Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

I think i either have someone ghosting or a key logger


  • Please log in to reply

#1
medic

medic

    Member

  • Member
  • PipPip
  • 74 posts
system runs slow especially on the internet. It seems that a number of my online accounts have been hacked -- i think via keystroke recorder.



Microsoft Windows Vista Professional (6.0.6001) Service Pack 1

A:\ [Removable] (Total:0 Mo/Free:0 Mo)
C:\ [Fixed] - NTFS - (Total:57223 Mo/Free:3811 Mo)
D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)

Sun 05/03/2009|19:35

----------------------\\ Processes..

--Locked-- [System Process]
--Locked-- System
---------- \SystemRoot\System32\smss.exe
---------- C:\Windows\system32\csrss.exe
---------- C:\Windows\system32\wininit.exe
---------- C:\Windows\system32\csrss.exe
---------- C:\Program Files\AVG\AVG8\avgrsx.exe
---------- C:\Windows\system32\winlogon.exe
---------- C:\Windows\system32\services.exe
---------- C:\Windows\system32\lsass.exe
---------- C:\Windows\system32\lsm.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\System32\svchost.exe
---------- C:\Windows\system32\Ati2evxx.exe
---------- C:\Windows\System32\svchost.exe
---------- C:\Windows\System32\svchost.exe
---------- C:\Windows\system32\svchost.exe
--Locked-- audiodg.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\SLsvc.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\WLANExt.exe
---------- C:\Windows\System32\spoolsv.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\Ati2evxx.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe
---------- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
---------- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
---------- C:\Users\medic\Documents\GMTViewer[1]\GMT Viewer\GMTRemoteControl.exe
---------- C:\Windows\system32\inetsrv\inetinfo.exe
---------- C:\Windows\System32\svchost.exe
---------- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
---------- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
---------- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
---------- C:\Windows\System32\tcpsvcs.exe
---------- C:\Windows\system32\slserv.exe
---------- C:\Windows\System32\snmp.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\PROGRA~1\AVG\AVG8\avgemc.exe
---------- C:\Windows\system32\vssvc.exe
---------- C:\Windows\system32\taskeng.exe
---------- C:\Windows\system32\svchost.exe
---------- C:\Windows\system32\taskeng.exe
---------- C:\Windows\system32\Dwm.exe
---------- C:\Program Files\Windows Defender\MSASCui.exe
---------- C:\Windows\RtHDVCpl.exe
---------- C:\Program Files\AVG\AVG8\avgtray.exe
---------- C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
---------- C:\Windows\system32\wuauclt.exe
---------- C:\Windows\WindowsMobile\wmdc.exe
---------- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
---------- C:\Program Files\Windows Sidebar\sidebar.exe
---------- C:\Program Files\Windows Media Player\wmpnscfg.exe
---------- C:\Program Files\Windows Media Player\wmpnetwk.exe
---------- C:\Windows\system32\wbem\unsecapp.exe
---------- C:\Windows\system32\wbem\wmiprvse.exe
---------- C:\Program Files\Windows Sidebar\sidebar.exe
---------- C:\Windows\System32\svchost.exe
---------- C:\Windows\System32\mobsync.exe
---------- C:\Program Files\Trillian\trillian.exe
---------- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
---------- C:\Windows\explorer.exe
---------- C:\Program Files\Internet Explorer\iexplore.exe
---------- C:\Program Files\Internet Explorer\iexplore.exe
---------- C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
---------- C:\Windows\system32\cmd.exe
---------- C:\Rooter$\RK.exe

----------------------\\ Search..

----------------------\\ ROOTKIT !!



1 - "C:\Rooter$\Rooter_1.txt" - Sun 05/03/2009|19:35

----------------------\\ Scan completed at 19:35





OTListIt Extras logfile created on: 5/3/2009 7:38:06 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.3 Folder = C:\Users\medic\Desktop\geeks to go
Windows Vista Business Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 0.78 Gb Available Physical Memory | 38.78% Memory free
4.00 Gb Paging File | 2.67 Gb Available in Paging File | 66.71% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 7.72 Gb Free Space | 13.82% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: MEDICLAP
Current User Name: medic
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox3\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
Reg Error: Unknown registry data type File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-2869060807-562205752-250988619-1000]
"EnableNotifications" = 1
"EnableNotificationsRef" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
"DisableNotifications" = 0
"EnableFirewall" = 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"DisableNotifications" = 0
"EnableFirewall" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile
"DisableNotifications" = 0
"EnableFirewall" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\GloballyOpenPorts\List

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\AuthorizedApplications\List]

