/
__Example_Output.txt
5794 lines (4951 loc) · 366 KB
/
__Example_Output.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
SYSTEM INFORMATION
====================================================
ComputerName = BIFROST
TCP/IP Hostname = Bifrost
ShutdownTime = Wed Oct 23 02:56:04 2013 (UTC)
Microsoft\Windows NT\CurrentVersion
RegisteredOrganization :
CurrentVersion : 6.3
CurrentBuild : 9600
CurrentBuildNumber : 9600
SystemRoot : C:\WINDOWS
ProductName : Windows 8.1 Pro
InstallDate : Mon Sep 23 19:47:15 2013 (UTC)
RegisteredOwner : dblake@asgard-venture-capital.com
====================================================
TIMEZONE INFORMATION
====================================================
DaylightName -> @tzres.dll,-111
StandardName -> @tzres.dll,-112
Bias -> 300 (5 hours)
ActiveTimeBias -> 240 (4 hours)
TimeZoneKeyName-> Eastern Standard Time
====================================================
NETWORKING INFORMATION
====================================================
=-=-=-=-=-=-=-=-=-=-=-=-=-=
IP SETTINGS
=-=-=-=-=-=-=-=-=-=-=-=-=-=
Adapter: {0BC34999-4F58-4304-A651-86E870A12EA4}
LastWrite Time: Mon Sep 23 19:21:39 2013 Z
EnableDHCP 1
NameServer
Domain
RegistrationEnabled 1
RegisterAdapterName 0
UseZeroBroadcast 0
EnableDeadGWDetect 1
ControlSet001\Services\Tcpip\Parameters\Interfaces has no subkeys.
Adapter: {46a0fb48-2484-11e3-824c-806e6f6e6963}
LastWrite Time: Mon Sep 23 20:07:54 2013 Z
ControlSet001\Services\Tcpip\Parameters\Interfaces has no subkeys.
Adapter: {5185491C-401D-491E-8C6F-07F6AFFF1A64}
LastWrite Time: Wed Oct 23 02:56:23 2013 Z
UseZeroBroadcast 0
EnableDeadGWDetect 1
EnableDHCP 1
NameServer
Domain
RegistrationEnabled 1
RegisterAdapterName 0
MTU 0
DhcpIPAddress 192.168.1.49
DhcpSubnetMask 255.255.255.0
DhcpServer 192.168.1.1
Lease 86400
LeaseObtainedTime Wed Oct 23 02:56:23 2013 Z
T1 Wed Oct 23 14:56:23 2013 Z
T2 Wed Oct 23 23:56:23 2013 Z
LeaseTerminatesTime Thu Oct 24 02:56:23 2013 Z
AddressType 0
IsServerNapAware 0
DhcpConnForceBroadcastFlag 0
DhcpNetworkHint talonne3
DhcpNameServer 192.168.1.1
DhcpDefaultGateway 192.168.1.1
DhcpDomain talonne
DhcpSubnetMaskOpt 255.255.255.0
DhcpInterfaceOptions
DhcpGatewayHardware
DhcpGatewayHardwareCount 1
Adapter: {5185491C-401D-491E-8C6F-07F6AFFF1A64}/051627B6F54516675627E6F57457563747
SSID Decoded: Park_Tavern_Guest
LastWrite Time: Mon Sep 23 19:18:06 2013 Z
EnableDHCP 1
UseZeroBroadcast 0
Adapter: {5185491C-401D-491E-8C6F-07F6AFFF1A64}/072776E2165627F6D266275656
SSID Decoded: prg.aero-free
LastWrite Time: Mon Oct 14 06:26:06 2013 Z
UseZeroBroadcast 0
EnableDeadGWDetect 1
EnableDHCP 1
NameServer
Domain
RegistrationEnabled 1
RegisterAdapterName 0
MTU 0
DhcpIPAddress 10.17.14.218
DhcpSubnetMask 255.255.0.0
DhcpServer 10.17.0.7
Lease 900
LeaseObtainedTime Mon Oct 14 06:24:08 2013 Z
T1 Mon Oct 14 06:31:38 2013 Z
T2 Mon Oct 14 06:37:15 2013 Z
LeaseTerminatesTime Mon Oct 14 06:39:08 2013 Z
AddressType 0
IsServerNapAware 0
DhcpConnForceBroadcastFlag 0
DhcpNetworkHint prg.aero-free
DhcpInterfaceOptions
5 Œ‘[R
DhcpNameServer 193.86.243.66 193.86.243.68
DhcpDefaultGateway 10.17.0.1
DhcpDomain prg.aero
DhcpSubnetMaskOpt 255.255.0.0
DhcpGatewayHardware
,kõjF
DhcpGatewayHardwareCount 1
Adapter: {5185491C-401D-491E-8C6F-07F6AFFF1A64}/143574142544
SSID Decoded: ASGARD
LastWrite Time: Mon Sep 23 19:18:06 2013 Z
EnableDHCP 1
UseZeroBroadcast 0
Adapter: {5185491C-401D-491E-8C6F-07F6AFFF1A64}/25F616D696E67674E6F6D656
SSID Decoded: RoamingGnome
LastWrite Time: Mon Sep 23 19:18:06 2013 Z
EnableDHCP 1
UseZeroBroadcast 0
Adapter: {5185491C-401D-491E-8C6F-07F6AFFF1A64}/3516D61627B616E646
SSID Decoded: Samarkand
LastWrite Time: Tue Oct 1 14:18:29 2013 Z
UseZeroBroadcast 0
EnableDeadGWDetect 1
EnableDHCP 1
NameServer
Domain
