30C} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{166F69BA-1C18-4445-9672-43E24A14284F} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{18868088-612F-4FC0-B1EB-032259668128} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{1FF50E2A-E63D-4231-8B88-7A04ED17DD90} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{265E5AF7-DFD7-4CEC-9618-0D81F96F38B0} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{2B217A8E-B341-422D-B049-50C640DFA351} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{31C73B8C-F7D1-475B-BB6C-6BEB068D9A1C} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{38507112-B163-4679-A04B-7FAEC7137D73} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{3A0E8C50-6A8A-468A-BE51-EB4D2F5E133E} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{3F48590D-39BA-40D1-BD05-49BD0EA440CE} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{40593D20-3031-4A2C-9444-5FEC488A5095} = PROFILE=PUBLIC | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=MICROSOFT OFFICE ONENOTE | APP=C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\ONENOTE.EXE |
{47F87594-B417-4D81-A334-F6FC24B7E359} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{49025AA9-A125-4496-AD1F-9BCE8B569A06} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{4BEFFBE8-F501-4D50-9E79-3B9E4E494833} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{4D9CA384-C5E4-4CC7-BDDC-443CF5343173} = PROFILE=PUBLIC | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=MICROSOFT OFFICE ONENOTE | APP=C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\ONENOTE.EXE |
{4E0FCE84-ABAA-435A-8774-DF9AD0D0B3E5} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{4F36356C-2BC6-4A59-9D68-F955F1510C12} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{4F737B34-7AAD-4DAF-9F0D-6ABB5307256A} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{4FD412F7-2768-4FF5-A6D5-8CD79D1A7356} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{502D4E93-1589-45C1-8C73-F63D42904442} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{5D7B64F1-A5C5-4937-8220-49D3F2C83577} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{60441285-9C7C-49FD-8162-3F694C97B637} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{68CD30EC-ED6F-4162-B764-0BFEBC885CEA} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{6EB4DC4A-9192-42A3-AEDF-EB33D330DB51} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{7B3E5771-3C71-43FA-8437-3FC3298A49E0} = PROFILE=PRIVATE | DIR=IN | ACTION=ALLOW | NAME=AVGUPD.EXE | APP=C:\PROGRAM FILES\AVG\AVG8\AVGUPD.EXE |
{83669094-4640-493D-B05E-44A1E903844E} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{85AED62B-A3CD-4C9B-9551-BEE1D5F67FF1} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{89B98DE4-21F3-4EFC-B0BD-C77EC7A1595A} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{8B78201C-9F83-4050-8679-9DD4C2EAAEEF} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{915B93CF-F75A-4B9F-A089-9983233B6306} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{958C0CEC-8A4F-495B-AEF8-BDAF7D2ADE0C} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{9680A8FB-0AC1-4AED-A716-4032F29C978D} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{9C9BE10A-3337-47C0-BD0D-7E5A6E921BD5} = PROFILE=PRIVATE | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=YAHOO! FT SERVER | APP=C:\PROGRAM FILES\YAHOO!\MESSENGER\YSERVER.EXE |