========== Vista Active Open Ports Exception List ==========

{06AB1BB8-E3AF-4388-8693-3448BA46C9A3} = LPORT=5721 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{0A42529F-5A74-4546-BE8E-EA0AC6E1F86E} = LPORT=990 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4001 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{11486F26-2AB7-4BF9-802F-F2268CADD5E5} = LPORT=990 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4001 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{121E19F9-4913-4833-8009-8DC32CA16FE1} = LPORT=5721 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{192BC44A-CC8B-4D42-B5FF-3F2D84EFC02F} = RPORT=5679 | PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4015 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{241C3ECB-7FEE-456C-965A-1CE40499DC2E} = LPORT=26675 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4006 |
{2773B150-9AE9-4121-8E8C-99B5D5C89ABF} = LPORT=26675 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4006 |
{28A54847-968D-4137-9A2A-671B480D0EC1} = LPORT=5721 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{2C44961C-C0FF-4DC5-9BEE-B2A02A418888} = LPORT=990 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4001 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{346A3207-1D74-40EE-A0C4-CF57D2EB385F} = LPORT=990 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4001 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{3AB56B6D-7729-4F27-B282-AB07E2BE4411} = LPORT=5678 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4004 | APP=%SYSTEMROOT%\WINDOWSMOBILE\WMDHOST.EXE |
{3B3F2709-F947-4D44-BDBC-5726B7EEEC37} = LPORT=999 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4005 | APP=%SYSTEMROOT%\WINDOWSMOBILE\WMDHOST.EXE |
{40D7BFD4-542A-4F6D-94A0-9A2C4E04D973} = LPORT=990 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4001 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{4288B0AB-9878-40DE-BAA2-91987AEE38E9} = RPORT=5679 | PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4015 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{4780F4DF-A3C1-4257-B8A6-28E9D787B504} = LPORT=990 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4001 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{5328A543-59A1-4A63-841B-2E78E41FFA08} = RPORT=5679 | PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4015 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{5429318D-B010-4FB4-8900-4A11159963C0} = LPORT=5721 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{551767C8-96C6-4442-845E-C22D09E78497} = LPORT=990 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4001 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{58C2C4A8-51C1-4314-8EB8-DCA16FBB499A} = RPORT=5679 | PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4015 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{5C8D0519-6252-43A1-9A8C-647B0E0DC89C} = LPORT=5721 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{67072E33-A659-46B1-8DEB-9B577C386960} = LPORT=3389 | PROFILE=DOMAIN | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | [email protected],-28753 | APP=SYSTEM |
{759BBDF9-2693-4331-902F-B75F591A39AA} = LPORT=999 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4005 | APP=%SYSTEMROOT%\WINDOWSMOBILE\WMDHOST.EXE |
{78B7E213-1C29-47C2-BAE2-79EEC886E9DD} = LPORT=990 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4001 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{7DA3F4E2-4133-44AB-8BA7-BECB4CFACE75} = LPORT=990 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4001 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{91F4FA59-A357-4FDD-B989-5F46A90DECDC} = LPORT=5678 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4004 | APP=%SYSTEMROOT%\WINDOWSMOBILE\WMDHOST.EXE |
{974359D3-6C9C-4C9D-9E5B-C6022E6854BD} = RPORT=5679 | PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4015 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{985B0C97-4083-44C2-9F4A-0E387FD2B621} = RPORT=5679 | PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4015 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{99B77499-3B71-49B6-ABE0-2C7CB3F1E198} = RPORT=5679 | PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4015 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{A928E309-645A-4134-98B9-BF0B7F47B47F} = RPORT=5679 | PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4015 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{AC32BD96-0C63-4B23-9342-B28AB760BEFD} = LPORT=5721 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{B9DDAAD9-301B-42AB-8BFE-264C982EEB52} = RPORT=5679 | PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4015 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{B9E2FF16-79AF-4126-A76C-5CA3E55C6112} = LPORT=5721 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{C2E9EB7F-A8BC-4F1B-BFAD-84EFB39AD534} = LPORT=5721 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{C5B9C3B7-0058-4BA3-BBDA-BD62B78B1BE6} = LPORT=5721 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{C9884480-6371-4963-B2C2-0EEEE125C344} = LPORT=990 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4001 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{EA845EE6-1C7A-47AE-BD35-BD3C703BE90A} = LPORT=5721 | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{EDD3628D-485A-4B7C-A09D-28C9B9DACC38} = RPORT=5679 | PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4015 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{FE8B8F29-9255-427A-A705-444D4C8B1AAC} = LPORT=6004 | PROFILE=PUBLIC | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=MICROSOFT OFFICE OUTLOOK | APP=C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\OUTLOOK.EXE |

