Sunday, March 18, 2012

Remote Intrusion Logs

Reading all PNP ID list from Win32_SystemDevices
===================================================================================================
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_MotherboardDevice.DeviceID="Motherboard"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="STORAGE\\VOLUME\\{FAE5CC81-A641-11E0-B274-806E6F6E6963}#0000004A7F500000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_VOLSNAP\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_AFD\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\PNP0B00\\4&297A31CB&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="SCSI\\CDROM&VEN_HP&PROD_DVD_A__DS8A5LH\\4&2AE7DAF&0&010000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_NULL\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_VWIFIFLT\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\PNP0C01\\4&297A31CB&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_PCW\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1002&DEV_4397&SUBSYS_3577103C&REV_00\\3&2411E6FE&3&90"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_MOUNTMGR\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1022&DEV_1510&SUBSYS_15101022&REV_00\\3&2411E6FE&3&00"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1022&DEV_1719&SUBSYS_00000000&REV_00\\3&2411E6FE&3&C7"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_WANARPV6\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_ATAPI\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_PEAUTH\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\PNP0C02\\3&2411E6FE&3"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_MPSDRV\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="SCSI\\DISK&VEN_HITACHI&PROD_HTS543232A7A384\\4&2AE7DAF&0&000000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_WDF01000\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_BEEP\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_PSCHED\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\PNP0C02\\4&297A31CB&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1002&DEV_4397&SUBSYS_3577103C&REV_00\\3&2411E6FE&3&B0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1022&DEV_1700&SUBSYS_00000000&REV_43\\3&2411E6FE&3&C0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_WFPLWF\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_10EC&DEV_5209&SUBSYS_3577103C&REV_01\\00000001004CE00000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\PNP0C04\\4&297A31CB&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="UMB\\UMB\\1&841921D&0&PRINTERBUSENUMERATOR"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\ACPI0003\\2&DABA3FF&3"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_CLFS\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\MSSMBIOS\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_RDPCDD\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\PNP0C09\\4&297A31CB&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\AUTHENTICAMD_-_AMD64_FAMILY_20_MODEL_1_-_AMD_E-350_PROCESSOR\\_0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\MS_AGILEVPNMINIPORT\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_CNG\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="USB\\ROOT_HUB\\4&26ABB447&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_RDPENCDD\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1002&DEV_4383&SUBSYS_3577103C&REV_40\\3&2411E6FE&3&A2"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1002&DEV_4399&SUBSYS_3577103C&REV_00\\3&2411E6FE&3&A5"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1022&DEV_1701&SUBSYS_00000000&REV_00\\3&2411E6FE&3&C1"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\PNP0C0A\\0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_10EC&DEV_8136&SUBSYS_3577103C&REV_05\\4&3828895F&0&00A9"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\MS_L2TPMINIPORT\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="USB\\ROOT_HUB\\4&34DF125A&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\PNP0C0C\\2&DABA3FF&3"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_RDPREFMP\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_DISCACHE\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\MS_NDISWANBH\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="USB\\ROOT_HUB\\4&7EE1969&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\PNP0C0D\\2&DABA3FF&3"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_RSPNDR\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\AUTHENTICAMD_-_AMD64_FAMILY_20_MODEL_1_-_AMD_E-350_PROCESSOR\\_1"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_MSISADRV\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1002&DEV_4384&SUBSYS_00000000&REV_40\\3&2411E6FE&3&A4"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1002&DEV_439D&SUBSYS_3577103C&REV_40\\3&2411E6FE&3&A3"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1022&DEV_1702&SUBSYS_00000000&REV_00\\3&2411E6FE&3&C2"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_10EC&DEV_8176&SUBSYS_1629103C&REV_01\\019181FEFF4CE00000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\MS_NDISWANIP\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="USB\\ROOT_HUB20\\4&14825D49&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_SECDRV\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\PNP0C14\\0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\SYN1E4B\\4&297A31CB&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\MS_NDISWANIPV6\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_SPLDR\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="USB\\ROOT_HUB20\\4&18BD4808&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_NATIVEWIFIP\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\THERMALZONE\\TSZ0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1002&DEV_4385&SUBSYS_3577103C&REV_42\\3&2411E6FE&3&A0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