{9D1BC4AF-FA76-4A35-A975-C7D0B6C0C5DE} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{A4CF87A3-42E8-4738-8608-FEC6F3BF0BAE} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{A4DB0C65-CA36-4FDB-BC3F-3D9E75037A55} = DIR=IN | ACTION=ALLOW | NAME=WINDOWS LIVE SYNC | APP=C:\PROGRAM FILES\WINDOWS LIVE\SYNC\WINDOWSLIVESYNC.EXE |
{A5AD408E-20B0-46CF-B947-D5A4AB034248} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{A7443C83-58C6-427B-9B33-5114C542985B} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{AA96D2D2-1063-4586-A9E7-E2980F7E7BDE} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{AE8D2F47-3063-45D7-986B-2C7624F92017} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{B1B92B1D-F2DD-46F4-B47E-220D376D23AC} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{B9A53EC3-0DBE-4E31-A7B0-C68D3FB5D8FE} = PROFILE=PRIVATE | DIR=IN | ACTION=ALLOW | NAME=AVGEMC.EXE | APP=C:\PROGRAM FILES\AVG\AVG8\AVGEMC.EXE |
{C08FAC61-7EC6-4F5E-855B-61DCB4B89122} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{C2322431-F37C-465F-A0D2-FC85DBAC9358} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{C9E5A688-B09F-4C0C-BE28-4A939F5E8CBA} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{DD7BFF17-66CF-40CC-BE10-0B1B7BBA2B51} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{DE8934F5-BD5E-45D5-807E-EB08EC685214} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{E074A2F4-6678-4698-BDA3-A375FB91CF44} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{E0E153E2-4F94-4835-A481-5952DFBEBF73} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{E1A03B90-04B2-469E-B9F3-F2A00F866572} = PROFILE=PUBLIC | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=MICROSOFT OFFICE GROOVE | APP=C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\GROOVE.EXE |
{E91CE9AB-3045-4696-BA5A-A09FA38EF4E6} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{EC355143-7C07-410C-B619-5C12DBC6A80B} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{EE331DA6-B18D-415A-8986-3D8E8973F1A8} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{EEB6BC1A-488F-413C-8FD6-579232E479F3} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{F017A1EC-9DF6-4E56-8DAD-EA2D0A7D5C8C} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{F059C2DD-DF54-4CC9-A827-626748D9B263} = PROFILE=PRIVATE | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=YAHOO! MESSENGER | APP=C:\PROGRAM FILES\YAHOO!\MESSENGER\YAHOOMESSENGER.EXE |
{F6724FDB-255C-4B46-9AEC-C66CAF131CA8} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{FAC4EACF-3C7B-4373-B55D-34BBE6516803} = PROFILE=PUBLIC | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=MICROSOFT OFFICE GROOVE | APP=C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\GROOVE.EXE |
{FBB3C59B-B8A9-4108-9ED7-BA0B71C4A2DB} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{FD0D0C14-2A8C-4FF8-B7F5-910A3CBE767A} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{FD13E1CB-0183-41EE-9547-1E8042A2189A} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{FDA903D5-095E-436A-9A4C-CE1012C170BC} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{FEEDEB9D-D696-4AA5-B7CD-3E9215A963D1} = PROFILE=PRIVATE | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=YAHOO! MESSENGER | APP=C:\PROGRAM FILES\YAHOO!\MESSENGER\YAHOOMESSENGER.EXE |
TCP Query User{4609A15F-93BF-47AF-BD64-E10A809CC7B9}C:\program files\mozilla firefox\firefox.exe = PROFILE=PRIVATE | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=FIREFOX | APP=C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE |
TCP Query User{84D22520-8C7E-4F8E-83F8-D51349B6E261}D:\autorun.exe = PROFILE=PRIVATE | PROTOCOL=6 | DIR=IN | ACTION=BLOCK | NAME=CD NAVIGATOR | APP=D:\AUTORUN.EXE |