========== Vista Active Application Exception List ==========

{016904C1-12BB-4DC3-BF5C-C14A84C085E5} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{01E5F4EB-736B-4275-AFAF-2410D0D61489} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{071DFED1-5B24-4357-B675-2131B39B6D0B} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{077BCB3D-944A-4028-8EE1-A7360FB97F6E} = DIR=IN | ACTION=ALLOW | NAME=SKYPE | APP=C:\PROGRAM FILES\SKYPE\PHONE\SKYPE.EXE |
{079E3560-D15C-4342-871B-35457DD90D8E} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{09226954-4A4E-47C6-9502-49D5FA7674E7} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{0A7D61FC-BE44-4B25-A510-0EF3B36C47C9} = PROFILE=PRIVATE | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=YAHOO! FT SERVER | APP=C:\PROGRAM FILES\YAHOO!\MESSENGER\YSERVER.EXE |
{1042B434-882C-49B4-A9C5-681B20683158} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{11FCD6D4-806E-4AE2-95AC-446B7DA1C519} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{12690B66-81D3-4F51-A2B6-25DFBB9DE30C} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{166F69BA-1C18-4445-9672-43E24A14284F} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{18868088-612F-4FC0-B1EB-032259668128} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{1FF50E2A-E63D-4231-8B88-7A04ED17DD90} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{265E5AF7-DFD7-4CEC-9618-0D81F96F38B0} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{2B217A8E-B341-422D-B049-50C640DFA351} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{31C73B8C-F7D1-475B-BB6C-6BEB068D9A1C} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{38507112-B163-4679-A04B-7FAEC7137D73} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{3A0E8C50-6A8A-468A-BE51-EB4D2F5E133E} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{3F48590D-39BA-40D1-BD05-49BD0EA440CE} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{40593D20-3031-4A2C-9444-5FEC488A5095} = PROFILE=PUBLIC | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=MICROSOFT OFFICE ONENOTE | APP=C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\ONENOTE.EXE |
{47F87594-B417-4D81-A334-F6FC24B7E359} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{49025AA9-A125-4496-AD1F-9BCE8B569A06} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{4BEFFBE8-F501-4D50-9E79-3B9E4E494833} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{4D9CA384-C5E4-4CC7-BDDC-443CF5343173} = PROFILE=PUBLIC | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=MICROSOFT OFFICE ONENOTE | APP=C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\ONENOTE.EXE |
{4E0FCE84-ABAA-435A-8774-DF9AD0D0B3E5} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{4F36356C-2BC6-4A59-9D68-F955F1510C12} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{4F737B34-7AAD-4DAF-9F0D-6ABB5307256A} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{4FD412F7-2768-4FF5-A6D5-8CD79D1A7356} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{502D4E93-1589-45C1-8C73-F63D42904442} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{5D7B64F1-A5C5-4937-8220-49D3F2C83577} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{60441285-9C7C-49FD-8162-3F694C97B637} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{68CD30EC-ED6F-4162-B764-0BFEBC885CEA} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{6EB4DC4A-9192-42A3-AEDF-EB33D330DB51} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{7B3E5771-3C71-43FA-8437-3FC3298A49E0} = PROFILE=PRIVATE | DIR=IN | ACTION=ALLOW | NAME=AVGUPD.EXE | APP=C:\PROGRAM FILES\AVG\AVG8\AVGUPD.EXE |
{83669094-4640-493D-B05E-44A1E903844E} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{85AED62B-A3CD-4C9B-9551-BEE1D5F67FF1} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{89B98DE4-21F3-4EFC-B0BD-C77EC7A1595A} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{8B78201C-9F83-4050-8679-9DD4C2EAAEEF} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{915B93CF-F75A-4B9F-A089-9983233B6306} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{958C0CEC-8A4F-495B-AEF8-BDAF7D2ADE0C} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{9680A8FB-0AC1-4AED-A716-4032F29C978D} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{9C9BE10A-3337-47C0-BD0D-7E5A6E921BD5} = PROFILE=PRIVATE | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=YAHOO! FT SERVER | APP=C:\PROGRAM FILES\YAHOO!\MESSENGER\YSERVER.EXE |