RegistrationEnabled 1
RegisterAdapterName 0
MTU 0
DhcpIPAddress 192.168.1.10
DhcpSubnetMask 255.255.255.0
DhcpServer 192.168.1.1
Lease 86400
LeaseObtainedTime Tue Oct 1 14:18:23 2013 Z
T1 Wed Oct 2 02:18:23 2013 Z
T2 Wed Oct 2 11:18:23 2013 Z
LeaseTerminatesTime Wed Oct 2 14:18:23 2013 Z
AddressType 0
IsServerNapAware 0
DhcpConnForceBroadcastFlag 0
DhcpNetworkHint Samarkand
DhcpInterfaceOptions
DhcpNameServer 192.168.1.1
DhcpDefaultGateway 192.168.1.1
DhcpDomain home
DhcpSubnetMaskOpt 255.255.255.0
DhcpGatewayHardware À¨ &bK^²
DhcpGatewayHardwareCount 1
Adapter: {5185491C-401D-491E-8C6F-07F6AFFF1A64}/361686D27657563747
SSID Decoded: cah-guest
LastWrite Time: Mon Oct 14 06:26:26 2013 Z
UseZeroBroadcast 0
EnableDeadGWDetect 1
EnableDHCP 1
NameServer
Domain
RegistrationEnabled 1
RegisterAdapterName 0
MTU 0
DhcpIPAddress 10.100.65.74
DhcpSubnetMask 255.255.255.0
DhcpServer 10.100.65.3
Lease 900
LeaseObtainedTime Mon Oct 14 06:26:12 2013 Z
T1 Mon Oct 14 06:33:42 2013 Z
T2 Mon Oct 14 06:39:19 2013 Z
LeaseTerminatesTime Mon Oct 14 06:41:12 2013 Z
AddressType 0
IsServerNapAware 0
DhcpConnForceBroadcastFlag 0
DhcpNetworkHint cah-guest
DhcpInterfaceOptions
dA5 ’[R „Ž[R
DhcpNameServer 193.86.243.66 193.86.243.68
DhcpDefaultGateway 10.100.65.1
DhcpDomain prg.aero
DhcpSubnetMaskOpt 255.255.255.0
DhcpGatewayHardware
dA Ûÿ p
DhcpGatewayHardwareCount 1
Adapter: {5185491C-401D-491E-8C6F-07F6AFFF1A64}/449637472796364702451636F6
SSID Decoded: District Taco
LastWrite Time: Thu Sep 26 18:15:57 2013 Z
UseZeroBroadcast 0
EnableDeadGWDetect 1
EnableDHCP 1
NameServer
Domain
RegistrationEnabled 1
RegisterAdapterName 0
MTU 0
DhcpIPAddress 192.168.1.102
DhcpSubnetMask 255.255.255.0
DhcpServer 192.168.1.1
Lease 86400
LeaseObtainedTime Thu Sep 26 17:51:05 2013 Z
T1 Fri Sep 27 05:51:05 2013 Z
T2 Fri Sep 27 14:51:05 2013 Z
LeaseTerminatesTime Fri Sep 27 17:51:05 2013 Z
AddressType 0
IsServerNapAware 0
DhcpConnForceBroadcastFlag 0
DhcpNetworkHint District Taco
DhcpInterfaceOptions
DhcpDefaultGateway 192.168.1.1
DhcpNameServer 192.168.1.1
DhcpSubnetMaskOpt 255.255.255.0
DhcpGatewayHardware À¨ ªKow
DhcpGatewayHardwareCount 1
Adapter: {5185491C-401D-491E-8C6F-07F6AFFF1A64}/87072756373736162756F57457563747
SSID Decoded: xpresscare_Guest
LastWrite Time: Mon Sep 23 19:18:06 2013 Z
EnableDHCP 1
UseZeroBroadcast 0
Adapter: {5185491C-401D-491E-8C6F-07F6AFFF1A64}/A596F6E6
SSID Decoded: Zion
LastWrite Time: Mon Sep 23 19:18:06 2013 Z
EnableDHCP 1
UseZeroBroadcast 0
Adapter: {5185491C-401D-491E-8C6F-07F6AFFF1A64}/C4F4453383
SSID Decoded: LOT38
LastWrite Time: Mon Oct 21 19:34:41 2013 Z
UseZeroBroadcast 0
EnableDeadGWDetect 1
EnableDHCP 1
NameServer
Domain
RegistrationEnabled 1
RegisterAdapterName 0
MTU 0
DhcpIPAddress 192.168.182.95
DhcpSubnetMask 255.255.255.0
DhcpServer 192.168.182.1
Lease 600
LeaseObtainedTime Mon Oct 21 19:24:46 2013 Z
T1 Mon Oct 21 19:29:46 2013 Z
T2 Mon Oct 21 19:33:31 2013 Z
LeaseTerminatesTime Mon Oct 21 19:34:46 2013 Z
AddressType 0
IsServerNapAware 0
DhcpConnForceBroadcastFlag 0
DhcpNetworkHint LOT38
DhcpInterfaceOptions
ÖÂeRÀ¨¶ ÖÂeRÿÿÿ 5 ÖÂeR
DhcpDomain key.chillispot.info
DhcpNameServer 10.1.10.1 10.1.10.1
DhcpDefaultGateway 192.168.182.1
DhcpSubnetMaskOpt 255.255.255.0
DhcpGatewayHardware À¨¶ ht)ëZ
DhcpGatewayHardwareCount 1
Adapter: {5185491C-401D-491E-8C6F-07F6AFFF1A64}/D4363416272716E60275966496
SSID Decoded: McCarran WiFi
LastWrite Time: Mon Sep 23 19:18:06 2013 Z
EnableDHCP 1
UseZeroBroadcast 0
Adapter: {54747FBB-D5C2-487A-A854-CE0D71AB02B0}
LastWrite Time: Mon Sep 23 19:20:55 2013 Z
UseZeroBroadcast 0
EnableDeadGWDetect 1
EnableDHCP 1
NameServer
Domain
RegistrationEnabled 1
RegisterAdapterName 0
MTU 0
ControlSet001\Services\Tcpip\Parameters\Interfaces has no subkeys.