TCP Query User{901D1097-D0FF-4093-B6D8-6B726255917E}C:\program files\internet explorer\iexplore.exe = PROFILE=PRIVATE | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=INTERNET EXPLORER | APP=C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE |
TCP Query User{D03A0B30-9D95-40D2-A940-646E9F138F2F}C:\users\medic\appdata\local\temp\temp1_sc101t_cd_initial_release.zip\sc101t_cd\autorun.exe = PROFILE=PRIVATE | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=AUTORUN.EXE | APP=C:\USERS\MEDIC\APPDATA\LOCAL\TEMP\TEMP1_SC101T_CD_INITIAL_RELEASE.ZIP\SC101T_CD\AUTORUN.EXE |
UDP Query User{8E17E162-11CE-43FB-8C6B-60E379AD5DF4}C:\program files\internet explorer\iexplore.exe = PROFILE=PRIVATE | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=INTERNET EXPLORER | APP=C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE |
UDP Query User{AB1ED99A-4310-41DE-ACD5-F6D64AF79B09}C:\users\medic\appdata\local\temp\temp1_sc101t_cd_initial_release.zip\sc101t_cd\autorun.exe = PROFILE=PRIVATE | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=AUTORUN.EXE | APP=C:\USERS\MEDIC\APPDATA\LOCAL\TEMP\TEMP1_SC101T_CD_INITIAL_RELEASE.ZIP\SC101T_CD\AUTORUN.EXE |
UDP Query User{B5279983-DE23-44E8-9F81-7A691D3B3D68}D:\autorun.exe = PROFILE=PRIVATE | PROTOCOL=17 | DIR=IN | ACTION=BLOCK | NAME=CD NAVIGATOR | APP=D:\AUTORUN.EXE |
UDP Query User{D34DA981-E106-4D8E-91D6-A65C41F3A7F7}C:\program files\mozilla firefox\firefox.exe = PROFILE=PRIVATE | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=FIREFOX | APP=C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{0837A661-FEC3-48B3-876C-91E7D32048A9}" = Macromedia Dreamweaver 8
"{10CE1EA2-12E9-11D3-825E-00C04F6843FE}" = Microsoft Office Sounds
"{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}" = QuickTime
"{1F8AE5F3-DCF7-1911-427B-E23AE9385FF8}" = ATI Catalyst Install Manager
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2BD5C305-1B27-4D41-B690-7A61172D2FEB}" = Macromedia Flash 8
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java 6 Update 5
"{353D20CC-719B-4A60-AD33-D03F88C10330}" = Microsoft Office Accounting PayPal Addin
"{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision
"{397FF711-8BD9-4388-ADFC-2A878B83F018}" = Cisco Network Assistant
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C52E7DA-C431-4239-B66B-1BF703D5B194}" = Windows Live Photo Gallery
"{46614A49-222A-48EF-87A9-BFD603E608E1}" = Microsoft Office Accounting Fixed Asset Manager
"{4C24A8C1-7CFA-4650-AF15-732F5BD7B46D}" = Macromedia Fireworks 8
"{506AFDAB-950B-4D3D-BF77-641B8AD34462}" = PrimeSuite Scanning Components 14.0
"{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}" = Macromedia Extension Manager
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8
"{5FA793A6-0071-42C1-9355-8F69A428C44F}" = Microsoft Office Accounting ADP Payroll Addin
"{619B8475-0F48-41B7-A370-5147F7092989}" = Virtual Earth 3D (Beta)
"{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI
"{64BBFDCB-D3C8-48c5-8FEB-73CC3502633B}" = Pantech Modem Link Software
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7279647E-8661-48DF-998E-E7DCC3E6955D}" = Microsoft Office Live Meeting 2005
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{768FE04E-FDEE-4EEC-AE7E-A25DF7E88591}" = PrimeSuite Client Components
"{7AB8B57B-5E54-49C1-98CC-86D4C1CC1949}" = OfficeSafe
"{81A34902-9D0B-4920-A25C-4CDC5D14B328}" = Jasc Paint Shop Pro 8