{9D1BC4AF-FA76-4A35-A975-C7D0B6C0C5DE} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{A4CF87A3-42E8-4738-8608-FEC6F3BF0BAE} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{A4DB0C65-CA36-4FDB-BC3F-3D9E75037A55} = DIR=IN | ACTION=ALLOW | NAME=WINDOWS LIVE SYNC | APP=C:\PROGRAM FILES\WINDOWS LIVE\SYNC\WINDOWSLIVESYNC.EXE |
{A5AD408E-20B0-46CF-B947-D5A4AB034248} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{A7443C83-58C6-427B-9B33-5114C542985B} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{AA96D2D2-1063-4586-A9E7-E2980F7E7BDE} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{AE8D2F47-3063-45D7-986B-2C7624F92017} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{B1B92B1D-F2DD-46F4-B47E-220D376D23AC} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{B9A53EC3-0DBE-4E31-A7B0-C68D3FB5D8FE} = PROFILE=PRIVATE | DIR=IN | ACTION=ALLOW | NAME=AVGEMC.EXE | APP=C:\PROGRAM FILES\AVG\AVG8\AVGEMC.EXE |
{C08FAC61-7EC6-4F5E-855B-61DCB4B89122} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{C2322431-F37C-465F-A0D2-FC85DBAC9358} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{C9E5A688-B09F-4C0C-BE28-4A939F5E8CBA} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{DD7BFF17-66CF-40CC-BE10-0B1B7BBA2B51} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{DE8934F5-BD5E-45D5-807E-EB08EC685214} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{E074A2F4-6678-4698-BDA3-A375FB91CF44} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{E0E153E2-4F94-4835-A481-5952DFBEBF73} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{E1A03B90-04B2-469E-B9F3-F2A00F866572} = PROFILE=PUBLIC | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=MICROSOFT OFFICE GROOVE | APP=C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\GROOVE.EXE |
{E91CE9AB-3045-4696-BA5A-A09FA38EF4E6} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{EC355143-7C07-410C-B619-5C12DBC6A80B} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{EE331DA6-B18D-415A-8986-3D8E8973F1A8} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{EEB6BC1A-488F-413C-8FD6-579232E479F3} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{F017A1EC-9DF6-4E56-8DAD-EA2D0A7D5C8C} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{F059C2DD-DF54-4CC9-A827-626748D9B263} = PROFILE=PRIVATE | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=YAHOO! MESSENGER | APP=C:\PROGRAM FILES\YAHOO!\MESSENGER\YAHOOMESSENGER.EXE |
{F6724FDB-255C-4B46-9AEC-C66CAF131CA8} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{FAC4EACF-3C7B-4373-B55D-34BBE6516803} = PROFILE=PUBLIC | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=MICROSOFT OFFICE GROOVE | APP=C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE12\GROOVE.EXE |
{FBB3C59B-B8A9-4108-9ED7-BA0B71C4A2DB} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{FD0D0C14-2A8C-4FF8-B7F5-910A3CBE767A} = PROTOCOL=17 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{FD13E1CB-0183-41EE-9547-1E8042A2189A} = PROTOCOL=6 | DIR=OUT | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4016 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=RAPIMGR |
{FDA903D5-095E-436A-9A4C-CE1012C170BC} = PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=@%SYSTEMROOT%\WINDOWSMOBILE\WMDCBASE.EXE,-4002 | APP=%SYSTEMROOT%\SYSTEM32\SVCHOST.EXE | SVC=WCESCOMM |
{FEEDEB9D-D696-4AA5-B7CD-3E9215A963D1} = PROFILE=PRIVATE | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=YAHOO! MESSENGER | APP=C:\PROGRAM FILES\YAHOO!\MESSENGER\YAHOOMESSENGER.EXE |
TCP Query User{4609A15F-93BF-47AF-BD64-E10A809CC7B9}C:\program files\mozilla firefox\firefox.exe = PROFILE=PRIVATE | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=FIREFOX | APP=C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE |
TCP Query User{84D22520-8C7E-4F8E-83F8-D51349B6E261}D:\autorun.exe = PROFILE=PRIVATE | PROTOCOL=6 | DIR=IN | ACTION=BLOCK | NAME=CD NAVIGATOR | APP=D:\AUTORUN.EXE |
TCP Query User{901D1097-D0FF-4093-B6D8-6B726255917E}C:\program files\internet explorer\iexplore.exe = PROFILE=PRIVATE | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=INTERNET EXPLORER | APP=C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE |
TCP Query User{D03A0B30-9D95-40D2-A940-646E9F138F2F}C:\users\medic\appdata\local\temp\temp1_sc101t_cd_initial_release.zip\sc101t_cd\autorun.exe = PROFILE=PRIVATE | PROTOCOL=6 | DIR=IN | ACTION=ALLOW | NAME=AUTORUN.EXE | APP=C:\USERS\MEDIC\APPDATA\LOCAL\TEMP\TEMP1_SC101T_CD_INITIAL_RELEASE.ZIP\SC101T_CD\AUTORUN.EXE |