\MS_PPPOEMINIPORT\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1002&DEV_43A0&SUBSYS_00001002&REV_00\\3&2411E6FE&3&A8"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\FIXEDBUTTON\\2&DABA3FF&3"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1022&DEV_1703&SUBSYS_00000000&REV_00\\3&2411E6FE&3&C3"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="USB\\VID_0C45&PID_6321\\5&F9AB14A&0&2"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_NDIS\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI_HAL\\PNP0C08\\0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\MS_PPTPMINIPORT\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\PNP0000\\4&297A31CB&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_NDISUIO\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="USB\\VID_0C45&PID_6321&MI_00\\6&11780B0E&0&0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\MS_SSTPMINIPORT\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\PNP0100\\4&297A31CB&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="STORAGE\\VOLUME\\{FAE5CC81-A641-11E0-B274-806E6F6E6963}#0000000000100000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1002&DEV_4391&SUBSYS_3577103C&REV_00\\3&2411E6FE&3&88"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1002&DEV_43A1&SUBSYS_00001002&REV_00\\3&2411E6FE&3&A9"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1022&DEV_1704&SUBSYS_00000000&REV_00\\3&2411E6FE&3&C4"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_NDPROXY\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_FVEVOL\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_TCPIP\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\*ISATAP\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\RDP_KBD\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="DISPLAY\\SEC4251\\4&1F28CD62&0&UID256"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\PNP0103\\3&2411E6FE&3"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_HTTP\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\*ISATAP\\0001"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_TCPIPREG\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\RDP_MOU\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\PNP0200\\4&297A31CB&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\ACPI_HAL\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_HWPOLICY\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_NETBT\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\SYSTEM\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1002&DEV_4396&SUBSYS_3577103C&REV_00\\3&2411E6FE&3&92"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="HDAUDIO\\FUNC_01&VEN_10EC&DEV_0270&SUBSYS_103C3577&REV_1001\\4&30E8B9E6&0&0001"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1002&DEV_43A3&SUBSYS_00001002&REV_00\\3&2411E6FE&3&AB"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_TDX\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1022&DEV_1716&SUBSYS_00000000&REV_00\\3&2411E6FE&3&C6"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="STORAGE\\VOLUME\\{FAE5CC81-A641-11E0-B274-806E6F6E6963}#000000000C800000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\BLBDRIVE\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\PNP0303\\4&297A31CB&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\SYSTEM\\0001"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_KSECDD\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_VGASAVE\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\COMPOSITEBUS\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\UMBUS\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\PNP0800\\4&297A31CB&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_NSIPROXY\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_KSECPKG\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_VOLMGRX\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\VDRVROOT\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\COMPOSITE_BATTERY\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1002&DEV_4396&SUBSYS_3577103C&REV_00\\3&2411E6FE&3&B2"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1002&DEV_9802&SUBSYS_3577103C&REV_00\\3&2411E6FE&3&08"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="PCI\\VEN_1022&DEV_1718&SUBSYS_00000000&REV_00\\3&2411E6FE&3&C5"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ACPI\\PNP0A08\\1"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\LEGACY_LLTDIO\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PnPEntity.DeviceID="ROOT\\VOLMGR\\0000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_SoundDevice.DeviceID="HDAUDIO\\FUNC_01&VEN_10EC&DEV_0270&SUBSYS_103C3577&REV_1001\\4&30E8B9E6&0&0001"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_Battery.DeviceID="HP"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_IDEController.DeviceID="PCI\\VEN_1002&DEV_4391&SUBSYS_3577103C&REV_00\\3&2411E6FE&3&88"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_Bus.DeviceID="PCI_BUS_0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_Bus.DeviceID="PCI_BUS_2"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_Bus.DeviceID="PNP_BUS_0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_Bus.DeviceID="PCI_BUS_6"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_Bus.DeviceID="PCI_BUS_7"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_Bus.DeviceID="PCI_BUS_1"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PortableBattery.DeviceID="Portable Battery 