"{871DF2BE-41D2-4334-AC33-839AF16FC8FE}" = Cisco Systems VPN Client 5.0.02.0090
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}" = Macromedia Flash 8 Video Encoder
"{8C6BB412-D3A8-4AAE-A01B-35B681789D68}" = mHelp
"{8C711818-076E-475C-B95B-DF11CD9D8DBE}" = Microsoft Office Accounting Equifax Addin
"{8ECB8220-F422-4BEB-9596-97033C533702}" = QuickBooks Pro 2008
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_PRJPROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_VISPROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_PRJPROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_VISPROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_PRJPROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_VISPROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0054-0409-0000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2007
"{90120000-0054-0409-0000-0000000FF1CE}_VISPROR_{519D9F45-CBF4-4E57-B419-11F196CCA8AE}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_PRJPROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_VISPROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
"{90120000-00B4-0409-0000-0000000FF1CE}" = Microsoft Office Project MUI (English) 2007
"{90120000-00B4-0409-0000-0000000FF1CE}_PRJPROR_{27A9D316-D332-433B-8EB1-1D93EE49F26D}" = Microsoft Office Project 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_PRJPROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_VISPROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{904CCF62-818D-4675-BC76-D37EB399F917}" = Windows Mobile Device Center
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-003B-0000-0000-0000000FF1CE}" = Microsoft Office Project Professional 2007
"{91120000-003B-0000-0000-0000000FF1CE}_PRJPROR_{9E73617F-2F38-4864-BD61-BB2DDFE43323}" = Microsoft Office Project 2007 Service Pack 2 (SP2)
"{91120000-0051-0000-0000-0000000FF1CE}" = Microsoft Office Visio Professional 2007
"{91120000-0051-0000-0000-0000000FF1CE}_VISPROR_{0FD405D3-CAF8-4CA6-8BFD-911D2F8A6585}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{939740B5-0064-4779-854A-8C1086181C05}" = Macromedia FreeHand MXa
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BBD1CB9-38CA-43EB-A67C-7631F804AED6}" = Microsoft Office Accounting 2007 SDK
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}" = Windows Live Sync
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{B0717D5A-1976-482B-9ADF-F19631A541A4}" = Microsoft Office Accounting 2007
"{BC595C7E-899E-44C1-8B25-8763853FF20C}" = 3D Home Architect Design Suite Deluxe 6
"{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{CA9BAADB-C262-4E05-B2E2-CEE8CE9809EC}" = mToolkit
"{CB8CA439-DA83-419C-A4CF-5A0A50025144}" = Windows Mobile Device Center Driver Update
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1D4C9A3-060B-472A-88B7-B313CD622381}" = Windows Marketplace upgrade options tool
"{D6FD2A0F-E1FD-4795-A774-D42261F92FF1}" = NETGEAR Storage Central Manager Utility
"{DBF6F373-236E-49EE-9A07-0F67B4EAC8E8}" = SPMP3050 Transcoding Tool
"{EA516024-D84D-41F1-814F-83175A6188F2}" = Logitech Video Enumerator
"{EB9A4856-C28A-4BC2-9373-975A33BB9CD4}" = Live Search Maps Add-In for Microsoft Office Outlook
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F5D7FAB5-A1FD-4DD3-983E-4155B09D7102}" = mCore
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"ACBLscore" = ACBLscore
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Illustrator 9.0" = Adobe Illustrator 9.0
"Adobe SVG Viewer" = Adobe SVG Viewer