UDP Query User{8E17E162-11CE-43FB-8C6B-60E379AD5DF4}C:\program files\internet explorer\iexplore.exe = PROFILE=PRIVATE | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=INTERNET EXPLORER | APP=C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE |
UDP Query User{AB1ED99A-4310-41DE-ACD5-F6D64AF79B09}C:\users\medic\appdata\local\temp\temp1_sc101t_cd_initial_release.zip\sc101t_cd\autorun.exe = PROFILE=PRIVATE | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=AUTORUN.EXE | APP=C:\USERS\MEDIC\APPDATA\LOCAL\TEMP\TEMP1_SC101T_CD_INITIAL_RELEASE.ZIP\SC101T_CD\AUTORUN.EXE |
UDP Query User{B5279983-DE23-44E8-9F81-7A691D3B3D68}D:\autorun.exe = PROFILE=PRIVATE | PROTOCOL=17 | DIR=IN | ACTION=BLOCK | NAME=CD NAVIGATOR | APP=D:\AUTORUN.EXE |
UDP Query User{D34DA981-E106-4D8E-91D6-A65C41F3A7F7}C:\program files\mozilla firefox\firefox.exe = PROFILE=PRIVATE | PROTOCOL=17 | DIR=IN | ACTION=ALLOW | NAME=FIREFOX | APP=C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{0837A661-FEC3-48B3-876C-91E7D32048A9}" = Macromedia Dreamweaver 8
"{10CE1EA2-12E9-11D3-825E-00C04F6843FE}" = Microsoft Office Sounds
"{1838C5A2-AB32-4145-85C1-BB9B8DFA24CD}" = QuickTime
"{1F8AE5F3-DCF7-1911-427B-E23AE9385FF8}" = ATI Catalyst Install Manager
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2BD5C305-1B27-4D41-B690-7A61172D2FEB}" = Macromedia Flash 8
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{353D20CC-719B-4A60-AD33-D03F88C10330}" = Microsoft Office Accounting PayPal Addin
"{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision
"{397FF711-8BD9-4388-ADFC-2A878B83F018}" = Cisco Network Assistant
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C52E7DA-C431-4239-B66B-1BF703D5B194}" = Windows Live Photo Gallery
"{46614A49-222A-48EF-87A9-BFD603E608E1}" = Microsoft Office Accounting Fixed Asset Manager
"{4C24A8C1-7CFA-4650-AF15-732F5BD7B46D}" = Macromedia Fireworks 8
"{506AFDAB-950B-4D3D-BF77-641B8AD34462}" = PrimeSuite Scanning Components 14.0
"{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}" = Macromedia Extension Manager
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8
"{5FA793A6-0071-42C1-9355-8F69A428C44F}" = Microsoft Office Accounting ADP Payroll Addin
"{619B8475-0F48-41B7-A370-5147F7092989}" = Virtual Earth 3D (Beta)
"{63DB9CCD-2B56-4217-9A3D-507AC78320CA}" = mWMI
"{64BBFDCB-D3C8-48c5-8FEB-73CC3502633B}" = Pantech Modem Link Software
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7279647E-8661-48DF-998E-E7DCC3E6955D}" = Microsoft Office Live Meeting 2005
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{768FE04E-FDEE-4EEC-AE7E-A25DF7E88591}" = PrimeSuite Client Components
"{7AB8B57B-5E54-49C1-98CC-86D4C1CC1949}" = OfficeSafe
"{81A34902-9D0B-4920-A25C-4CDC5D14B328}" = Jasc Paint Shop Pro 8
"{871DF2BE-41D2-4334-AC33-839AF16FC8FE}" = Cisco Systems VPN Client 5.0.02.0090
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}" = Macromedia Flash 8 Video Encoder
"{8C6BB412-D3A8-4AAE-A01B-35B681789D68}" = mHelp
"{8C711818-076E-475C-B95B-DF11CD9D8DBE}" = Microsoft Office Accounting Equifax Addin
"{8ECB8220-F422-4BEB-9596-97033C533702}" = QuickBooks Pro 2008
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_PRJPROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}_VISPROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_PRJPROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}_VISPROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_PRJPROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}_VISPROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0054-0409-0000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2007
"{90120000-0054-0409-0000-0000000FF1CE}_VISPROR_{519D9F45-CBF4-4E57-B419-11F196CCA8AE}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_PRJPROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}_VISPROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
"{90120000-00B4-0409-0000-0000000FF1CE}" = Microsoft Office Project MUI (English) 2007
"{90120000-00B4-0409-0000-0000000FF1CE}_PRJPROR_{27A9D316-D332-433B-8EB1-1D93EE49F26D}" = Microsoft Office Project 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_PRJPROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}_VISPROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{904CCF62-818D-4675-BC76-D37EB399F917}" = Windows Mobile Device Center