Adapter: {8718928D-CBEB-45EA-A621-800A9249001D}
LastWrite Time: Thu Aug 22 14:46:19 2013 Z
UseZeroBroadcast 0
EnableDeadGWDetect 1
EnableDHCP 1
NameServer
Domain
RegistrationEnabled 1
RegisterAdapterName 0
ControlSet001\Services\Tcpip\Parameters\Interfaces has no subkeys.
=-=-=-=-=-=-=-=-=-=-=-=-=-=
NETWORK LIST
=-=-=-=-=-=-=-=-=-=-=-=-=-=
Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles
attwifi
Key LastWrite : Mon Sep 23 19:18:06 2013 Z
DateLastConnected: Thu Sep 5 22:37:08 2013
DateCreated : Thu Sep 5 22:37:08 2013
DefaultGatewayMac: 00-90-FB-43-A3-88
Type : wireless
Zion
Key LastWrite : Mon Sep 23 19:18:06 2013 Z
DateLastConnected: Fri Sep 13 11:23:24 2013
DateCreated : Thu Sep 12 16:28:54 2013
DefaultGatewayMac: 00-18-0A-22-2B-0C
Type : wireless
LOT38
Key LastWrite : Mon Oct 21 18:19:12 2013 Z
DateLastConnected: Mon Oct 21 14:19:12 2013
DateCreated : Mon Oct 21 14:19:12 2013
DefaultGatewayMac: 68-7F-74-29-EB-5A
Type : wireless
Cox-CaesarsLV-Rooms
Key LastWrite : Mon Sep 23 19:18:06 2013 Z
DateLastConnected: Thu Sep 12 02:45:19 2013
DateCreated : Thu Sep 12 02:45:19 2013
DefaultGatewayMac: 00-1B-24-E0-29-55
Type : wireless
gogoinflight
Key LastWrite : Thu Oct 3 11:49:48 2013 Z
DateLastConnected: Thu Oct 3 07:49:48 2013
DateCreated : Thu Oct 3 07:48:58 2013
DefaultGatewayMac: 00-E0-4B-22-96-D9
Type : wireless
CaesarsLV-Convention-Cox
Key LastWrite : Mon Sep 23 19:18:06 2013 Z
DateLastConnected: Sat Sep 21 18:08:28 2013
DateCreated : Sat Sep 21 13:01:29 2013
DefaultGatewayMac: 00-16-36-CA-17-6A
Type : wireless
Park_Tavern_Guest
Key LastWrite : Mon Sep 23 19:18:06 2013 Z
DateLastConnected: Fri Sep 6 11:40:45 2013
DateCreated : Fri Sep 6 11:40:45 2013
DefaultGatewayMac: 80-1F-02-79-35-C8
Type : wireless
attwifi 2
Key LastWrite : Mon Sep 23 19:18:06 2013 Z
DateLastConnected: Wed Sep 11 19:30:34 2013
DateCreated : Wed Sep 11 19:30:34 2013
DefaultGatewayMac: 00-90-FB-47-79-AA
Type : wireless
McCormickSchmicks
Key LastWrite : Mon Sep 23 19:18:06 2013 Z
DateLastConnected: Thu Sep 5 22:36:06 2013
DateCreated : Thu Sep 5 22:36:06 2013
DefaultGatewayMac: 00-90-FB-43-A3-88
Type : wireless
Baileys Guest
Key LastWrite : Mon Sep 23 19:18:06 2013 Z
DateLastConnected: Thu Sep 5 22:42:13 2013
DateCreated : Thu Sep 5 21:25:34 2013
DefaultGatewayMac: A0-F3-C1-FF-00-0A
Type : wireless
talonne3
Key LastWrite : Wed Oct 23 02:56:23 2013 Z
DateLastConnected: Tue Oct 22 22:56:23 2013
DateCreated : Fri Aug 30 23:45:28 2013
DefaultGatewayMac: 00-7F-28-CF-44-DB
Type : wireless
angelo
Key LastWrite : Sun Oct 13 10:23:59 2013 Z
DateLastConnected: Sun Oct 13 06:23:59 2013
DateCreated : Sat Oct 5 11:06:30 2013
DefaultGatewayMac: 00-0C-42-9B-8F-39
Type : wireless
RoamingGnome
Key LastWrite : Mon Sep 23 19:18:06 2013 Z
DateLastConnected: Fri Sep 20 19:58:23 2013
DateCreated : Thu Sep 19 19:05:13 2013
DefaultGatewayMac: A6-C3-61-E9-08-00
Type : wireless
prg.aero-free
Key LastWrite : Mon Oct 14 06:24:12 2013 Z
DateLastConnected: Mon Oct 14 02:24:12 2013
DateCreated : Mon Oct 14 02:24:12 2013
DefaultGatewayMac: 2C-6B-F5-1C-6A-46
Type : wireless
McCarran WiFi
Key LastWrite : Mon Sep 23 19:18:06 2013 Z
DateLastConnected: Thu Sep 12 01:51:58 2013
DateCreated : Thu Sep 12 01:51:58 2013
DefaultGatewayMac: 00-00-5E-00-01-65
Type : wireless
Cox-CaesarsLV-Rooms 2
Key LastWrite : Mon Sep 23 19:18:06 2013 Z
DateLastConnected: Thu Sep 12 11:20:07 2013