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"Android Newsgroup Downloader_is1" = Android Newsgroup Downloader v 6.1
"AVG8Uninstall" = AVG Free 8.0
"Bridge Squeezes Complete" = Bridge Squeezes Complete
"Bridge_Base_Online" = Bridge Base Online
"Carbonite Backup" = Carbonite
"CutePDF Writer Installation" = CutePDF Writer 2.7
"Dell Laser MFP 1600n" = Dell Laser MFP 1600n Software Uninstall
"ENTERPRISER" = Microsoft Office Enterprise 2007
"ERUNT_is1" = ERUNT 1.1j
"FoxyTunesForFirefox" = FoxyTunes for Firefox
"FTDICOMM" = USB Download Interface Driver
"GAP - Gas Absorption Program" = GAP - Gas Absorption Program
"GAP RGBM 2.3" = GAP RGBM 2.3
"IE7Pro_is1" = IE7Pro
"ieSpell" = ieSpell
"InstallShield_{BC595C7E-899E-44C1-8B25-8763853FF20C}" = 3D Home Architect Design Suite Deluxe 6
"IObit SmartDefrag Beta5.01_is1" = IObit SmartDefrag
"Jasc Paint Shop Pro 8.10 Update Patch" = Jasc Paint Shop Pro 8.10 Update Patch
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediLexicon Toolbar_is1" = MediLexicon Toolbar v.1.0
"MediLexiconMediLexicon" = MediLexicon - Toolbar
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Office Accounting 2007" = Microsoft Office Accounting 2007
"Microsoft Office Accounting Equifax Addin" = Microsoft Office Accounting Equifax Addin
"Microsoft Office Accounting PayPal Addin" = Microsoft Office Accounting PayPal Addin
"Mikogo" = Mikogo
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"Mozilla Thunderbird (2.0.0.21)" = Mozilla Thunderbird (2.0.0.21)
"NDCMedisoft Network Professional 10 SP2" = NDCMedisoft Network Professional 10 SP2
"PRJPROR" = Microsoft Office Project Professional 2007
"ProInst" = Intel® PROSet/Wireless Software
"RealPlayer 6.0" = RealPlayer
"ToolbarBrowser_is1" = ToolbarBrowser v2.4
"Trend Micro HouseCall 6.6" = HouseCall 6.6
"Trillian" = Trillian
"TurboMeeting" = TurboMeeting
"VISPROR" = Microsoft Office Visio Professional 2007
"V-Planner Mobile_is1" = V-Planner Mobile 3.27
"V-Planner_is1" = V-Planner 3.84
"VZAccess Manager" = VZAccess Manager
"WinLiveSuite_Wave3" = Windows Live Essentials
"Yahoo! Messenger" = Yahoo! Messenger
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ActiveTouchMeetingClient" = WebEx
"CrossFTP" = CrossFTP
"GoToMeeting" = GoToMeeting/GoToWebinar 3.0.0.198
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 3/24/2008 11:41:39 AM | Computer Name = mediclap | Source = Perflib | ID = 1008
Description =
Error - 3/24/2008 11:41:53 AM | Computer Name = mediclap | Source = usbperf | ID = 2004
Description = Usbperf data collection failed. Collect function called with usupported
Query Type.
Error - 3/24/2008 11:45:12 AM | Computer Name = mediclap | Source = usbperf | ID = 2004
Description = Usbperf data collection failed. Collect function called with usupported
Query Type.
Error - 3/24/2008 11:51:07 AM | Computer Name = mediclap | Source = usbperf | ID = 2004
Description = Usbperf data collection failed. Collect function called with usupported
Query Type.
Error - 3/24/2008 12:05:14 PM | Computer Name = mediclap | Source = usbperf | ID = 2004
Description = Usbperf data collection failed. Collect function called with usupported
Query Type.
Error - 3/24/2008 12:07:44 PM | Computer Name = mediclap | Source = usbperf | ID = 2004
Description = Usbperf data collection failed. Collect function called with usupported
Query Type.
Error - 3/24/2008 12:13:43 PM | Computer Name = mediclap | Source = usbperf | ID = 2004
Description = Usbperf data collection failed. Collect function called with usupported
Query Type.
Error - 3/28/2008 9:04:19 PM | Computer Name = mediclap | Source = VSS | ID = 12310
Description =
Error - 3/28/2008 9:04:19 PM | Computer Name = mediclap | Source = VSS | ID = 12298
Description =
Error - 3/29/2008 6:10:14 PM | Computer Name = mediclap | Source = VSS | ID = 12289
Description =
[ DFS Replication Events ]
Error - 4/2/2008 10:56:07 AM | Computer Name = mediclap | Source = DFSR | ID = 4004
Description = The DFS Replication service stopped replication on the replicated
folder at local path C:\Users\medic\AppData\Local\Microsoft\Windows\Temporary Internet
Files\FileShare\Windows Collaboration\{FCA5BF7B-D700-0150-8EF1-814794DF17CE}. Additional
Information: Error: 2 (The system cannot find the file specified.) Additional context
of the error: Replicated Folder Name: Windows Meeting Space Folders Replicated
Folder ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Replication Group Name: Windows Meeting
Space Group Replication Group ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Member ID:
52366055-8A0A-7C63-5560-36520A8A637C
Error - 4/2/2008 11:20:07 AM | Computer Name = mediclap | Source = DFSR | ID = 4004
Description = The DFS Replication service stopped replication on the replicated
folder at local path C:\Users\medic\AppData\Local\Microsoft\Windows\Temporary Internet
Files\FileShare\Windows Collaboration\{FCA5BF7B-D700-0150-8EF1-814794DF17CE}. Additional
Information: Error: 2 (The system cannot find the file specified.) Additional context
of the error: Replicated Folder Name: Windows Meeting Space Folders Replicated
Folder ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Replication Group Name: Windows Meeting
Space Group Replication Group ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Member ID:
52366055-8A0A-7C63-5560-36520A8A637C
Error - 4/2/2008 12:52:07 PM | Computer Name = mediclap | Source = DFSR | ID = 4004
Description = The DFS Replication service stopped replication on the replicated
folder at local path C:\Users\medic\AppData\Local\Microsoft\Windows\Temporary Internet
Files\FileShare\Windows Collaboration\{FCA5BF7B-D700-0150-8EF1-814794DF17CE}. Additional
Information: Error: 2 (The system cannot find the file specified.) Additional context
of the error: Replicated Folder Name: Windows Meeting Space Folders Replicated
Folder ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Replication Group Name: Windows Meeting
Space Group Replication Group ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Member ID:
52366055-8A0A-7C63-5560-36520A8A637C
Error - 4/2/2008 1:56:03 PM | Computer Name = mediclap | Source = DFSR | ID = 4004
Description = The DFS Replication service stopped replication on the replicated
folder at local path C:\Users\medic\AppData\Local\Microsoft\Windows\Temporary Internet
Files\FileShare\Windows Collaboration\{FCA5BF7B-D700-0150-8EF1-814794DF17CE}. Additional
Information: Error: 2 (The system cannot find the file specified.) Additional context
of the error: Replicated Folder Name: Windows Meeting Space Folders Replicated
Folder ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Replication Group Name: Windows Meeting
Space Group Replication Group ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Member ID:
52366055-8A0A-7C63-5560-36520A8A637C
Error - 4/2/2008 2:03:03 PM | Computer Name = mediclap | Source = DFSR | ID = 4004
Description = The DFS Replication service stopped replication on the replicated
folder at local path C:\Users\medic\AppData\Local\Microsoft\Windows\Temporary Internet
Files\FileShare\Windows Collaboration\{FCA5BF7B-D700-0150-8EF1-814794DF17CE}. Additional
Information: Error: 2 (The system cannot find the file specified.) Additional context
of the error: Replicated Folder Name: Windows Meeting Space Folders Replicated
Folder ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Replication Group Name: Windows Meeting
Space Group Replication Group ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Member ID:
52366055-8A0A-7C63-5560-36520A8A637C
Error - 4/2/2008 2:27:03 PM | Computer Name = mediclap | Source = DFSR | ID = 4004
Description = The DFS Replication service stopped replication on the replicated
folder at local path C:\Users\medic\AppData\Local\Microsoft\Windows\Temporary Internet
Files\FileShare\Windows Collaboration\{FCA5BF7B-D700-0150-8EF1-814794DF17CE}. Additional
Information: Error: 2 (The system cannot find the file specified.) Additional context
of the error: Replicated Folder Name: Windows Meeting Space Folders Replicated
Folder ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Replication Group Name: Windows Meeting
Space Group Replication Group ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Member ID:
52366055-8A0A-7C63-5560-36520A8A637C
Error - 4/2/2008 3:59:03 PM | Computer Name = mediclap | Source = DFSR | ID = 4004
Description = The DFS Replication service stopped replication on the replicated
folder at local path C:\Users\medic\AppData\Local\Microsoft\Windows\Temporary Internet
Files\FileShare\Windows Collaboration\{FCA5BF7B-D700-0150-8EF1-814794DF17CE}. Additional
Information: Error: 2 (The system cannot find the file specified.) Additional context
of the error: Replicated Folder Name: Windows Meeting Space Folders Replicated
Folder ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Replication Group Name: Windows Meeting
Space Group Replication Group ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Member ID:
52366055-8A0A-7C63-5560-36520A8A637C
Error - 4/2/2008 8:10:39 PM | Computer Name = mediclap | Source = DFSR | ID = 4004
Description = The DFS Replication service stopped replication on the replicated
folder at local path C:\Users\medic\AppData\Local\Microsoft\Windows\Temporary Internet
Files\FileShare\Windows Collaboration\{FCA5BF7B-D700-0150-8EF1-814794DF17CE}. Additional
Information: Error: 2 (The system cannot find the file specified.) Additional context
of the error: Replicated Folder Name: Windows Meeting Space Folders Replicated
Folder ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Replication Group Name: Windows Meeting
Space Group Replication Group ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Member ID:
52366055-8A0A-7C63-5560-36520A8A637C
Error - 4/2/2008 11:31:01 PM | Computer Name = mediclap | Source = DFSR | ID = 4004
Description = The DFS Replication service stopped replication on the replicated
folder at local path C:\Users\medic\AppData\Local\Microsoft\Windows\Temporary Internet
Files\FileShare\Windows Collaboration\{FCA5BF7B-D700-0150-8EF1-814794DF17CE}. Additional
Information: Error: 2 (The system cannot find the file specified.) Additional context
of the error: Replicated Folder Name: Windows Meeting Space Folders Replicated
Folder ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Replication Group Name: Windows Meeting
Space Group Replication Group ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Member ID:
52366055-8A0A-7C63-5560-36520A8A637C
Error - 4/2/2008 11:38:01 PM | Computer Name = mediclap | Source = DFSR | ID = 4004
Description = The DFS Replication service stopped replication on the replicated
folder at local path C:\Users\medic\AppData\Local\Microsoft\Windows\Temporary Internet
Files\FileShare\Windows Collaboration\{FCA5BF7B-D700-0150-8EF1-814794DF17CE}. Additional
Information: Error: 2 (The system cannot find the file specified.) Additional context
of the error: Replicated Folder Name: Windows Meeting Space Folders Replicated
Folder ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Replication Group Name: Windows Meeting
Space Group Replication Group ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Member ID:
52366055-8A0A-7C63-5560-36520A8A637C
[ OSession Events ]
Error - 11/8/2007 2:52:35 PM | Computer Name = mediclap | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 11464
seconds with 120 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 4/28/2009 11:34:49 PM | Computer Name = mediclap | Source = BTHUSB | ID = 327696
Description = The mutual authentication between the local Bluetooth adapter and
a device with Bluetooth adapter address (00:23:d6:a8:e1:c6) failed.
Error - 4/28/2009 11:35:19 PM | Computer Name = mediclap | Source = BTHUSB | ID = 327696
Description = The mutual authentication between the local Bluetooth adapter and
a device with Bluetooth adapter address (00:23:d6:a8:e1:c6) failed.
Error - 4/29/2009 3:58:54 PM | Computer Name = mediclap | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description =
Error - 4/29/2009 8:35:49 PM | Computer Name = mediclap | Source = EventLog | ID = 6008
Description = The previous system shutdown at 7:16:50 PM on 4/29/2009 was unexpected.
Error - 4/29/2009 8:33:28 PM | Computer Name = mediclap | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!
Error - 4/29/2009 8:33:28 PM | Computer Name = mediclap | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description =
Error - 4/29/2009 8:33:30 PM | Computer Name = mediclap | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 1
Description =
Error - 4/29/2009 8:33:40 PM | Computer Name = mediclap | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!
Error - 4/29/2009 8:35:54 PM | Computer Name = mediclap | Source = HTTP | ID = 15016
Description =
Error - 4/29/2009 8:37:11 PM | Computer Name = mediclap | Source = Service Control Manager | ID = 7000
Description =
< End of report >