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-003B-0000-0000-0000000FF1CE}" = Microsoft Office Project Professional 2007
"{91120000-003B-0000-0000-0000000FF1CE}_PRJPROR_{9E73617F-2F38-4864-BD61-BB2DDFE43323}" = Microsoft Office Project 2007 Service Pack 2 (SP2)
"{91120000-0051-0000-0000-0000000FF1CE}" = Microsoft Office Visio Professional 2007
"{91120000-0051-0000-0000-0000000FF1CE}_VISPROR_{0FD405D3-CAF8-4CA6-8BFD-911D2F8A6585}" = Microsoft Office Visio 2007 Service Pack 2 (SP2)
"{939740B5-0064-4779-854A-8C1086181C05}" = Macromedia FreeHand MXa
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BBD1CB9-38CA-43EB-A67C-7631F804AED6}" = Microsoft Office Accounting 2007 SDK
"{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}" = mDriver
"{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}" = Windows Live Sync
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{B0717D5A-1976-482B-9ADF-F19631A541A4}" = Microsoft Office Accounting 2007
"{BC595C7E-899E-44C1-8B25-8763853FF20C}" = 3D Home Architect Design Suite Deluxe 6
"{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{CA9BAADB-C262-4E05-B2E2-CEE8CE9809EC}" = mToolkit
"{CB8CA439-DA83-419C-A4CF-5A0A50025144}" = Windows Mobile Device Center Driver Update
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1D4C9A3-060B-472A-88B7-B313CD622381}" = Windows Marketplace upgrade options tool
"{D6FD2A0F-E1FD-4795-A774-D42261F92FF1}" = NETGEAR Storage Central Manager Utility
"{DBF6F373-236E-49EE-9A07-0F67B4EAC8E8}" = SPMP3050 Transcoding Tool
"{EA516024-D84D-41F1-814F-83175A6188F2}" = Logitech Video Enumerator
"{EB9A4856-C28A-4BC2-9373-975A33BB9CD4}" = Live Search Maps Add-In for Microsoft Office Outlook
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F5D7FAB5-A1FD-4DD3-983E-4155B09D7102}" = mCore
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"ACBLscore" = ACBLscore
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Illustrator 9.0" = Adobe Illustrator 9.0
"Adobe SVG Viewer" = Adobe SVG Viewer
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"Android Newsgroup Downloader_is1" = Android Newsgroup Downloader v 6.1
"AVG8Uninstall" = AVG Free 8.0
"Bridge Squeezes Complete" = Bridge Squeezes Complete
"Bridge_Base_Online" = Bridge Base Online
"Carbonite Backup" = Carbonite
"CutePDF Writer Installation" = CutePDF Writer 2.7
"Dell Laser MFP 1600n" = Dell Laser MFP 1600n Software Uninstall
"ENTERPRISER" = Microsoft Office Enterprise 2007
"ERUNT_is1" = ERUNT 1.1j
"FoxyTunesForFirefox" = FoxyTunes for Firefox
"FTDICOMM" = USB Download Interface Driver
"GAP - Gas Absorption Program" = GAP - Gas Absorption Program
"GAP RGBM 2.3" = GAP RGBM 2.3
"IE7Pro_is1" = IE7Pro
"ieSpell" = ieSpell
"InstallShield_{BC595C7E-899E-44C1-8B25-8763853FF20C}" = 3D Home Architect Design Suite Deluxe 6
"IObit SmartDefrag Beta5.01_is1" = IObit SmartDefrag
"Jasc Paint Shop Pro 8.10 Update Patch" = Jasc Paint Shop Pro 8.10 Update Patch
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediLexicon Toolbar_is1" = MediLexicon Toolbar v.1.0
"MediLexiconMediLexicon" = MediLexicon - Toolbar
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Office Accounting 2007" = Microsoft Office Accounting 2007
"Microsoft Office Accounting Equifax Addin" = Microsoft Office Accounting Equifax Addin
"Microsoft Office Accounting PayPal Addin" = Microsoft Office Accounting PayPal Addin
"Mikogo" = Mikogo
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"Mozilla Thunderbird (2.0.0.21)" = Mozilla Thunderbird (2.0.0.21)
"NDCMedisoft Network Professional 10 SP2" = NDCMedisoft Network Professional 10 SP2
"PRJPROR" = Microsoft Office Project Professional 2007
"ProInst" = Intel® PROSet/Wireless Software
"RealPlayer 6.0" = RealPlayer
"ToolbarBrowser_is1" = ToolbarBrowser v2.4
"Trend Micro HouseCall 6.6" = HouseCall 6.6
"Trillian" = Trillian
"TurboMeeting" = TurboMeeting
"VISPROR" = Microsoft Office Visio Professional 2007
"V-Planner Mobile_is1" = V-Planner Mobile 3.27
"V-Planner_is1" = V-Planner 3.84
"VZAccess Manager" = VZAccess Manager
"WinLiveSuite_Wave3" = Windows Live Essentials
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ActiveTouchMeetingClient" = WebEx
"CrossFTP" = CrossFTP
"GoToMeeting" = GoToMeeting/GoToWebinar 3.0.0.198