0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_NetworkAdapter.DeviceID="0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_NetworkAdapter.DeviceID="1"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_NetworkAdapter.DeviceID="2"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_NetworkAdapter.DeviceID="3"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_NetworkAdapter.DeviceID="4"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_NetworkAdapter.DeviceID="5"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_NetworkAdapter.DeviceID="6"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_NetworkAdapter.DeviceID="7"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_NetworkAdapter.DeviceID="8"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_NetworkAdapter.DeviceID="9"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_NetworkAdapter.DeviceID="10"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_NetworkAdapter.DeviceID="11"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_NetworkAdapter.DeviceID="12"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_Printer.DeviceID="Microsoft XPS Document Writer"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_Printer.DeviceID="Fax"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_Processor.DeviceID="CPU0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_CDROMDrive.DeviceID="SCSI\\CDROM&VEN_HP&PROD_DVD_A__DS8A5LH\\4&2AE7DAF&0&010000"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_DiskDrive.DeviceID="\\\\.\\PHYSICALDRIVE0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_DiskPartition.DeviceID="Disk #0, Partition #0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_DiskPartition.DeviceID="Disk #0, Partition #1"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_DiskPartition.DeviceID="Disk #0, Partition #2"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_LogicalDisk.DeviceID="C:"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_LogicalDisk.DeviceID="D:"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_LogicalDisk.DeviceID="H:"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_MemoryArray.DeviceID="Memory Array 0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_MemoryDevice.DeviceID="Memory Device 0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_MemoryDevice.DeviceID="Memory Device 1"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_Keyboard.DeviceID="ACPI\\PNP0303\\4&297A31CB&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_USBController.DeviceID="PCI\\VEN_1002&DEV_4397&SUBSYS_3577103C&REV_00\\3&2411E6FE&3&90"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_USBController.DeviceID="PCI\\VEN_1002&DEV_4397&SUBSYS_3577103C&REV_00\\3&2411E6FE&3&B0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_USBController.DeviceID="PCI\\VEN_1002&DEV_4399&SUBSYS_3577103C&REV_00\\3&2411E6FE&3&A5"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_USBController.DeviceID="PCI\\VEN_1002&DEV_4396&SUBSYS_3577103C&REV_00\\3&2411E6FE&3&92"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_USBController.DeviceID="PCI\\VEN_1002&DEV_4396&SUBSYS_3577103C&REV_00\\3&2411E6FE&3&B2"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_PointingDevice.DeviceID="ACPI\\SYN1E4B\\4&297A31CB&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_USBHub.DeviceID="USB\\ROOT_HUB\\4&26ABB447&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_USBHub.DeviceID="USB\\ROOT_HUB\\4&34DF125A&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_USBHub.DeviceID="USB\\ROOT_HUB\\4&7EE1969&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_USBHub.DeviceID="USB\\ROOT_HUB20\\4&14825D49&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_USBHub.DeviceID="USB\\ROOT_HUB20\\4&18BD4808&0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_USBHub.DeviceID="USB\\VID_0C45&PID_6321\\5&F9AB14A&0&2"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_CacheMemory.DeviceID="Cache Memory 0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_CacheMemory.DeviceID="Cache Memory 1"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_DesktopMonitor.DeviceID="DesktopMonitor1"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_VideoController.DeviceID="VideoController1"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_VoltageProbe.DeviceID="root\\cimv2 0"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_Volume.DeviceID="\\\\?\\Volume{ef0ef444-a63f-11e0-a6db-806e6f6e6963}\\"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_Volume.DeviceID="\\\\?\\Volume{ef0ef445-a63f-11e0-a6db-806e6f6e6963}\\"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_Volume.DeviceID="\\\\?\\Volume{5eb44131-a640-11e0-8117-3cd92b21a2b7}\\"
\\WIN-7L1TU2RL4PE\root\cimv2:Win32_Volume.DeviceID="\\\\?\\Volume{fae5cc8d-a641-11e0-b274-806e6f6e6963}\\"
End of reading all PNP ID list from Win32_SystemDevices
===================================================================================================
===================================================================================================
===================================================================================================
Start cleaning out PNP ID list and get all starting with VID, VEN, FUNC and Display
===================================================================================================
PCI\\VEN_1002&DEV_4397
PCI\\VEN_1022&DEV_1510
PCI\\VEN_1022&DEV_1719
PCI\\VEN_1002&DEV_4397
PCI\\VEN_1022&DEV_1700
PCI\\VEN_10EC&DEV_5209
PCI\\VEN_1002&DEV_4383
PCI\\VEN_1002&DEV_4399
PCI\\VEN_1022&DEV_1701
PCI\\VEN_10EC&DEV_8136
PCI\\VEN_1002&DEV_4384
PCI\\VEN_1002&DEV_439D
PCI\\VEN_1022&DEV_1702
PCI\\VEN_10EC&DEV_8176
PCI\\VEN_1002&DEV_4385
PCI\\VEN_1002&DEV_43A0
PCI\\VEN_1022&DEV_1703
USB\\VID_0C45&PID_6321
USB\\VID_0C45&PID_6321
PCI\\VEN_1002&DEV_4391
PCI\\VEN_1002&DEV_43A1
PCI\\VEN_1022&DEV_1704
DISPLAY\\SEC4251
PCI\\VEN_1002&DEV_4396
HDAUDIO\\FUNC_01&VEN_10EC
PCI\\VEN_1002&DEV_43A3
PCI\\VEN_1022&DEV_1716
PCI\\VEN_1002&DEV_4396
PCI\\VEN_1002&DEV_9802
PCI\\VEN_1022&DEV_1718
HDAUDIO\\FUNC_01&VEN_10EC
PCI\\VEN_1002&DEV_4391
PCI\\VEN_1002&DEV_4397
PCI\\VEN_1002&DEV_4397
PCI\\VEN_1002&DEV_4399
PCI\\VEN_1002&DEV_4396
PCI\\VEN_1002&DEV_4396
USB\\VID_0C45&PID_6321
End of cleaning out PNP ID list and get all starting with VID, VEN, FUNC and Display
===================================================================================================