DateCreated : Thu Sep 12 11:20:07 2013
DefaultGatewayMac: 00-16-36-CA-17-6A
Type : wireless
GCOMM
Key LastWrite : Mon Oct 14 07:17:57 2013 Z
DateLastConnected: Mon Oct 14 03:17:57 2013
DateCreated : Mon Oct 14 02:26:35 2013
DefaultGatewayMac: D4-CA-6D-80-C4-B3
Type : wireless
ASGARD
Key LastWrite : Mon Sep 23 19:18:06 2013 Z
DateLastConnected: Mon Sep 23 11:44:58 2013
DateCreated : Fri Aug 30 12:55:56 2013
DefaultGatewayMac: 00-15-FF-03-67-E5
Type : wireless
cah-guest
Key LastWrite : Mon Oct 14 06:26:13 2013 Z
DateLastConnected: Mon Oct 14 02:26:13 2013
DateCreated : Mon Oct 14 02:26:13 2013
DefaultGatewayMac: 00-10-DB-FF-20-70
Type : wireless
hhonors
Key LastWrite : Mon Sep 23 19:18:06 2013 Z
DateLastConnected: Sat Aug 10 14:46:39 2013
DateCreated : Sat Aug 10 14:46:39 2013
DefaultGatewayMac: 00-90-FB-32-8D-D8
Type : wireless
xpresscare_Guest
Key LastWrite : Mon Sep 23 19:18:06 2013 Z
DateLastConnected: Mon Sep 23 11:46:58 2013
DateCreated : Mon Sep 23 11:46:58 2013
DefaultGatewayMac: 98-FC-11-5C-63-C4
Type : wireless
Zion 2
Key LastWrite : Mon Sep 23 19:18:06 2013 Z
DateLastConnected: Thu Sep 19 16:14:39 2013
DateCreated : Thu Sep 19 15:53:02 2013
DefaultGatewayMac: 00-18-0A-35-B2-B4
Type : wireless
Washington Dulles WiFi
Key LastWrite : Mon Sep 23 19:18:06 2013 Z
DateLastConnected: Wed Sep 11 19:31:17 2013
DateCreated : Wed Sep 11 19:31:17 2013
DefaultGatewayMac: 00-00-5E-00-01-3C
Type : wireless
Samarkand
Key LastWrite : Tue Oct 1 14:15:25 2013 Z
DateLastConnected: Tue Oct 1 10:15:25 2013
DateCreated : Sun Sep 29 14:33:06 2013
DefaultGatewayMac: 00-26-62-4B-5E-B2
Type : wireless
tmobile
Key LastWrite : Sat Oct 5 07:13:06 2013 Z
DateLastConnected: Sat Oct 5 03:13:06 2013
DateCreated : Sat Oct 5 03:13:06 2013
DefaultGatewayMac: 00-00-0C-07-AC-35
Type : wireless
District Taco
Key LastWrite : Thu Sep 26 17:51:05 2013 Z
DateLastConnected: Thu Sep 26 13:51:05 2013
DateCreated : Tue Sep 10 13:41:03 2013
DefaultGatewayMac: 20-AA-4B-6F-77-09
Type : wireless
Nacho
Key LastWrite : Mon Sep 23 19:18:06 2013 Z
DateLastConnected: Sun Aug 11 23:08:16 2013
DateCreated : Sat Aug 10 11:01:16 2013
DefaultGatewayMac: 00-23-69-58-11-1D
Type : wireless
Date Domain/IP
Mon Sep 23 19:18:06 2013 Z 150.202.1.3
Mon Sep 23 19:18:06 2013 Z coxhn.net
Mon Sep 23 19:18:06 2013 Z fhrg.com
Mon Oct 14 07:17:52 2013 Z gcomm.cz
Mon Sep 23 19:18:06 2013 Z hil-bosbhhh.bos.wayport.net
Tue Oct 1 14:18:29 2013 Z home
Mon Sep 23 19:18:06 2013 Z hsd1.ma.comcast.net.
Mon Oct 21 18:19:12 2013 Z key.chillispot.info
Mon Sep 23 19:18:06 2013 Z landrysmscc.dca.wayport.net
Mon Sep 23 19:18:06 2013 Z mccarranwifi.com
Mon Oct 14 06:26:26 2013 Z prg.aero
Tue Oct 1 14:16:49 2013 Z talonne
Mon Sep 23 19:18:06 2013 Z washiad2.dulleva.wayport.net
====================================================
FIREWALL DETAILS
====================================================
Windows Firewall Configuration
ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
LastWrite Time Mon Sep 23 19:14:08 2013 (UTC)
EnableFirewall -> 1
DisableNotifications -> 0
Windows Firewall Configuration
ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
LastWrite Time Mon Sep 23 19:14:08 2013 (UTC)
EnableFirewall -> 1
DisableNotifications -> 0
====================================================
PERSISTENT ROUTES
====================================================
routes v.20100817
(System) Get persistent routes
Select not found.
====================================================
LOCAL USER AND GROUP INFORMATION
====================================================
User Information
-------------------------
Username : Administrator [500]
Full Name :
User Comment : Built-in account for administering the computer/domain
Account Type : Default Admin User
Account Created : Mon Sep 23 19:24:36 2013 Z
Name :
Last Login Date : Sun Jun 2 03:57:44 2013 Z
Pwd Reset Date : Thu Jul 26 07:27:03 2012 Z
Pwd Fail Date : Never
Login Count : 13
--> Password does not expire
--> Account Disabled
--> Normal user account
Username : Guest [501]
Full Name :
User Comment : Built-in account for guest access to the computer/domain
Account Type : Default Guest Acct
Account Created : Mon Sep 23 19:24:36 2013 Z
Name :
Last Login Date : Never
Pwd Reset Date : Never
Pwd Fail Date : Never
Login Count : 0
--> Password does not expire
--> Account Disabled
--> Password not required
--> Normal user account
Username : Donald [1001]
Full Name : Donald Blake
User Comment :
Account Type : Default Admin User
Account Created : Sat Aug 10 03:03:12 2013 Z
Name : Donald Blake
InternetName : dblake@asgard-venture-capital.com
Last Login Date : Tue Oct 22 16:38:07 2013 Z
Pwd Reset Date : Sat Aug 10 03:03:23 2013 Z
Pwd Fail Date : Never
Login Count : 0
--> Password does not expire
--> Normal user account
Username : HomeGroupUser$ [1003]
Full Name : HomeGroupUser$
User Comment : Built-in account for homegroup access to the computer
Account Type : Custom Limited Acct
Account Created : Tue Oct 1 18:51:20 2013 Z
Name :
Last Login Date : Tue Oct 22 09:05:46 2013 Z
Pwd Reset Date : Tue Oct 1 18:51:20 2013 Z
Pwd Fail Date : Never
Login Count : 0
--> Password does not expire
--> Normal user account
-------------------------
Group Membership Information
-------------------------
Group Name : Event Log Readers [0]
LastWrite : Thu Jul 26 07:19:51 2012 Z
Group Comment : Members of this group can read event logs from local machine
Users : None
Group Name : Guests [1]
LastWrite : Sun Jun 2 03:18:03 2013 Z
Group Comment : Guests have the same access as members of the Users group by default, except for the Guest account which is further restricted
Users :
S-1-5-21-718126207-1171771683-1750804747-501
Group Name : Network Configuration Operators [0]
LastWrite : Mon Aug 12 03:08:08 2013 Z
Group Comment : Members in this group can have some administrative privileges to manage configuration of networking features
Users : None
Group Name : Performance Log Users [0]
LastWrite : Thu Jul 26 07:19:51 2012 Z
Group Comment : Members of this group may schedule logging of performance counters, enable trace providers, and collect event traces both locally and via remote access to this computer
Users : None
Group Name : Hyper-V Administrators [0]
LastWrite : Mon Aug 12 03:08:08 2013 Z
Group Comment : Members of this group have complete and unrestricted access to all features of Hyper-V.
Users : None
Group Name : IIS_IUSRS [1]
LastWrite : Thu Jul 26 07:19:51 2012 Z
Group Comment : Built-in group used by Internet Information Services.
Users :
S-1-5-17
Group Name : Backup Operators [0]
LastWrite : Mon Aug 12 03:08:08 2013 Z
Group Comment : Backup Operators can override security restrictions for the sole purpose of backing up or restoring files
Users : None
Group Name : Users [2]
LastWrite : Sat Aug 10 03:03:27 2013 Z
Group Comment : Users are prevented from making accidental or intentional system-wide changes and can run most applications
Users :
S-1-5-4
S-1-5-11
Group Name : Access Control Assistance Operators [0]
LastWrite : Mon Aug 12 03:08:08 2013 Z
Group Comment : Members of this group can remotely query authorization attributes and permissions for resources on this computer.
Users : None
Group Name : Distributed COM Users [0]
LastWrite : Thu Jul 26 07:19:51 2012 Z
Group Comment : Members are allowed to launch, activate and use Distributed COM objects on this machine.
Users : None
Group Name : Administrators [2]
LastWrite : Sat Aug 10 03:03:12 2013 Z
Group Comment : Administrators have complete and unrestricted access to the computer/domain
Users :
S-1-5-21-718126207-1171771683-1750804747-1001
S-1-5-21-718126207-1171771683-1750804747-500
Group Name : Power Users [0]
LastWrite : Mon Aug 12 03:08:08 2013 Z
Group Comment : Power Users are included for backwards compatibility and possess limited administrative powers
Users : None
Group Name : Cryptographic Operators [0]
LastWrite : Mon Aug 12 03:08:08 2013 Z
Group Comment : Members are authorized to perform cryptographic operations.
Users : None
Group Name : Remote Management Users [0]
LastWrite : Thu Jul 26 07:19:51 2012 Z
Group Comment : Members of this group can access WMI resources over management protocols (such as WS-Management via the Windows Remote Management service). This applies only to WMI namespaces that grant access to the user.
Users : None
Group Name : Replicator [0]
LastWrite : Mon Aug 12 03:08:08 2013 Z
Group Comment : Supports file replication in a domain
Users : None
Group Name : Performance Monitor Users [0]
LastWrite : Thu Jul 26 07:19:51 2012 Z
Group Comment : Members of this group can access performance counter data locally and remotely
Users : None
Group Name : Remote Desktop Users [0]
LastWrite : Mon Aug 12 03:08:08 2013 Z
Group Comment : Members in this group are granted the right to logon remotely
Users : None
Analysis Tips:
- For well-known SIDs, see http://support.microsoft.com/kb/243330
- S-1-5-4 = Interactive
- S-1-5-11 = Authenticated Users
- Correlate the user SIDs to the output of the ProfileList plugin
====================================================
AUTORUNS
====================================================
Key: Microsoft\Windows\CurrentVersion\Run
Last write time: 10/19/2013 2:06:22 AM +00:00
Number of Values: 13
Number of Subkeys: 0
------------ Value #0 ------------
Name: DptfPolicyLpmServiceHelper (RegSz)
Data: C:\WINDOWS\system32\DptfPolicyLpmServiceHelper.exe (Slack: 00-00-00-00-00-00)
------------ Value #1 ------------
Name: RtsFT (RegSz)
Data: RTFTrack.exe (Slack: 00-00)
------------ Value #2 ------------
Name: SynLenovoGestureMgr (RegExpandSz)
Data: "%ProgramFiles%\Synaptics\SynTP\SynLenovoGestureMgr.exe" /m (Slack: 00-00-00-00)
------------ Value #3 ------------
Name: cAudioFilterAgent (RegSz)
Data: C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe (Slack: 00-00-00-00)
------------ Value #4 ------------
Name: ForteConfig (RegSz)
Data: C:\Program Files\Conexant\ForteConfig\fmapp.exe (Slack: 00-00-00-00)
------------ Value #5 ------------
Name: SmartAudio (RegSz)
Data: C:\Program Files\CONEXANT\SAII\SACpl.exe /t (Slack: 00-00-00-00)
------------ Value #6 ------------
Name: BtServer (RegSz)
Data: "C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe" (Slack: 00-00-00-00)
------------ Value #7 ------------
Name: Lenovo Transition (RegSz)
Data: C:\Program Files (x86)\Lenovo\Lenovo Transition\Lenovo Transition.exe -HIDE (Slack: 00-00-00-00)
------------ Value #8 ------------
Name: yogaserver (RegSz)
Data: C:\ProgramData\YogaSmartSwicth\yogaserver.exe
------------ Value #9 ------------
Name: SynTPEnh (RegExpandSz)
Data: %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe (Slack: 00-00-00-00)
------------ Value #10 ------------
Name: IgfxTray (RegSz)
Data: "C:\WINDOWS\system32\igfxtray.exe" (Slack: 00-00-30-00-2E-00)
------------ Value #11 ------------
Name: HotKeysCmds (RegSz)
Data: "C:\WINDOWS\system32\hkcmd.exe" (Slack: 74-00-30-00)
------------ Value #12 ------------
Name: Persistence (RegSz)
Data: "C:\WINDOWS\system32\igfxpers.exe" (Slack: 69-00-6E-00-66-00)
Key: Microsoft\Windows\CurrentVersion\RunOnce
Last write time: 10/23/2013 10:11:26 AM +00:00
Number of Values: 0
Number of Subkeys: 0
Key: Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Last write time: 9/23/2013 7:14:06 PM +00:00
Number of Values: 0
Number of Subkeys: 0
Key: Classes\PROTOCOLS\Filter\application/octet-stream
Last write time: 9/23/2013 7:14:10 PM +00:00
Number of Values: 1
Number of Subkeys: 0
------------ Value #0 ------------
Name: CLSID (RegSz)
Data: {1E66F26B-79EE-11D2-8710-00C04F79ED0D} (Slack: 00-00-00-00-00-00)
Key: Classes\PROTOCOLS\Filter\application/x-complus
Last write time: 9/23/2013 7:14:10 PM +00:00
Number of Values: 1
Number of Subkeys: 0
------------ Value #0 ------------
Name: CLSID (RegSz)
Data: {1E66F26B-79EE-11D2-8710-00C04F79ED0D} (Slack: 00-00-00-00-00-00)
Key: Classes\PROTOCOLS\Filter\application/x-msdownload
Last write time: 9/23/2013 7:14:10 PM +00:00
Number of Values: 1
Number of Subkeys: 0
------------ Value #0 ------------
Name: CLSID (RegSz)
Data: {1E66F26B-79EE-11D2-8710-00C04F79ED0D} (Slack: 00-00-00-00-00-00)
====================================================
WINLOGON
====================================================
Microsoft\Windows NT\CurrentVersion\Winlogon
LastWrite Time Wed Oct 23 02:56:17 2013 (UTC)
LegalNoticeText =
LegalNoticeCaption =
ForceUnlockLogon = 0
ReportBootOk = 1
AutoRestartShell = 1
PowerdownAfterShutdown = 0
ShutdownWithoutLogon = 0
PasswordExpiryWarning = 5
WinStationsDisabled = 0
scremoveoption = 0
EnableFirstLogonAnimation = 1
AutoAdminLogon = 0
DisableCad = 1
DebugServerCommand = no
CachedLogonsCount = 10
ShutdownFlags = 39
Background = 0 0 0
Shell = explorer.exe
Userinit = C:\Windows\system32\userinit.exe,
PreCreateKnownFolders = {A520A1A4-1780-4FF6-BD18-167343C5AF16}
VMApplet = SystemPropertiesPerformance.exe /pagefile
LastUsedUsername = MicrosoftAccount\dblake@asgard-venture-capital.com
DefaultUserName = MicrosoftAccount\dblake@asgard-venture-capital.com
AutoLogonSID = S-1-11-96-3623454863-58364-18864-2661722203-1597581903-3241140313-1528907555-2380831335-2281093177-363464117
Notify subkey contents:
igfxcui - Sat Oct 19 02:06:22 2013
DLLName: igfxdev.dll
Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon
LastWrite Time Mon Sep 23 19:14:11 2013 (UTC)
DefaultDomainName =
DefaultUserName =
Userinit = userinit.exe
Shell = explorer.exe
PreCreateKnownFolders = {A520A1A4-1780-4FF6-BD18-167343C5AF16}
VMApplet = SystemPropertiesPerformance.exe /pagefile
Notify subkey not found.
Analysis Tips: The UserInit and Shell values are executed when a user logs on.
The UserInit value should contain a reference to userinit.exe; the Shell value
should contain just 'explorer.exe'. Check TaskMan & System values, if found.
====================================================
USB MASS STORAGE DEVICE HISTORY
====================================================
USBStor
ControlSet001\Enum\USB
ROOT_HUB20 [Mon Sep 23 19:14:28 2013]
S/N: 4&14c1c731&0 [Wed Oct 23 02:56:15 2013]
Device Parameters LastWrite: [Tue Oct 1 14:15:07 2013]
Properties LastWrite : [Mon Sep 23 19:47:16 2013]
ParentIdPrefix: 5&1a59d89a&1
S/N: 4&2be5801c&0 [Wed Oct 23 02:56:15 2013]
Device Parameters LastWrite: [Tue Oct 1 14:15:07 2013]
Properties LastWrite : [Mon Sep 23 19:47:16 2013]
ParentIdPrefix: 5&294335c8&1
ROOT_HUB30 [Mon Sep 23 19:13:49 2013]
S/N: 4&d858888&0&0 [Wed Oct 23 02:56:15 2013]
Device Parameters LastWrite: [Tue Oct 1 14:15:07 2013]
Properties LastWrite : [Mon Sep 23 19:47:16 2013]
ParentIdPrefix: 5&262ed807&0
VID_03EB&PID_8814 [Mon Sep 23 19:14:29 2013]
S/N: 6&b2dbb92&0&4 [Wed Oct 23 02:56:18 2013]
Device Parameters LastWrite: [Mon Sep 23 19:14:36 2013]
Properties LastWrite : [Mon Sep 23 19:47:16 2013]
ParentIdPrefix: 7&8bb8b58&0
VID_03EB&PID_8814&MI_00 [Mon Sep 23 19:14:29 2013]
S/N: 7&8bb8b58&0&0000 [Wed Oct 23 02:56:19 2013]
Device Parameters LastWrite: [Mon Sep 23 19:14:36 2013]
Properties LastWrite : [Mon Sep 23 19:47:16 2013]
ParentIdPrefix: 8&24551890&0
VID_03EB&PID_8814&MI_01 [Mon Sep 23 19:14:29 2013]
S/N: 7&8bb8b58&0&0001 [Wed Oct 23 02:56:19 2013]
Device Parameters LastWrite: [Mon Sep 23 19:14:36 2013]
Properties LastWrite : [Mon Sep 23 19:47:16 2013]
ParentIdPrefix: 8&378534ce&0
VID_0421&PID_0661 [Sat Oct 19 19:40:14 2013]
S/N: 0000001173C819470000000000000000 [Mon Oct 21 20:40:23 2013]
Device Parameters LastWrite: [Sat Oct 19 19:40:14 2013]
Properties LastWrite : [Sat Oct 19 19:40:15 2013]
ParentIdPrefix: 6&6d096df&0
VID_0421&PID_0661&MI_00 [Sat Oct 19 19:40:14 2013]
S/N: 6&6d096df&0&0000 [Mon Oct 21 20:40:25 2013]
Device Parameters LastWrite: [Sat Oct 19 19:40:18 2013]
Properties LastWrite : [Sat Oct 19 19:40:18 2013]
FriendlyName : Donald's Windows Phone
VID_0421&PID_0661&MI_01 [Sat Oct 19 19:40:14 2013]
S/N: 6&6d096df&0&0001 [Sat Oct 19 19:40:14 2013]
Device Parameters LastWrite: [Sat Oct 19 19:40:14 2013]
Properties LastWrite : [Sat Oct 19 19:40:15 2013]
FriendlyName : RM-860|Nokia Lumia 928
VID_0421&PID_0661&MI_02 [Sat Oct 19 19:40:14 2013]
S/N: 6&6d096df&0&0002 [Sat Oct 19 19:40:14 2013]
Device Parameters LastWrite: [Sat Oct 19 19:40:14 2013]
Properties LastWrite : [Sat Oct 19 19:40:15 2013]
FriendlyName : RM-860|Nokia Lumia 928
VID_0421&PID_066E [Mon Oct 21 17:31:47 2013]
S/N: 5&262ed807&0&4 [Mon Oct 21 17:31:47 2013]
Device Parameters LastWrite: [Mon Oct 21 17:31:47 2013]
Properties LastWrite : [Mon Oct 21 17:31:48 2013]
FriendlyName : NOKIA BOOTMGR
VID_045E&PID_062A [Mon Oct 21 17:31:54 2013]
S/N: 5&262ed807&0&4 [Mon Oct 21 17:31:54 2013]
Device Parameters LastWrite: [Mon Oct 21 17:31:56 2013]
Properties LastWrite : [Mon Oct 21 17:31:55 2013]
ParentIdPrefix: 6&1f067bf6&0
VID_04F2&PID_B35E [Mon Sep 23 19:14:30 2013]
S/N: 0x0001 [Wed Oct 23 02:56:18 2013]
Device Parameters LastWrite: [Mon Sep 23 19:14:36 2013]
Properties LastWrite : [Mon Sep 23 19:47:16 2013]
ParentIdPrefix: 7&38823332&1
VID_04F2&PID_B35E&MI_00 [Mon Sep 23 19:14:31 2013]
S/N: 7&38823332&1&0000 [Wed Oct 23 02:56:19 2013]
Device Parameters LastWrite: [Mon Sep 23 19:14:46 2013]
Properties LastWrite : [Mon Sep 23 19:47:16 2013]
FriendlyName : @oem17.inf,%rtsuvc.FriendlyName%;Lenovo EasyCamera
VID_058F&PID_6366 [Sun Oct 13 09:03:24 2013]
S/N: 058F63666438 [Sun Oct 13 09:03:25 2013]
Device Parameters LastWrite: [Sun Oct 13 09:03:24 2013]
Properties LastWrite : [Sun Oct 13 09:03:25 2013]
VID_05AC&PID_129A [Fri Oct 18 01:34:33 2013]
S/N: b15b3ded774bb82bbb8f3a592105338c6e0bd485 [Fri Oct 18 02:09:11 2013]
Device Parameters LastWrite: [Fri Oct 18 02:09:11 2013]
Properties LastWrite : [Fri Oct 18 01:34:36 2013]
FriendlyName : @oem74.inf,%iPhone.DeviceDesc%;Apple Mobile Device USB Driver
VID_05AC&PID_12A4 [Thu Oct 17 16:44:13 2013]
S/N: c5a218ca97fb7bd4f1ac881aa801d594a6fefb9c [Thu Oct 17 16:44:20 2013]
Device Parameters LastWrite: [Thu Oct 17 16:44:21 2013]
Properties LastWrite : [Thu Oct 17 16:44:18 2013]
FriendlyName : Apple iPad
VID_090C&PID_1000 [Mon Oct 21 18:46:16 2013]
S/N: AA04012700011123 [Mon Oct 21 20:11:48 2013]
Device Parameters LastWrite: [Mon Oct 21 18:46:16 2013]
Properties LastWrite : [Mon Oct 21 18:46:17 2013]
S/N: AA04012700013494 [Fri Oct 18 18:32:25 2013]
Device Parameters LastWrite: [Fri Oct 18 18:32:25 2013]
Properties LastWrite : [Thu Oct 17 19:28:34 2013]
VID_0BDA&PID_0129 [Mon Sep 23 19:14:29 2013]
S/N: 20100201396000000 [Wed Oct 23 02:56:19 2013]
Device Parameters LastWrite: [Mon Sep 23 19:23:09 2013]
Properties LastWrite : [Mon Sep 23 19:47:16 2013]
VID_0BDA&PID_1724 [Mon Sep 23 19:14:30 2013]
S/N: 00e04c000001 [Wed Oct 23 02:56:16 2013]
Device Parameters LastWrite: [Mon Sep 23 19:14:36 2013]
Properties LastWrite : [Mon Sep 23 19:47:16 2013]
ParentIdPrefix: 7&1308b7d4&1
VID_0BDA&PID_1724&MI_00 [Mon Sep 23 19:14:30 2013]
S/N: 7&1308b7d4&1&0000 [Wed Oct 23 02:56:18 2013]
Device Parameters LastWrite: [Mon Sep 23 19:14:38 2013]
Properties LastWrite : [Mon Sep 23 19:47:16 2013]
ParentIdPrefix: 8&36e5acd6&0
VID_0BDA&PID_1724&MI_02 [Mon Sep 23 19:14:30 2013]
S/N: 7&1308b7d4&1&0002 [Mon Sep 23 19:21:35 2013]
Device Parameters LastWrite: [Mon Sep 23 19:14:44 2013]
Properties LastWrite : [Mon Sep 23 19:47:16 2013]
FriendlyName : Realtek RTL8723A Wireless LAN 802.11n USB 2.0 Network Adapter
ParentIdPrefix: 8&a364398&0
VID_1058&PID_0702 [Fri Oct 18 18:32:18 2013]
S/N: 575848323038333634303334 [Fri Oct 18 18:33:44 2013]
Device Parameters LastWrite: [Fri Oct 18 18:32:18 2013]
Properties LastWrite : [Fri Oct 18 18:32:19 2013]
VID_1058&PID_0704 [Wed Oct 23 03:09:13 2013]
S/N: 57442D5758453830385A3735373133 [Wed Oct 23 03:09:13 2013]
Device Parameters LastWrite: [Wed Oct 23 04:57:01 2013]
Properties LastWrite : [Wed Oct 23 03:09:14 2013]
VID_1221&PID_3234 [Thu Oct 17 21:06:15 2013]
S/N: 1000000000001C37 [Mon Oct 21 18:45:56 2013]
Device Parameters LastWrite: [Thu Oct 17 21:06:15 2013]
Properties LastWrite : [Thu Oct 17 21:06:16 2013]
VID_1307&PID_0116 [Tue Oct 22 21:41:53 2013]
S/N: 00000022928277 [Wed Oct 23 02:56:28 2013]
Device Parameters LastWrite: [Tue Oct 22 21:41:53 2013]
Properties LastWrite : [Tue Oct 22 21:41:54 2013]
VID_152E&PID_2507 [Mon Sep 23 19:14:29 2013]
S/N: P01100109005530 [Mon Sep 23 19:21:27 2013]
Device Parameters LastWrite: [Mon Sep 23 19:14:29 2013]
Properties LastWrite : [Mon Sep 23 19:14:29 2013]
VID_1EC9&PID_A081 [Fri Oct 18 18:33:24 2013]
S/N: MBA34212080313074295 [Fri Oct 18 18:43:56 2013]
Device Parameters LastWrite: [Fri Oct 18 18:43:56 2013]
Properties LastWrite : [Fri Oct 18 18:33:25 2013]
VID_2047&PID_0855 [Mon Sep 23 19:14:30 2013]
S/N: 0F73806F2E001600 [Wed Oct 23 03:58:22 2013]
Device Parameters LastWrite: [Mon Sep 23 19:14:32 2013]
Properties LastWrite : [Mon Sep 23 19:47:16 2013]
ParentIdPrefix: 7&397bac5&1