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/24/2008 11:41:39 AM | Computer Name = mediclap | Source = Perflib | ID = 1008
Description =

Error - 3/24/2008 11:41:53 AM | Computer Name = mediclap | Source = usbperf | ID = 2004
Description = Usbperf data collection failed. Collect function called with usupported
Query Type.

Error - 3/24/2008 11:45:12 AM | Computer Name = mediclap | Source = usbperf | ID = 2004
Description = Usbperf data collection failed. Collect function called with usupported
Query Type.

Error - 3/24/2008 11:51:07 AM | Computer Name = mediclap | Source = usbperf | ID = 2004
Description = Usbperf data collection failed. Collect function called with usupported
Query Type.

Error - 3/24/2008 12:05:14 PM | Computer Name = mediclap | Source = usbperf | ID = 2004
Description = Usbperf data collection failed. Collect function called with usupported
Query Type.

Error - 3/24/2008 12:07:44 PM | Computer Name = mediclap | Source = usbperf | ID = 2004
Description = Usbperf data collection failed. Collect function called with usupported
Query Type.

Error - 3/24/2008 12:13:43 PM | Computer Name = mediclap | Source = usbperf | ID = 2004
Description = Usbperf data collection failed. Collect function called with usupported
Query Type.

Error - 3/28/2008 9:04:19 PM | Computer Name = mediclap | Source = VSS | ID = 12310
Description =

Error - 3/28/2008 9:04:19 PM | Computer Name = mediclap | Source = VSS | ID = 12298
Description =

Error - 3/29/2008 6:10:14 PM | Computer Name = mediclap | Source = VSS | ID = 12289
Description =

[ DFS Replication Events ]
Error - 4/2/2008 10:56:07 AM | Computer Name = mediclap | Source = DFSR | ID = 4004
Description = The DFS Replication service stopped replication on the replicated
folder at local path C:\Users\medic\AppData\Local\Microsoft\Windows\Temporary Internet
Files\FileShare\Windows Collaboration\{FCA5BF7B-D700-0150-8EF1-814794DF17CE}. Additional
Information: Error: 2 (The system cannot find the file specified.) Additional context
of the error: Replicated Folder Name: Windows Meeting Space Folders Replicated
Folder ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Replication Group Name: Windows Meeting
Space Group Replication Group ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Member ID:
52366055-8A0A-7C63-5560-36520A8A637C

Error - 4/2/2008 11:20:07 AM | Computer Name = mediclap | Source = DFSR | ID = 4004
Description = The DFS Replication service stopped replication on the replicated
folder at local path C:\Users\medic\AppData\Local\Microsoft\Windows\Temporary Internet
Files\FileShare\Windows Collaboration\{FCA5BF7B-D700-0150-8EF1-814794DF17CE}. Additional
Information: Error: 2 (The system cannot find the file specified.) Additional context
of the error: Replicated Folder Name: Windows Meeting Space Folders Replicated
Folder ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Replication Group Name: Windows Meeting
Space Group Replication Group ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Member ID:
52366055-8A0A-7C63-5560-36520A8A637C

Error - 4/2/2008 12:52:07 PM | Computer Name = mediclap | Source = DFSR | ID = 4004
Description = The DFS Replication service stopped replication on the replicated
folder at local path C:\Users\medic\AppData\Local\Microsoft\Windows\Temporary Internet
Files\FileShare\Windows Collaboration\{FCA5BF7B-D700-0150-8EF1-814794DF17CE}. Additional
Information: Error: 2 (The system cannot find the file specified.) Additional context
of the error: Replicated Folder Name: Windows Meeting Space Folders Replicated
Folder ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Replication Group Name: Windows Meeting
Space Group Replication Group ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Member ID:
52366055-8A0A-7C63-5560-36520A8A637C

Error - 4/2/2008 1:56:03 PM | Computer Name = mediclap | Source = DFSR | ID = 4004
Description = The DFS Replication service stopped replication on the replicated
folder at local path C:\Users\medic\AppData\Local\Microsoft\Windows\Temporary Internet
Files\FileShare\Windows Collaboration\{FCA5BF7B-D700-0150-8EF1-814794DF17CE}. Additional
Information: Error: 2 (The system cannot find the file specified.) Additional context
of the error: Replicated Folder Name: Windows Meeting Space Folders Replicated
Folder ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Replication Group Name: Windows Meeting
Space Group Replication Group ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Member ID:
52366055-8A0A-7C63-5560-36520A8A637C

Error - 4/2/2008 2:03:03 PM | Computer Name = mediclap | Source = DFSR | ID = 4004
Description = The DFS Replication service stopped replication on the replicated
folder at local path C:\Users\medic\AppData\Local\Microsoft\Windows\Temporary Internet
Files\FileShare\Windows Collaboration\{FCA5BF7B-D700-0150-8EF1-814794DF17CE}. Additional
Information: Error: 2 (The system cannot find the file specified.) Additional context
of the error: Replicated Folder Name: Windows Meeting Space Folders Replicated
Folder ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Replication Group Name: Windows Meeting
Space Group Replication Group ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Member ID:
52366055-8A0A-7C63-5560-36520A8A637C