c:\hp\bin\rstonepre.ini
Starting RStone
Passed in Initialize COM
Passed in Initialize Security
Passed to create IWbemLocator object
Passed to read from: ROOT WMI
Passed to set security level on the proxy
Passed to read from: MSSMBios_RawSMBiosTables
Passed to connect to: ROOT CIMV2
Passed to set proxy blanket
Passed to read from: Win32_ComputerSystem
Passed to read from: Win32_BaseBoard
Passed to read from: Win32_SystemDevices

Starting Webcam search by reading Device Names
Passed to read from: Win32_PnPEntity
intel raid controller windows 7
wdc wd2500bekt-60a25t1 ata device
wdc wd2500bekt-60a25t1 ata device
dynamic volume manager
universal serial bus (usb) controller
aliide
pci host bridge
pci device
iirsp
iirsp
vsmraid
amdide
null
intelide
intelide
amdsata
microsoft watchdog timer driver
nvraid
pci device
universal serial bus (usb) controller
isapnp
pci host bridge
ethernet controller
ethernet controller
kernel mode driver frameworks service
nvstor
amdsbs
ksecdd
ksecdd
pciide
arc
arc
ksecpkg
pci to pci bridge
pci to pci bridge
pci to isa bridge
pci host bridge
pci host bridge
adaptec sas/sata-ii raid windows inbox miniport driver
performance counters for windows driver
network controller
network controller
lsi_fc
lsi_fc
lsi_fc
qlogic fibre channel miniport driver
ide channel
lsi_sas
lsi_sas
lsi_sas
qlogic iscsi miniport driver
common log (clfs)
pci to pci bridge
pci host bridge
pci host bridge
lsi_sas2
ata channel 0
ata channel 0
cmdide
cmdide
cmdide
lsi_scsi
lsi_scsi
cng
sbp-2 transport/protocol bus driver
ata channel 1
ata channel 1
serial ata controller
megasas
pci to pci bridge
microsoft composite battery driver
pci host bridge
sisraid2
ramdisk
ramdisk
ramdisk
megasr
megasr
sisraid4
sisraid4
mount point manager
elxstor
elxstor
elxstor
universal serial bus (usb) controller
stexstor
pci to pci bridge
pci host bridge
pci host bridge
pci host bridge
pci host bridge
disk virtual machine bus acceleration filter driver
disk virtual machine bus acceleration filter driver
msisadrv
msisadrv
msisadrv
storvsc
adp94xx
universal serial bus (usb) controller
video controller (vga compatible)
pci host bridge
pci host bridge
pci host bridge
tcp/ip protocol driver
adpahci
ndis system driver
hp dvdram gt31l ata device
Found the word HP
hp dvdram gt31l ata device
Found the word HP
terminal device driver
adpu320
hp webcam-101
Found the word HP
Found the word Webcam
Passed to read for: Webcam

Passed to read for: BatteryDesignCap
Failed to find C:\System.sav\Info.bom
Found C:\Info.bom
Start printing out all PNP IDs from Device Manager to INI file
Finished printing out all PNP IDs from Device Manager to INI file
End of log file



c:\hp\bin\rstonefupdate.ini
Starting RStone
Passed in Initialize COM
Passed in Initialize Security
Passed to create IWbemLocator object
Passed to read from: ROOT WMI
Passed to set security level on the proxy
Passed to read from: MSSMBios_RawSMBiosTables
Passed to connect to: ROOT CIMV2
Passed to set proxy blanket
Passed to read from: Win32_ComputerSystem
Passed to read from: Win32_BaseBoard
Passed to read from: Win32_SystemDevices

Starting Webcam search by reading Device Names
Passed to read from: Win32_PnPEntity
intel raid controller windows 7
hitachi hts543232a7a384 ata device
hitachi hts543232a7a384 ata device
dynamic volume manager
universal serial bus (usb) controller
aliide
pci host bridge
pci device
iirsp
iirsp
vsmraid
amdide
null
intelide
intelide
amdsata
microsoft watchdog timer driver
nvraid
pci device
universal serial bus (usb) controller
isapnp
pci host bridge
ethernet controller
ethernet controller
kernel mode driver frameworks service
nvstor
amdsbs
ksecdd
ksecdd
pciide
arc
arc
ksecpkg
pci to pci bridge
pci to pci bridge
pci to isa bridge
pci host bridge
pci host bridge
adaptec sas/sata-ii raid windows inbox miniport driver
performance counters for windows driver
network controller
network controller
lsi_fc
lsi_fc
lsi_fc
qlogic fibre channel miniport driver
ide channel
lsi_sas
lsi_sas
lsi_sas
qlogic iscsi miniport driver
common log (clfs)
pci to pci bridge
pci host bridge
pci host bridge
lsi_sas2
ata channel 0
ata channel 0
cmdide
cmdide
cmdide
lsi_scsi
lsi_scsi
cng
sbp-2 transport/protocol bus driver
ata channel 1
ata channel 1
serial ata controller
megasas
pci to pci bridge
microsoft composite battery driver
pci host bridge
sisraid2
ramdisk
ramdisk
ramdisk
megasr
megasr
sisraid4
sisraid4
mount point manager
elxstor
elxstor
elxstor
universal serial bus (usb) controller
stexstor
pci to pci bridge
pci host bridge
pci host bridge
pci host bridge
pci host bridge
disk virtual machine bus acceleration filter driver
disk virtual machine bus acceleration filter driver
msisadrv
msisadrv
msisadrv
storvsc
adp94xx
universal serial bus (usb) controller
video controller (vga compatible)
pci host bridge
pci host bridge
pci host bridge
tcp/ip protocol driver
adpahci
ndis system driver
hp dvd a  ds8a5lh ata device
Found the word HP
hp dvd a  ds8a5lh ata device
Found the word HP
terminal device driver
adpu320
hp webcam-101
Found the word HP
Found the word Webcam
Passed to read for: Webcam

Passed to read for: BatteryDesignCap
Found C:\System.sav\Info.bom
Start printing out all PNP IDs from Device Manager to INI file
Finished printing out all PNP IDs from Device Manager to INI file
End of log file


DANIEL S. ABRAHAMIAN
REMOTE INTRUSION LOGS
FEELMYFLAME

No comments:

Post a Comment