Error - 4/2/2008 2:27:03 PM | Computer Name = mediclap | Source = DFSR | ID = 4004
Description = The DFS Replication service stopped replication on the replicated
folder at local path C:\Users\medic\AppData\Local\Microsoft\Windows\Temporary Internet
Files\FileShare\Windows Collaboration\{FCA5BF7B-D700-0150-8EF1-814794DF17CE}. Additional
Information: Error: 2 (The system cannot find the file specified.) Additional context
of the error: Replicated Folder Name: Windows Meeting Space Folders Replicated
Folder ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Replication Group Name: Windows Meeting
Space Group Replication Group ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Member ID:
52366055-8A0A-7C63-5560-36520A8A637C

Error - 4/2/2008 3:59:03 PM | Computer Name = mediclap | Source = DFSR | ID = 4004
Description = The DFS Replication service stopped replication on the replicated
folder at local path C:\Users\medic\AppData\Local\Microsoft\Windows\Temporary Internet
Files\FileShare\Windows Collaboration\{FCA5BF7B-D700-0150-8EF1-814794DF17CE}. Additional
Information: Error: 2 (The system cannot find the file specified.) Additional context
of the error: Replicated Folder Name: Windows Meeting Space Folders Replicated
Folder ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Replication Group Name: Windows Meeting
Space Group Replication Group ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Member ID:
52366055-8A0A-7C63-5560-36520A8A637C

Error - 4/2/2008 8:10:39 PM | Computer Name = mediclap | Source = DFSR | ID = 4004
Description = The DFS Replication service stopped replication on the replicated
folder at local path C:\Users\medic\AppData\Local\Microsoft\Windows\Temporary Internet
Files\FileShare\Windows Collaboration\{FCA5BF7B-D700-0150-8EF1-814794DF17CE}. Additional
Information: Error: 2 (The system cannot find the file specified.) Additional context
of the error: Replicated Folder Name: Windows Meeting Space Folders Replicated
Folder ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Replication Group Name: Windows Meeting
Space Group Replication Group ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Member ID:
52366055-8A0A-7C63-5560-36520A8A637C

Error - 4/2/2008 11:31:01 PM | Computer Name = mediclap | Source = DFSR | ID = 4004
Description = The DFS Replication service stopped replication on the replicated
folder at local path C:\Users\medic\AppData\Local\Microsoft\Windows\Temporary Internet
Files\FileShare\Windows Collaboration\{FCA5BF7B-D700-0150-8EF1-814794DF17CE}. Additional
Information: Error: 2 (The system cannot find the file specified.) Additional context
of the error: Replicated Folder Name: Windows Meeting Space Folders Replicated
Folder ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Replication Group Name: Windows Meeting
Space Group Replication Group ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Member ID:
52366055-8A0A-7C63-5560-36520A8A637C

Error - 4/2/2008 11:38:01 PM | Computer Name = mediclap | Source = DFSR | ID = 4004
Description = The DFS Replication service stopped replication on the replicated
folder at local path C:\Users\medic\AppData\Local\Microsoft\Windows\Temporary Internet
Files\FileShare\Windows Collaboration\{FCA5BF7B-D700-0150-8EF1-814794DF17CE}. Additional
Information: Error: 2 (The system cannot find the file specified.) Additional context
of the error: Replicated Folder Name: Windows Meeting Space Folders Replicated
Folder ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Replication Group Name: Windows Meeting
Space Group Replication Group ID: 78DFE459-D8F0-44C3-B8FF-2FA9D369EAC4 Member ID:
52366055-8A0A-7C63-5560-36520A8A637C

[ OSession Events ]
Error - 11/8/2007 2:52:35 PM | Computer Name = mediclap | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 11464
seconds with 120 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 4/28/2009 11:34:49 PM | Computer Name = mediclap | Source = BTHUSB | ID = 327696
Description = The mutual authentication between the local Bluetooth adapter and
a device with Bluetooth adapter address (00:23:d6:a8:e1:c6) failed.

Error - 4/28/2009 11:35:19 PM | Computer Name = mediclap | Source = BTHUSB | ID = 327696
Description = The mutual authentication between the local Bluetooth adapter and
a device with Bluetooth adapter address (00:23:d6:a8:e1:c6) failed.

Error - 4/29/2009 3:58:54 PM | Computer Name = mediclap | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description =

Error - 4/29/2009 8:35:49 PM | Computer Name = mediclap | Source = EventLog | ID = 6008
Description = The previous system shutdown at 7:16:50 PM on 4/29/2009 was unexpected.

Error - 4/29/2009 8:33:28 PM | Computer Name = mediclap | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 4/29/2009 8:33:28 PM | Computer Name = mediclap | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description =

Error - 4/29/2009 8:33:30 PM | Computer Name = mediclap | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 1
Description =

Error - 4/29/2009 8:33:40 PM | Computer Name = mediclap | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 4/29/2009 8:35:54 PM | Computer Name = mediclap | Source = HTTP | ID = 15016
Description =

Error - 4/29/2009 8:37:11 PM | Computer Name = mediclap | Source = Service Control Manager | ID = 7000
Description =


< End of report >
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP