Sophos mailmonitor --Contd

These are the logs
External Users/Domains: [email protected], [email protected]
Internal Users/Domains: [email protected], [email protected], [email protected]
These are hosted on iplanet...
Alternate Conversion channel approach is used as per Chad's PDF
----AVBOX------------------MTA---------------EXTMAILSVR
............................................|
............................................|
........................................Store/Dir Server
==============================================
Mail from USER hasan -> preetam & nasarullah
==============================================
ON MTA
========
21-Sep-2005 10:02:51.24 tcp_local + O TCP|MTArouter_IP|25|Clt_extMailserver_DNS_IP|1233 SMTP
21-Sep-2005 10:02:59.50 tcp_local tcp_scan E 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_scan/004/ZZ0IN5001059OZVL.00 <[email protected]> mailsrv rgandhi (Clt_extMailserver [Clt_extMailserver_DNS_IP])
21-Sep-2005 10:02:59.50 tcp_local tcp_scan E 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_scan/004/ZZ0IN5001059OZVL.00 <[email protected]> mailsrv rgandhi (Clt_extMailserver [Clt_extMailserver_DNS_IP])
21-Sep-2005 10:02:59.50 > Date: Tue, 20 Sep 2005 10:02:51 +0800
21-Sep-2005 10:02:59.50 > From: "hasan" <[email protected]>
21-Sep-2005 10:02:59.50 > Subject: Attachment
21-Sep-2005 10:02:59.50 > To: "nasarullah" <[email protected]>
21-Sep-2005 10:02:59.50 > Cc: <[email protected]>
21-Sep-2005 10:02:59.50 > Message-id: <[email protected]>
21-Sep-2005 10:02:59.50 > MIME-version: 1.0
21-Sep-2005 10:02:59.50 > X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
21-Sep-2005 10:02:59.50 > X-Mailer: Microsoft Outlook Express 6.00.2900.2180
21-Sep-2005 10:02:59.50 > Content-type: multipart/mixed;     boundary="----=_NextPart_000_0021_01C5BDCA.76179E70"
21-Sep-2005 10:02:59.50 > X-Priority: 3
21-Sep-2005 10:02:59.50 > X-MSMail-priority: Normal
21-Sep-2005 10:02:59.54 tcp_local + C TCP|MTArouter_IP|25|Clt_extMailserver_DNS_IP|1233 SMTP
21-Sep-2005 10:02:59.80 tcp_scan - O TCP|MTArouter_IP|37666|AVscanner_IP|10024 SMTP/[AVscanner_IP]/[AVscanner_IP]
21-Sep-2005 10:02:59.82 tcp_local + O TCP|MTArouter_IP|25|AVscanner_IP|13816 SMTP
21-Sep-2005 10:02:59.97 tcp_local + C TCP|MTArouter_IP|25|AVscanner_IP|13816 SMTP
21-Sep-2005 10:03:03.23 tcp_scan D 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_scan/004/ZZ0IN5001059OZVL.00 <[email protected]> mailsrv [AVscanner_IP] dns;[AVscanner_IP] (TCP|MTArouter_IP|37666|AVscanner_IP|10024) (pxmta -- Server ESMTP [iPlanet Messaging Server 5.2 HotFix 2.07 [built Jun 24 2005]]) smtp;250 2.1.5 [email protected] and options OK.
21-Sep-2005 10:03:03.23 tcp_scan D 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_scan/004/ZZ0IN5001059OZVL.00 <[email protected]> mailsrv [AVscanner_IP] dns;[AVscanner_IP] (TCP|MTArouter_IP|37666|AVscanner_IP|10024) (pxmta -- Server ESMTP [iPlanet Messaging Server 5.2 HotFix 2.07 [built Jun 24 2005]]) smtp;250 2.1.5 [email protected] and options OK.
21-Sep-2005 10:03:03.23 > Received: from rgandhi (Clt_extMailserver [Clt_extMailserver_DNS_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with SMTP id <[email protected]>; Wed, 21 Sep 2005 10:02:59 +0800 (SGT)
21-Sep-2005 10:03:03.23 > Date: Tue, 20 Sep 2005 10:02:51 +0800
21-Sep-2005 10:03:03.23 > From: hasan <[email protected]>
21-Sep-2005 10:03:03.23 > Subject: Attachment
21-Sep-2005 10:03:03.23 > To: nasarullah <[email protected]>
21-Sep-2005 10:03:03.23 > Cc: [email protected]
21-Sep-2005 10:03:03.23 > Message-id: <[email protected]>
21-Sep-2005 10:03:03.23 > MIME-version: 1.0
21-Sep-2005 10:03:03.23 > X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
21-Sep-2005 10:03:03.23 > X-Mailer: Microsoft Outlook Express 6.00.2900.2180
21-Sep-2005 10:03:03.23 > Content-type: multipart/mixed; boundary="----=_NextPart_000_0021_01C5BDCA.76179E70"
21-Sep-2005 10:03:03.23 > X-Priority: 3
21-Sep-2005 10:03:03.23 > X-MSMail-priority: Normal
21-Sep-2005 10:03:03.24 tcp_local + O TCP|MTArouter_IP|25|AVscanner_IP|13818 SMTP
21-Sep-2005 10:03:03.25 tcp_scan - C TCP|MTArouter_IP|37666|AVscanner_IP|10024 SMTP/[AVscanner_IP]/[AVscanner_IP]
21-Sep-2005 10:03:05.84 tcp_noscan tcp_intranet E 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_intranet/004/ZZ0IN50010B9P5VL.00 <[email protected]> mailsrv logserver (logserver [AVscanner_IP])
21-Sep-2005 10:03:05.84 tcp_noscan tcp_intranet E 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_intranet/004/ZZ0IN50010B9P5VL.00 <[email protected]> mailsrv logserver (logserver [AVscanner_IP])
21-Sep-2005 10:03:05.84 > Received:      from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]);     Tue, 20 Sep 2005 02:02:42 +0000
21-Sep-2005 10:03:05.84 > Received: from rgandhi (Clt_extMailserver [Clt_extMailserver_DNS_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with SMTP id <[email protected]>; Wed, 21 Sep 2005 10:02:59 +0800 (SGT)
21-Sep-2005 10:03:05.84 > Date: Tue, 20 Sep 2005 10:02:51 +0800
21-Sep-2005 10:03:05.84 > From: hasan <[email protected]>
21-Sep-2005 10:03:05.84 > Subject: Attachment
21-Sep-2005 10:03:05.84 > To: nasarullah <[email protected]>
21-Sep-2005 10:03:05.84 > Cc: [email protected]
21-Sep-2005 10:03:05.84 > Message-id: <[email protected]>
21-Sep-2005 10:03:05.84 > MIME-version: 1.0
21-Sep-2005 10:03:05.84 > X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
21-Sep-2005 10:03:05.84 > X-Mailer: Microsoft Outlook Express 6.00.2900.2180
21-Sep-2005 10:03:05.84 > Content-type: multipart/mixed; boundary="----=_NextPart_000_0021_01C5BDCA.76179E70"
21-Sep-2005 10:03:05.84 > X-Priority: 3
21-Sep-2005 10:03:05.84 > X-MSMail-priority: Normal
21-Sep-2005 10:03:05.88 tcp_local + C TCP|MTArouter_IP|25|AVscanner_IP|13818 SMTP
21-Sep-2005 10:03:06.07 tcp_intranet - O TCP|MTA_IP|37670|STORE_IP|25 SMTP/mailserver.mail.com/mailserver.mail.com
21-Sep-2005 10:03:07.02 tcp_intranet D 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_intranet/004/ZZ0IN50010B9P5VL.00 <[email protected]> mailsrv mailserver.mail.com dns;mailserver.mail.com (TCP|MTA_IP|37670|STORE_IP|25) (mailserver -- Server ESMTP [iPlanet Messaging Server 5.2 HotFix 2.07 [built Jun 24 2005]]) smtp;250 2.1.5 @mailserver.mail.com:[email protected] and options OK.
21-Sep-2005 10:03:07.02 tcp_intranet D 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_intranet/004/ZZ0IN50010B9P5VL.00 <[email protected]> mailsrv mailserver.mail.com dns;mailserver.mail.com (TCP|MTA_IP|37670|STORE_IP|25) (mailserver -- Server ESMTP [iPlanet Messaging Server 5.2 HotFix 2.07 [built Jun 24 2005]]) smtp;250 2.1.5 @mailserver.mail.com:[email protected] and options OK.
21-Sep-2005 10:03:07.02 > Received: from logserver (logserver [AVscanner_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]>; Wed, 21 Sep 2005 10:03:05 +0800 (SGT)
21-Sep-2005 10:03:07.02 > Received: from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]); Tue, 20 Sep 2005 02:02:42 +0000
21-Sep-2005 10:03:07.02 > Received: from rgandhi (Clt_extMailserver [Clt_extMailserver_DNS_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with SMTP id <[email protected]>; Wed, 21 Sep 2005 10:02:59 +0800 (SGT)
21-Sep-2005 10:03:07.02 > Date: Tue, 20 Sep 2005 10:02:51 +0800
21-Sep-2005 10:03:07.02 > From: hasan <[email protected]>
21-Sep-2005 10:03:07.02 > Subject: Attachment
21-Sep-2005 10:03:07.02 > To: nasarullah <[email protected]>
21-Sep-2005 10:03:07.02 > Cc: [email protected]
21-Sep-2005 10:03:07.02 > Message-id: <[email protected]>
21-Sep-2005 10:03:07.02 > MIME-version: 1.0
21-Sep-2005 10:03:07.02 > X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
21-Sep-2005 10:03:07.02 > X-Mailer: Microsoft Outlook Express 6.00.2900.2180
21-Sep-2005 10:03:07.02 > Content-type: multipart/mixed; boundary="----=_NextPart_000_0021_01C5BDCA.76179E70"
21-Sep-2005 10:03:07.02 > X-Priority: 3
21-Sep-2005 10:03:07.02 > X-MSMail-priority: Normal
21-Sep-2005 10:03:07.03 tcp_intranet - C TCP|MTA_IP|37670|STORE_IP|25 SMTP/mailserver.mail.com/mailserver.mail.com
On Store
=========
20-Sep-2005 10:00:50.29 tcp_local + O TCP|STORE_IP|25|MTA_IP|37670 SMTP
20-Sep-2005 10:00:51.23 tcp_local ims-ms E 493 [email protected] rfc822;[email protected] nasarullah%alpha.com@ims-ms-daemon /iplanet/iMS52/msg-mailserver/imta/queue/ims-ms/000/ZZ0IN300709EXEHR.00 <[email protected]> mailsrv pxmta (pxmta [MTA_IP])
20-Sep-2005 10:00:51.23 tcp_local ims-ms E 493 [email protected] rfc822;[email protected] preetam%beta.sg@ims-ms-daemon /iplanet/iMS52/msg-mailserver/imta/queue/ims-ms/000/ZZ0IN300709EXEHR.00 <[email protected]> mailsrv pxmta (pxmta [MTA_IP])
20-Sep-2005 10:00:51.23 > Received: from logserver (logserver [AVscanner_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]>; Wed, 21 Sep 2005 10:03:05 +0800 (SGT)
20-Sep-2005 10:00:51.23 > Received: from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]); Tue, 20 Sep 2005 02:02:42 +0000
20-Sep-2005 10:00:51.23 > Received: from rgandhi (rgandhi.sgp.tsi [10.25.105.77]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with SMTP id <[email protected]>; Wed, 21 Sep 2005 10:02:59 +0800 (SGT)
20-Sep-2005 10:00:51.23 > Date: Tue, 20 Sep 2005 10:02:51 +0800
20-Sep-2005 10:00:51.23 > From: hasan <[email protected]>
20-Sep-2005 10:00:51.23 > Subject: Attachment
20-Sep-2005 10:00:51.23 > To: nasarullah <[email protected]>
20-Sep-2005 10:00:51.23 > Cc: [email protected]
20-Sep-2005 10:00:51.23 > Message-id: <[email protected]>
20-Sep-2005 10:00:51.23 > MIME-version: 1.0
20-Sep-2005 10:00:51.23 > X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
20-Sep-2005 10:00:51.23 > X-Mailer: Microsoft Outlook Express 6.00.2900.2180
20-Sep-2005 10:00:51.23 > Content-type: multipart/mixed; boundary="----=_NextPart_000_0021_01C5BDCA.76179E70"
20-Sep-2005 10:00:51.23 > X-Priority: 3
20-Sep-2005 10:00:51.23 > X-MSMail-priority: Normal
20-Sep-2005 10:00:51.24 tcp_local + C TCP|STORE_IP|25|MTA_IP|37670 SMTP
20-Sep-2005 10:00:51.42 ims-ms D 493 [email protected] rfc822;[email protected] nasarullah%alpha.com@ims-ms-daemon /iplanet/iMS52/msg-mailserver/imta/queue/ims-ms/000/ZZ0IN300709EXEHR.00 <[email protected]> mailsrv
20-Sep-2005 10:00:51.42 ims-ms D 493 [email protected] rfc822;[email protected] preetam%beta.sg@ims-ms-daemon /iplanet/iMS52/msg-mailserver/imta/queue/ims-ms/000/ZZ0IN300709EXEHR.00 <[email protected]> mailsrv
20-Sep-2005 10:00:51.42 > Return-path: <[email protected]>
20-Sep-2005 10:00:51.42 > Received: from pxmta (pxmta [MTA_IP]) by mailserver.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]>; Tue, 20 Sep 2005 10:00:50 +0800 (SGT)
20-Sep-2005 10:00:51.42 > Received: from logserver (logserver [AVscanner_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]>; Wed, 21 Sep 2005 10:03:05 +0800 (SGT)
20-Sep-2005 10:00:51.42 > Received: from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]); Tue, 20 Sep 2005 02:02:42 +0000
20-Sep-2005 10:00:51.42 > Received: from rgandhi (rgandhi.sgp.tsi [10.25.105.77]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with SMTP id <[email protected]>; Wed, 21 Sep 2005 10:02:59 +0800 (SGT)
20-Sep-2005 10:00:51.42 > Date: Tue, 20 Sep 2005 10:02:51 +0800
20-Sep-2005 10:00:51.42 > From: hasan <[email protected]>
20-Sep-2005 10:00:51.42 > Subject: Attachment
20-Sep-2005 10:00:51.42 > To: nasarullah <[email protected]>
20-Sep-2005 10:00:51.42 > Cc: [email protected]
20-Sep-2005 10:00:51.42 > Message-id: <[email protected]>
20-Sep-2005 10:00:51.42 > MIME-version: 1.0
20-Sep-2005 10:00:51.42 > X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
20-Sep-2005 10:00:51.42 > X-Mailer: Microsoft Outlook Express 6.00.2900.2180
20-Sep-2005 10:00:51.42 > Content-type: multipart/mixed; boundary="----=_NextPart_000_0021_01C5BDCA.76179E70"
20-Sep-2005 10:00:51.42 > X-Priority: 3
20-Sep-2005 10:00:51.42 > X-MSMail-priority: Normal
========================================================
Mail from USER [email protected] -> [email protected]
========================================================
ON MTA
========
21-Sep-2005 10:03:08.68 tcp_local + O TCP|MTArouter_IP|25|Clt_extMailserver_DNS_IP|1237 SMTP
21-Sep-2005 10:03:08.91 tcp_auth tcp_scan EA 2 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_scan/017/ZZ0IN50010E9P8VL.00 <[email protected]> *[email protected] rgandhi (Clt_extMailserver [Clt_extMailserver_DNS_IP])
21-Sep-2005 10:03:08.92 tcp_local + C TCP|MTArouter_IP|25|Clt_extMailserver_DNS_IP|1237 SMTP
21-Sep-2005 10:03:08.92 tcp_scan - O TCP|MTArouter_IP|37673|AVscanner_IP|10024 SMTP/[AVscanner_IP]/[AVscanner_IP]
21-Sep-2005 10:03:08.94 tcp_local + O TCP|MTArouter_IP|25|AVscanner_IP|13819 SMTP
21-Sep-2005 10:03:09.07 tcp_local + C TCP|MTArouter_IP|25|AVscanner_IP|13819 SMTP
21-Sep-2005 10:03:09.21 tcp_scan D 2 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_scan/017/ZZ0IN50010E9P8VL.00 <[email protected]> *[email protected] [AVscanner_IP] dns;[AVscanner_IP] (TCP|MTArouter_IP|37673|AVscanner_IP|10024) (pxmta -- Server ESMTP [iPlanet Messaging Server 5.2 HotFix 2.07 [built Jun 24 2005]]) smtp;250 2.1.5 [email protected] and options OK.
21-Sep-2005 10:03:09.21 > Received: from rgandhi (Clt_extMailserver [Clt_extMailserver_DNS_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTPA id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:03:08 +0800 (SGT)
21-Sep-2005 10:03:09.23 tcp_local + O TCP|MTArouter_IP|25|AVscanner_IP|13820 SMTP
21-Sep-2005 10:03:09.23 tcp_scan - C TCP|MTArouter_IP|37673|AVscanner_IP|10024 SMTP/[AVscanner_IP]/[AVscanner_IP]
21-Sep-2005 10:03:09.33 tcp_noscan tcp_intranet E 3 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_intranet/008/ZZ0IN50010J9P9VL.00 <[email protected]> mailsrv logserver (logserver [AVscanner_IP])
21-Sep-2005 10:03:09.33 > Received:      from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]);     Tue, 20 Sep 2005 02:02:51 +0000
21-Sep-2005 10:03:09.33 > Received: from rgandhi (Clt_extMailserver [Clt_extMailserver_DNS_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTPA id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:03:08 +0800 (SGT)
21-Sep-2005 10:03:09.34 tcp_intranet - O TCP|MTA_IP|37675|STORE_IP|25 SMTP/mailserver.mail.com/mailserver.mail.com
21-Sep-2005 10:03:09.37 tcp_intranet D 3 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_intranet/008/ZZ0IN50010J9P9VL.00 <[email protected]> mailsrv mailserver.mail.com dns;mailserver.mail.com (TCP|MTA_IP|37675|STORE_IP|25) (mailserver -- Server ESMTP [iPlanet Messaging Server 5.2 HotFix 2.07 [built Jun 24 2005]]) smtp;250 2.1.5 @mailserver.mail.com:[email protected] and options OK.
21-Sep-2005 10:03:09.37 > Received: from logserver (logserver [AVscanner_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:03:09 +0800 (SGT)
21-Sep-2005 10:03:09.37 > Received: from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]); Tue, 20 Sep 2005 02:02:51 +0000
21-Sep-2005 10:03:09.37 > Received: from rgandhi (Clt_extMailserver [Clt_extMailserver_DNS_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTPA id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:03:08 +0800 (SGT)
21-Sep-2005 10:03:09.37 tcp_intranet - C TCP|MTA_IP|37675|STORE_IP|25 SMTP/mailserver.mail.com/mailserver.mail.com
21-Sep-2005 10:03:09.47 tcp_local + C TCP|MTArouter_IP|25|AVscanner_IP|13820 SMTP
On Store
===========
20-Sep-2005 10:00:53.56 tcp_local + O TCP|STORE_IP|25|MTA_IP|37675 SMTP
20-Sep-2005 10:00:53.58 tcp_local ims-ms E 3 [email protected] rfc822;[email protected] preetam%beta.sg@ims-ms-daemon /iplanet/iMS52/msg-mailserver/imta/queue/ims-ms/013/ZZ0IN30070CEXHHR.00 <[email protected]> mailsrv pxmta (pxmta [MTA_IP])
20-Sep-2005 10:00:53.58 > Received: from logserver (logserver [AVscanner_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:03:09 +0800 (SGT)
20-Sep-2005 10:00:53.58 > Received: from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]); Tue, 20 Sep 2005 02:02:51 +0000
20-Sep-2005 10:00:53.58 > Received: from rgandhi (rgandhi.sgp.tsi [10.25.105.77]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTPA id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:03:08 +0800 (SGT)
20-Sep-2005 10:00:53.58 tcp_local + C TCP|STORE_IP|25|MTA_IP|37675 SMTP
20-Sep-2005 10:00:53.60 ims-ms D 3 [email protected] rfc822;[email protected] preetam%beta.sg@ims-ms-daemon /iplanet/iMS52/msg-mailserver/imta/queue/ims-ms/013/ZZ0IN30070CEXHHR.00 <[email protected]> mailsrv
20-Sep-2005 10:00:53.60 > Return-path: <[email protected]>
20-Sep-2005 10:00:53.60 > Received: from pxmta (pxmta [MTA_IP]) by mailserver.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected]; Tue, 20 Sep 2005 10:00:53 +0800 (SGT)
20-Sep-2005 10:00:53.60 > Received: from logserver (logserver [AVscanner_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:03:09 +0800 (SGT)
20-Sep-2005 10:00:53.60 > Received: from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]); Tue, 20 Sep 2005 02:02:51 +0000
20-Sep-2005 10:00:53.60 > Received: from rgandhi (rgandhi.sgp.tsi [10.25.105.77]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTPA id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:03:08 +0800 (SGT)
========================================================
Mail from USER [email protected] --> [email protected]
========================================================
On MTA
=======
21-Sep-2005 10:11:33.97 tcp_local + O TCP|MTArouter_IP|25|Clt_extMailserver_DNS_IP|1312 SMTP
21-Sep-2005 10:11:36.36 tcp_local tcp_scan E 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_scan/019/ZZ0IN50010OA3CVL.01 <[email protected]> mailsrv RGANDHI.test.com (Clt_extMailserver [Clt_extMailserver_DNS_IP])
21-Sep-2005 10:11:36.36 > Received: from rgandhi ([Clt_extMailserver_DNS_IP]) by test.com with MailEnable ESMTP; Tue, 20 Sep 2005 10:11:32 +0800
21-Sep-2005 10:11:36.36 tcp_local + C TCP|MTArouter_IP|25|Clt_extMailserver_DNS_IP|1312 SMTP
21-Sep-2005 10:11:36.51 tcp_scan - O TCP|MTArouter_IP|37702|AVscanner_IP|10024 SMTP/[AVscanner_IP]/[AVscanner_IP]
21-Sep-2005 10:11:36.54 tcp_local + O TCP|MTArouter_IP|25|AVscanner_IP|13919 SMTP
21-Sep-2005 10:11:36.81 tcp_local + C TCP|MTArouter_IP|25|AVscanner_IP|13919 SMTP
21-Sep-2005 10:11:39.41 tcp_scan D 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_scan/019/ZZ0IN50010OA3CVL.01 <[email protected]> mailsrv [AVscanner_IP] dns;[AVscanner_IP] (TCP|MTArouter_IP|37702|AVscanner_IP|10024) (pxmta -- Server ESMTP [iPlanet Messaging Server 5.2 HotFix 2.07 [built Jun 24 2005]]) smtp;250 2.1.5 [email protected] and options OK.
21-Sep-2005 10:11:39.41 > Received: from RGANDHI.test.com (Clt_extMailserver [Clt_extMailserver_DNS_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:11:36 +0800 (SGT)
21-Sep-2005 10:11:39.41 > Received: from rgandhi ([Clt_extMailserver_DNS_IP]) by test.com with MailEnable ESMTP; Tue, 20 Sep 2005 10:11:32 +0800
21-Sep-2005 10:11:39.42 tcp_local + O TCP|MTArouter_IP|25|AVscanner_IP|13920 SMTP
21-Sep-2005 10:11:39.44 tcp_scan - C TCP|MTArouter_IP|37702|AVscanner_IP|10024 SMTP/[AVscanner_IP]/[AVscanner_IP]
21-Sep-2005 10:11:41.96 tcp_noscan tcp_intranet E 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_intranet/015/ZZ0IN50010UA3HVL.00 <[email protected]> mailsrv logserver (logserver [AVscanner_IP])
21-Sep-2005 10:11:41.96 > Received:      from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]);     Tue, 20 Sep 2005 02:11:19 +0000
21-Sep-2005 10:11:41.96 > Received: from RGANDHI.test.com (Clt_extMailserver [Clt_extMailserver_DNS_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:11:36 +0800 (SGT)
21-Sep-2005 10:11:41.96 > Received: from rgandhi ([Clt_extMailserver_DNS_IP]) by test.com with MailEnable ESMTP; Tue, 20 Sep 2005 10:11:32 +0800
21-Sep-2005 10:11:41.99 tcp_local + C TCP|MTArouter_IP|25|AVscanner_IP|13920 SMTP
21-Sep-2005 10:11:42.13 tcp_intranet - O TCP|MTA_IP|37709|STORE_IP|25 SMTP/mailserver.mail.com/mailserver.mail.com
21-Sep-2005 10:11:42.59 tcp_intranet D 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_intranet/015/ZZ0IN50010UA3HVL.00 <[email protected]> mailsrv mailserver.mail.com dns;mailserver.mail.com (TCP|MTA_IP|37709|STORE_IP|25) (mailserver -- Server ESMTP [iPlanet Messaging Server 5.2 HotFix 2.07 [built Jun 24 2005]]) smtp;250 2.1.5 @mailserver.mail.com:[email protected] and options OK.
21-Sep-2005 10:11:42.59 > Received: from logserver (logserver [AVscanner_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:11:41 +0800 (SGT)
21-Sep-2005 10:11:42.59 > Received: from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]); Tue, 20 Sep 2005 02:11:19 +0000
21-Sep-2005 10:11:42.59 > Received: from RGANDHI.test.com (Clt_extMailserver [Clt_extMailserver_DNS_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:11:36 +0800 (SGT)
21-Sep-2005 10:11:42.59 > Received: from rgandhi ([Clt_extMailserver_DNS_IP]) by test.com with MailEnable ESMTP; Tue, 20 Sep 2005 10:11:32 +0800
21-Sep-2005 10:11:42.59 tcp_intranet - C TCP|MTA_IP|37709|STORE_IP|25 SMTP/mailserver.mail.com/mailserver.mail.com
On Store
==========
20-Sep-2005 10:09:26.34 tcp_local + O TCP|STORE_IP|25|MTA_IP|37709 SMTP
20-Sep-2005 10:09:26.79 tcp_local ims-ms E 493 [email protected] rfc822;[email protected] preetam%beta.sg@ims-ms-daemon /iplanet/iMS52/msg-mailserver/imta/queue/ims-ms/003/ZZ0IN30070GFBQHR.00 <[email protected]> mailsrv pxmta (pxmta [MTA_IP])
20-Sep-2005 10:09:26.79 > Received: from logserver (logserver [AVscanner_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:11:41 +0800 (SGT)
20-Sep-2005 10:09:26.79 > Received: from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]); Tue, 20 Sep 2005 02:11:19 +0000
20-Sep-2005 10:09:26.79 > Received: from RGANDHI.test.com (rgandhi.sgp.tsi [10.25.105.77]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:11:36 +0800 (SGT)
20-Sep-2005 10:09:26.79 > Received: from rgandhi ([10.25.105.77]) by test.com with MailEnable ESMTP; Tue, 20 Sep 2005 10:11:32 +0800
20-Sep-2005 10:09:26.80 tcp_local + C TCP|STORE_IP|25|MTA_IP|37709 SMTP
20-Sep-2005 10:09:27.17 ims-ms D 493 [email protected] rfc822;[email protected] preetam%beta.sg@ims-ms-daemon /iplanet/iMS52/msg-mailserver/imta/queue/ims-ms/003/ZZ0IN30070GFBQHR.00 <[email protected]> mailsrv
20-Sep-2005 10:09:27.17 > Return-path: <[email protected]>
20-Sep-2005 10:09:27.17 > Received: from pxmta (pxmta [MTA_IP]) by mailserver.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected]; Tue, 20 Sep 2005 10:09:26 +0800 (SGT)
20-Sep-2005 10:09:27.17 > Received: from logserver (logserver [AVscanner_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:11:41 +0800 (SGT)
20-Sep-2005 10:09:27.17 > Received: from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]); Tue, 20 Sep 2005 02:11:19 +0000
20-Sep-2005 10:09:27.17 > Received: from RGANDHI.test.com (rgandhi.sgp.tsi [10.25.105.77]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:11:36 +0800 (SGT)
20-Sep-2005 10:09:27.17 > Received: from rgandhi ([10.25.105.77]) by test.com with MailEnable ESMTP; Tue, 20 Sep 2005 10:11:32 +0800
========================================================
Mail from USER [email protected] --> [email protected]
========================================================
On MTA
=======
21-Sep-2005 10:12:48.69 tcp_local + O TCP|MTArouter_IP|25|Clt_extMailserver_DNS_IP|1326 SMTP
21-Sep-2005 10:12:48.74 tcp_local + C TCP|MTArouter_IP|25|Clt_extMailserver_DNS_IP|1326 SMTP
21-Sep-2005 10:12:53.89 tcp_local + O TCP|MTArouter_IP|25|Clt_extMailserver_DNS_IP|1327 SMTP
21-Sep-2005 10:12:53.95 tcp_auth tcp_scan EA 3 [email protected] rfc822;[email protected] [email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_scan/013/ZZ0IN50010ZA5HVL.01 <[email protected]> *[email protected] rgandhi (Clt_extMailserver [Clt_extMailserver_DNS_IP])
21-Sep-2005 10:12:53.95 tcp_scan - O TCP|MTArouter_IP|37718|AVscanner_IP|10024 SMTP/[AVscanner_IP]/[AVscanner_IP]
21-Sep-2005 10:12:53.96 tcp_auth tcp_scan EA 3 [email protected] rfc822;[email protected] [email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_scan/015/ZZ0IN500110A5HVL.00 <[email protected]> *[email protected] rgandhi (Clt_extMailserver [Clt_extMailserver_DNS_IP])
21-Sep-2005 10:12:53.96 tcp_local + C TCP|MTArouter_IP|25|Clt_extMailserver_DNS_IP|1327 SMTP
21-Sep-2005 10:12:53.97 tcp_scan - O TCP|MTArouter_IP|37719|AVscanner_IP|10024 SMTP/[AVscanner_IP]/[AVscanner_IP]
21-Sep-2005 10:12:53.97 tcp_local + O TCP|MTArouter_IP|25|AVscanner_IP|13930 SMTP
21-Sep-2005 10:12:54.01 tcp_local + O TCP|MTArouter_IP|25|AVscanner_IP|13931 SMTP
21-Sep-2005 10:12:54.16 tcp_local + C TCP|MTArouter_IP|25|AVscanner_IP|13930 SMTP
21-Sep-2005 10:12:54.64 tcp_local + C TCP|MTArouter_IP|25|AVscanner_IP|13931 SMTP
21-Sep-2005 10:12:54.64 tcp_scan D 3 [email protected] rfc822;[email protected] maile

These are the logs
External Users/Domains: [email protected], [email protected]
Internal Users/Domains: [email protected], [email protected], [email protected]
These are hosted on iplanet...
Alternate Conversion channel approach is used as per Chad's PDF
----AVBOX------------------MTA---------------EXTMAILSVR
............................................|
............................................|
........................................Store/Dir Server
==============================================
Mail from USER hasan -> preetam & nasarullah
==============================================
ON MTA
========
21-Sep-2005 10:02:51.24 tcp_local + O TCP|MTArouter_IP|25|Clt_extMailserver_DNS_IP|1233 SMTP
21-Sep-2005 10:02:59.50 tcp_local tcp_scan E 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_scan/004/ZZ0IN5001059OZVL.00 <[email protected]> mailsrv rgandhi (Clt_extMailserver [Clt_extMailserver_DNS_IP])
21-Sep-2005 10:02:59.50 tcp_local tcp_scan E 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_scan/004/ZZ0IN5001059OZVL.00 <[email protected]> mailsrv rgandhi (Clt_extMailserver [Clt_extMailserver_DNS_IP])
21-Sep-2005 10:02:59.50 > Date: Tue, 20 Sep 2005 10:02:51 +0800
21-Sep-2005 10:02:59.50 > From: "hasan" <[email protected]>
21-Sep-2005 10:02:59.50 > Subject: Attachment
21-Sep-2005 10:02:59.50 > To: "nasarullah" <[email protected]>
21-Sep-2005 10:02:59.50 > Cc: <[email protected]>
21-Sep-2005 10:02:59.50 > Message-id: <[email protected]>
21-Sep-2005 10:02:59.50 > MIME-version: 1.0
21-Sep-2005 10:02:59.50 > X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
21-Sep-2005 10:02:59.50 > X-Mailer: Microsoft Outlook Express 6.00.2900.2180
21-Sep-2005 10:02:59.50 > Content-type: multipart/mixed;     boundary="----=_NextPart_000_0021_01C5BDCA.76179E70"
21-Sep-2005 10:02:59.50 > X-Priority: 3
21-Sep-2005 10:02:59.50 > X-MSMail-priority: Normal
21-Sep-2005 10:02:59.54 tcp_local + C TCP|MTArouter_IP|25|Clt_extMailserver_DNS_IP|1233 SMTP
21-Sep-2005 10:02:59.80 tcp_scan - O TCP|MTArouter_IP|37666|AVscanner_IP|10024 SMTP/[AVscanner_IP]/[AVscanner_IP]
21-Sep-2005 10:02:59.82 tcp_local + O TCP|MTArouter_IP|25|AVscanner_IP|13816 SMTP
21-Sep-2005 10:02:59.97 tcp_local + C TCP|MTArouter_IP|25|AVscanner_IP|13816 SMTP
21-Sep-2005 10:03:03.23 tcp_scan D 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_scan/004/ZZ0IN5001059OZVL.00 <[email protected]> mailsrv [AVscanner_IP] dns;[AVscanner_IP] (TCP|MTArouter_IP|37666|AVscanner_IP|10024) (pxmta -- Server ESMTP [iPlanet Messaging Server 5.2 HotFix 2.07 [built Jun 24 2005]]) smtp;250 2.1.5 [email protected] and options OK.
21-Sep-2005 10:03:03.23 tcp_scan D 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_scan/004/ZZ0IN5001059OZVL.00 <[email protected]> mailsrv [AVscanner_IP] dns;[AVscanner_IP] (TCP|MTArouter_IP|37666|AVscanner_IP|10024) (pxmta -- Server ESMTP [iPlanet Messaging Server 5.2 HotFix 2.07 [built Jun 24 2005]]) smtp;250 2.1.5 [email protected] and options OK.
21-Sep-2005 10:03:03.23 > Received: from rgandhi (Clt_extMailserver [Clt_extMailserver_DNS_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with SMTP id <[email protected]>; Wed, 21 Sep 2005 10:02:59 +0800 (SGT)
21-Sep-2005 10:03:03.23 > Date: Tue, 20 Sep 2005 10:02:51 +0800
21-Sep-2005 10:03:03.23 > From: hasan <[email protected]>
21-Sep-2005 10:03:03.23 > Subject: Attachment
21-Sep-2005 10:03:03.23 > To: nasarullah <[email protected]>
21-Sep-2005 10:03:03.23 > Cc: [email protected]
21-Sep-2005 10:03:03.23 > Message-id: <[email protected]>
21-Sep-2005 10:03:03.23 > MIME-version: 1.0
21-Sep-2005 10:03:03.23 > X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
21-Sep-2005 10:03:03.23 > X-Mailer: Microsoft Outlook Express 6.00.2900.2180
21-Sep-2005 10:03:03.23 > Content-type: multipart/mixed; boundary="----=_NextPart_000_0021_01C5BDCA.76179E70"
21-Sep-2005 10:03:03.23 > X-Priority: 3
21-Sep-2005 10:03:03.23 > X-MSMail-priority: Normal
21-Sep-2005 10:03:03.24 tcp_local + O TCP|MTArouter_IP|25|AVscanner_IP|13818 SMTP
21-Sep-2005 10:03:03.25 tcp_scan - C TCP|MTArouter_IP|37666|AVscanner_IP|10024 SMTP/[AVscanner_IP]/[AVscanner_IP]
21-Sep-2005 10:03:05.84 tcp_noscan tcp_intranet E 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_intranet/004/ZZ0IN50010B9P5VL.00 <[email protected]> mailsrv logserver (logserver [AVscanner_IP])
21-Sep-2005 10:03:05.84 tcp_noscan tcp_intranet E 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_intranet/004/ZZ0IN50010B9P5VL.00 <[email protected]> mailsrv logserver (logserver [AVscanner_IP])
21-Sep-2005 10:03:05.84 > Received:      from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]);     Tue, 20 Sep 2005 02:02:42 +0000
21-Sep-2005 10:03:05.84 > Received: from rgandhi (Clt_extMailserver [Clt_extMailserver_DNS_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with SMTP id <[email protected]>; Wed, 21 Sep 2005 10:02:59 +0800 (SGT)
21-Sep-2005 10:03:05.84 > Date: Tue, 20 Sep 2005 10:02:51 +0800
21-Sep-2005 10:03:05.84 > From: hasan <[email protected]>
21-Sep-2005 10:03:05.84 > Subject: Attachment
21-Sep-2005 10:03:05.84 > To: nasarullah <[email protected]>
21-Sep-2005 10:03:05.84 > Cc: [email protected]
21-Sep-2005 10:03:05.84 > Message-id: <[email protected]>
21-Sep-2005 10:03:05.84 > MIME-version: 1.0
21-Sep-2005 10:03:05.84 > X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
21-Sep-2005 10:03:05.84 > X-Mailer: Microsoft Outlook Express 6.00.2900.2180
21-Sep-2005 10:03:05.84 > Content-type: multipart/mixed; boundary="----=_NextPart_000_0021_01C5BDCA.76179E70"
21-Sep-2005 10:03:05.84 > X-Priority: 3
21-Sep-2005 10:03:05.84 > X-MSMail-priority: Normal
21-Sep-2005 10:03:05.88 tcp_local + C TCP|MTArouter_IP|25|AVscanner_IP|13818 SMTP
21-Sep-2005 10:03:06.07 tcp_intranet - O TCP|MTA_IP|37670|STORE_IP|25 SMTP/mailserver.mail.com/mailserver.mail.com
21-Sep-2005 10:03:07.02 tcp_intranet D 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_intranet/004/ZZ0IN50010B9P5VL.00 <[email protected]> mailsrv mailserver.mail.com dns;mailserver.mail.com (TCP|MTA_IP|37670|STORE_IP|25) (mailserver -- Server ESMTP [iPlanet Messaging Server 5.2 HotFix 2.07 [built Jun 24 2005]]) smtp;250 2.1.5 @mailserver.mail.com:[email protected] and options OK.
21-Sep-2005 10:03:07.02 tcp_intranet D 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_intranet/004/ZZ0IN50010B9P5VL.00 <[email protected]> mailsrv mailserver.mail.com dns;mailserver.mail.com (TCP|MTA_IP|37670|STORE_IP|25) (mailserver -- Server ESMTP [iPlanet Messaging Server 5.2 HotFix 2.07 [built Jun 24 2005]]) smtp;250 2.1.5 @mailserver.mail.com:[email protected] and options OK.
21-Sep-2005 10:03:07.02 > Received: from logserver (logserver [AVscanner_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]>; Wed, 21 Sep 2005 10:03:05 +0800 (SGT)
21-Sep-2005 10:03:07.02 > Received: from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]); Tue, 20 Sep 2005 02:02:42 +0000
21-Sep-2005 10:03:07.02 > Received: from rgandhi (Clt_extMailserver [Clt_extMailserver_DNS_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with SMTP id <[email protected]>; Wed, 21 Sep 2005 10:02:59 +0800 (SGT)
21-Sep-2005 10:03:07.02 > Date: Tue, 20 Sep 2005 10:02:51 +0800
21-Sep-2005 10:03:07.02 > From: hasan <[email protected]>
21-Sep-2005 10:03:07.02 > Subject: Attachment
21-Sep-2005 10:03:07.02 > To: nasarullah <[email protected]>
21-Sep-2005 10:03:07.02 > Cc: [email protected]
21-Sep-2005 10:03:07.02 > Message-id: <[email protected]>
21-Sep-2005 10:03:07.02 > MIME-version: 1.0
21-Sep-2005 10:03:07.02 > X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
21-Sep-2005 10:03:07.02 > X-Mailer: Microsoft Outlook Express 6.00.2900.2180
21-Sep-2005 10:03:07.02 > Content-type: multipart/mixed; boundary="----=_NextPart_000_0021_01C5BDCA.76179E70"
21-Sep-2005 10:03:07.02 > X-Priority: 3
21-Sep-2005 10:03:07.02 > X-MSMail-priority: Normal
21-Sep-2005 10:03:07.03 tcp_intranet - C TCP|MTA_IP|37670|STORE_IP|25 SMTP/mailserver.mail.com/mailserver.mail.com
On Store
=========
20-Sep-2005 10:00:50.29 tcp_local + O TCP|STORE_IP|25|MTA_IP|37670 SMTP
20-Sep-2005 10:00:51.23 tcp_local ims-ms E 493 [email protected] rfc822;[email protected] nasarullah%alpha.com@ims-ms-daemon /iplanet/iMS52/msg-mailserver/imta/queue/ims-ms/000/ZZ0IN300709EXEHR.00 <[email protected]> mailsrv pxmta (pxmta [MTA_IP])
20-Sep-2005 10:00:51.23 tcp_local ims-ms E 493 [email protected] rfc822;[email protected] preetam%beta.sg@ims-ms-daemon /iplanet/iMS52/msg-mailserver/imta/queue/ims-ms/000/ZZ0IN300709EXEHR.00 <[email protected]> mailsrv pxmta (pxmta [MTA_IP])
20-Sep-2005 10:00:51.23 > Received: from logserver (logserver [AVscanner_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]>; Wed, 21 Sep 2005 10:03:05 +0800 (SGT)
20-Sep-2005 10:00:51.23 > Received: from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]); Tue, 20 Sep 2005 02:02:42 +0000
20-Sep-2005 10:00:51.23 > Received: from rgandhi (rgandhi.sgp.tsi [10.25.105.77]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with SMTP id <[email protected]>; Wed, 21 Sep 2005 10:02:59 +0800 (SGT)
20-Sep-2005 10:00:51.23 > Date: Tue, 20 Sep 2005 10:02:51 +0800
20-Sep-2005 10:00:51.23 > From: hasan <[email protected]>
20-Sep-2005 10:00:51.23 > Subject: Attachment
20-Sep-2005 10:00:51.23 > To: nasarullah <[email protected]>
20-Sep-2005 10:00:51.23 > Cc: [email protected]
20-Sep-2005 10:00:51.23 > Message-id: <[email protected]>
20-Sep-2005 10:00:51.23 > MIME-version: 1.0
20-Sep-2005 10:00:51.23 > X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
20-Sep-2005 10:00:51.23 > X-Mailer: Microsoft Outlook Express 6.00.2900.2180
20-Sep-2005 10:00:51.23 > Content-type: multipart/mixed; boundary="----=_NextPart_000_0021_01C5BDCA.76179E70"
20-Sep-2005 10:00:51.23 > X-Priority: 3
20-Sep-2005 10:00:51.23 > X-MSMail-priority: Normal
20-Sep-2005 10:00:51.24 tcp_local + C TCP|STORE_IP|25|MTA_IP|37670 SMTP
20-Sep-2005 10:00:51.42 ims-ms D 493 [email protected] rfc822;[email protected] nasarullah%alpha.com@ims-ms-daemon /iplanet/iMS52/msg-mailserver/imta/queue/ims-ms/000/ZZ0IN300709EXEHR.00 <[email protected]> mailsrv
20-Sep-2005 10:00:51.42 ims-ms D 493 [email protected] rfc822;[email protected] preetam%beta.sg@ims-ms-daemon /iplanet/iMS52/msg-mailserver/imta/queue/ims-ms/000/ZZ0IN300709EXEHR.00 <[email protected]> mailsrv
20-Sep-2005 10:00:51.42 > Return-path: <[email protected]>
20-Sep-2005 10:00:51.42 > Received: from pxmta (pxmta [MTA_IP]) by mailserver.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]>; Tue, 20 Sep 2005 10:00:50 +0800 (SGT)
20-Sep-2005 10:00:51.42 > Received: from logserver (logserver [AVscanner_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]>; Wed, 21 Sep 2005 10:03:05 +0800 (SGT)
20-Sep-2005 10:00:51.42 > Received: from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]); Tue, 20 Sep 2005 02:02:42 +0000
20-Sep-2005 10:00:51.42 > Received: from rgandhi (rgandhi.sgp.tsi [10.25.105.77]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with SMTP id <[email protected]>; Wed, 21 Sep 2005 10:02:59 +0800 (SGT)
20-Sep-2005 10:00:51.42 > Date: Tue, 20 Sep 2005 10:02:51 +0800
20-Sep-2005 10:00:51.42 > From: hasan <[email protected]>
20-Sep-2005 10:00:51.42 > Subject: Attachment
20-Sep-2005 10:00:51.42 > To: nasarullah <[email protected]>
20-Sep-2005 10:00:51.42 > Cc: [email protected]
20-Sep-2005 10:00:51.42 > Message-id: <[email protected]>
20-Sep-2005 10:00:51.42 > MIME-version: 1.0
20-Sep-2005 10:00:51.42 > X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
20-Sep-2005 10:00:51.42 > X-Mailer: Microsoft Outlook Express 6.00.2900.2180
20-Sep-2005 10:00:51.42 > Content-type: multipart/mixed; boundary="----=_NextPart_000_0021_01C5BDCA.76179E70"
20-Sep-2005 10:00:51.42 > X-Priority: 3
20-Sep-2005 10:00:51.42 > X-MSMail-priority: Normal
========================================================
Mail from USER [email protected] -> [email protected]
========================================================
ON MTA
========
21-Sep-2005 10:03:08.68 tcp_local + O TCP|MTArouter_IP|25|Clt_extMailserver_DNS_IP|1237 SMTP
21-Sep-2005 10:03:08.91 tcp_auth tcp_scan EA 2 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_scan/017/ZZ0IN50010E9P8VL.00 <[email protected]> *[email protected] rgandhi (Clt_extMailserver [Clt_extMailserver_DNS_IP])
21-Sep-2005 10:03:08.92 tcp_local + C TCP|MTArouter_IP|25|Clt_extMailserver_DNS_IP|1237 SMTP
21-Sep-2005 10:03:08.92 tcp_scan - O TCP|MTArouter_IP|37673|AVscanner_IP|10024 SMTP/[AVscanner_IP]/[AVscanner_IP]
21-Sep-2005 10:03:08.94 tcp_local + O TCP|MTArouter_IP|25|AVscanner_IP|13819 SMTP
21-Sep-2005 10:03:09.07 tcp_local + C TCP|MTArouter_IP|25|AVscanner_IP|13819 SMTP
21-Sep-2005 10:03:09.21 tcp_scan D 2 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_scan/017/ZZ0IN50010E9P8VL.00 <[email protected]> *[email protected] [AVscanner_IP] dns;[AVscanner_IP] (TCP|MTArouter_IP|37673|AVscanner_IP|10024) (pxmta -- Server ESMTP [iPlanet Messaging Server 5.2 HotFix 2.07 [built Jun 24 2005]]) smtp;250 2.1.5 [email protected] and options OK.
21-Sep-2005 10:03:09.21 > Received: from rgandhi (Clt_extMailserver [Clt_extMailserver_DNS_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTPA id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:03:08 +0800 (SGT)
21-Sep-2005 10:03:09.23 tcp_local + O TCP|MTArouter_IP|25|AVscanner_IP|13820 SMTP
21-Sep-2005 10:03:09.23 tcp_scan - C TCP|MTArouter_IP|37673|AVscanner_IP|10024 SMTP/[AVscanner_IP]/[AVscanner_IP]
21-Sep-2005 10:03:09.33 tcp_noscan tcp_intranet E 3 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_intranet/008/ZZ0IN50010J9P9VL.00 <[email protected]> mailsrv logserver (logserver [AVscanner_IP])
21-Sep-2005 10:03:09.33 > Received:      from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]);     Tue, 20 Sep 2005 02:02:51 +0000
21-Sep-2005 10:03:09.33 > Received: from rgandhi (Clt_extMailserver [Clt_extMailserver_DNS_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTPA id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:03:08 +0800 (SGT)
21-Sep-2005 10:03:09.34 tcp_intranet - O TCP|MTA_IP|37675|STORE_IP|25 SMTP/mailserver.mail.com/mailserver.mail.com
21-Sep-2005 10:03:09.37 tcp_intranet D 3 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_intranet/008/ZZ0IN50010J9P9VL.00 <[email protected]> mailsrv mailserver.mail.com dns;mailserver.mail.com (TCP|MTA_IP|37675|STORE_IP|25) (mailserver -- Server ESMTP [iPlanet Messaging Server 5.2 HotFix 2.07 [built Jun 24 2005]]) smtp;250 2.1.5 @mailserver.mail.com:[email protected] and options OK.
21-Sep-2005 10:03:09.37 > Received: from logserver (logserver [AVscanner_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:03:09 +0800 (SGT)
21-Sep-2005 10:03:09.37 > Received: from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]); Tue, 20 Sep 2005 02:02:51 +0000
21-Sep-2005 10:03:09.37 > Received: from rgandhi (Clt_extMailserver [Clt_extMailserver_DNS_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTPA id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:03:08 +0800 (SGT)
21-Sep-2005 10:03:09.37 tcp_intranet - C TCP|MTA_IP|37675|STORE_IP|25 SMTP/mailserver.mail.com/mailserver.mail.com
21-Sep-2005 10:03:09.47 tcp_local + C TCP|MTArouter_IP|25|AVscanner_IP|13820 SMTP
On Store
===========
20-Sep-2005 10:00:53.56 tcp_local + O TCP|STORE_IP|25|MTA_IP|37675 SMTP
20-Sep-2005 10:00:53.58 tcp_local ims-ms E 3 [email protected] rfc822;[email protected] preetam%beta.sg@ims-ms-daemon /iplanet/iMS52/msg-mailserver/imta/queue/ims-ms/013/ZZ0IN30070CEXHHR.00 <[email protected]> mailsrv pxmta (pxmta [MTA_IP])
20-Sep-2005 10:00:53.58 > Received: from logserver (logserver [AVscanner_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:03:09 +0800 (SGT)
20-Sep-2005 10:00:53.58 > Received: from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]); Tue, 20 Sep 2005 02:02:51 +0000
20-Sep-2005 10:00:53.58 > Received: from rgandhi (rgandhi.sgp.tsi [10.25.105.77]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTPA id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:03:08 +0800 (SGT)
20-Sep-2005 10:00:53.58 tcp_local + C TCP|STORE_IP|25|MTA_IP|37675 SMTP
20-Sep-2005 10:00:53.60 ims-ms D 3 [email protected] rfc822;[email protected] preetam%beta.sg@ims-ms-daemon /iplanet/iMS52/msg-mailserver/imta/queue/ims-ms/013/ZZ0IN30070CEXHHR.00 <[email protected]> mailsrv
20-Sep-2005 10:00:53.60 > Return-path: <[email protected]>
20-Sep-2005 10:00:53.60 > Received: from pxmta (pxmta [MTA_IP]) by mailserver.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected]; Tue, 20 Sep 2005 10:00:53 +0800 (SGT)
20-Sep-2005 10:00:53.60 > Received: from logserver (logserver [AVscanner_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:03:09 +0800 (SGT)
20-Sep-2005 10:00:53.60 > Received: from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]); Tue, 20 Sep 2005 02:02:51 +0000
20-Sep-2005 10:00:53.60 > Received: from rgandhi (rgandhi.sgp.tsi [10.25.105.77]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTPA id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:03:08 +0800 (SGT)
========================================================
Mail from USER [email protected] --> [email protected]
========================================================
On MTA
=======
21-Sep-2005 10:11:33.97 tcp_local + O TCP|MTArouter_IP|25|Clt_extMailserver_DNS_IP|1312 SMTP
21-Sep-2005 10:11:36.36 tcp_local tcp_scan E 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_scan/019/ZZ0IN50010OA3CVL.01 <[email protected]> mailsrv RGANDHI.test.com (Clt_extMailserver [Clt_extMailserver_DNS_IP])
21-Sep-2005 10:11:36.36 > Received: from rgandhi ([Clt_extMailserver_DNS_IP]) by test.com with MailEnable ESMTP; Tue, 20 Sep 2005 10:11:32 +0800
21-Sep-2005 10:11:36.36 tcp_local + C TCP|MTArouter_IP|25|Clt_extMailserver_DNS_IP|1312 SMTP
21-Sep-2005 10:11:36.51 tcp_scan - O TCP|MTArouter_IP|37702|AVscanner_IP|10024 SMTP/[AVscanner_IP]/[AVscanner_IP]
21-Sep-2005 10:11:36.54 tcp_local + O TCP|MTArouter_IP|25|AVscanner_IP|13919 SMTP
21-Sep-2005 10:11:36.81 tcp_local + C TCP|MTArouter_IP|25|AVscanner_IP|13919 SMTP
21-Sep-2005 10:11:39.41 tcp_scan D 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_scan/019/ZZ0IN50010OA3CVL.01 <[email protected]> mailsrv [AVscanner_IP] dns;[AVscanner_IP] (TCP|MTArouter_IP|37702|AVscanner_IP|10024) (pxmta -- Server ESMTP [iPlanet Messaging Server 5.2 HotFix 2.07 [built Jun 24 2005]]) smtp;250 2.1.5 [email protected] and options OK.
21-Sep-2005 10:11:39.41 > Received: from RGANDHI.test.com (Clt_extMailserver [Clt_extMailserver_DNS_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:11:36 +0800 (SGT)
21-Sep-2005 10:11:39.41 > Received: from rgandhi ([Clt_extMailserver_DNS_IP]) by test.com with MailEnable ESMTP; Tue, 20 Sep 2005 10:11:32 +0800
21-Sep-2005 10:11:39.42 tcp_local + O TCP|MTArouter_IP|25|AVscanner_IP|13920 SMTP
21-Sep-2005 10:11:39.44 tcp_scan - C TCP|MTArouter_IP|37702|AVscanner_IP|10024 SMTP/[AVscanner_IP]/[AVscanner_IP]
21-Sep-2005 10:11:41.96 tcp_noscan tcp_intranet E 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_intranet/015/ZZ0IN50010UA3HVL.00 <[email protected]> mailsrv logserver (logserver [AVscanner_IP])
21-Sep-2005 10:11:41.96 > Received:      from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]);     Tue, 20 Sep 2005 02:11:19 +0000
21-Sep-2005 10:11:41.96 > Received: from RGANDHI.test.com (Clt_extMailserver [Clt_extMailserver_DNS_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:11:36 +0800 (SGT)
21-Sep-2005 10:11:41.96 > Received: from rgandhi ([Clt_extMailserver_DNS_IP]) by test.com with MailEnable ESMTP; Tue, 20 Sep 2005 10:11:32 +0800
21-Sep-2005 10:11:41.99 tcp_local + C TCP|MTArouter_IP|25|AVscanner_IP|13920 SMTP
21-Sep-2005 10:11:42.13 tcp_intranet - O TCP|MTA_IP|37709|STORE_IP|25 SMTP/mailserver.mail.com/mailserver.mail.com
21-Sep-2005 10:11:42.59 tcp_intranet D 492 [email protected] rfc822;[email protected] @mailserver.mail.com:[email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_intranet/015/ZZ0IN50010UA3HVL.00 <[email protected]> mailsrv mailserver.mail.com dns;mailserver.mail.com (TCP|MTA_IP|37709|STORE_IP|25) (mailserver -- Server ESMTP [iPlanet Messaging Server 5.2 HotFix 2.07 [built Jun 24 2005]]) smtp;250 2.1.5 @mailserver.mail.com:[email protected] and options OK.
21-Sep-2005 10:11:42.59 > Received: from logserver (logserver [AVscanner_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:11:41 +0800 (SGT)
21-Sep-2005 10:11:42.59 > Received: from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]); Tue, 20 Sep 2005 02:11:19 +0000
21-Sep-2005 10:11:42.59 > Received: from RGANDHI.test.com (Clt_extMailserver [Clt_extMailserver_DNS_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:11:36 +0800 (SGT)
21-Sep-2005 10:11:42.59 > Received: from rgandhi ([Clt_extMailserver_DNS_IP]) by test.com with MailEnable ESMTP; Tue, 20 Sep 2005 10:11:32 +0800
21-Sep-2005 10:11:42.59 tcp_intranet - C TCP|MTA_IP|37709|STORE_IP|25 SMTP/mailserver.mail.com/mailserver.mail.com
On Store
==========
20-Sep-2005 10:09:26.34 tcp_local + O TCP|STORE_IP|25|MTA_IP|37709 SMTP
20-Sep-2005 10:09:26.79 tcp_local ims-ms E 493 [email protected] rfc822;[email protected] preetam%beta.sg@ims-ms-daemon /iplanet/iMS52/msg-mailserver/imta/queue/ims-ms/003/ZZ0IN30070GFBQHR.00 <[email protected]> mailsrv pxmta (pxmta [MTA_IP])
20-Sep-2005 10:09:26.79 > Received: from logserver (logserver [AVscanner_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:11:41 +0800 (SGT)
20-Sep-2005 10:09:26.79 > Received: from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]); Tue, 20 Sep 2005 02:11:19 +0000
20-Sep-2005 10:09:26.79 > Received: from RGANDHI.test.com (rgandhi.sgp.tsi [10.25.105.77]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:11:36 +0800 (SGT)
20-Sep-2005 10:09:26.79 > Received: from rgandhi ([10.25.105.77]) by test.com with MailEnable ESMTP; Tue, 20 Sep 2005 10:11:32 +0800
20-Sep-2005 10:09:26.80 tcp_local + C TCP|STORE_IP|25|MTA_IP|37709 SMTP
20-Sep-2005 10:09:27.17 ims-ms D 493 [email protected] rfc822;[email protected] preetam%beta.sg@ims-ms-daemon /iplanet/iMS52/msg-mailserver/imta/queue/ims-ms/003/ZZ0IN30070GFBQHR.00 <[email protected]> mailsrv
20-Sep-2005 10:09:27.17 > Return-path: <[email protected]>
20-Sep-2005 10:09:27.17 > Received: from pxmta (pxmta [MTA_IP]) by mailserver.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected]; Tue, 20 Sep 2005 10:09:26 +0800 (SGT)
20-Sep-2005 10:09:27.17 > Received: from logserver (logserver [AVscanner_IP]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:11:41 +0800 (SGT)
20-Sep-2005 10:09:27.17 > Received: from pxmta (pxmta-out [])     by logserver-lan ([AVscanner_IP]); Tue, 20 Sep 2005 02:11:19 +0000
20-Sep-2005 10:09:27.17 > Received: from RGANDHI.test.com (rgandhi.sgp.tsi [10.25.105.77]) by pxmta.mail.com (iPlanet Messaging Server 5.2 HotFix 2.07 (built Jun 24 2005)) with ESMTP id <[email protected]> for [email protected] (ORCPT [email protected]); Wed, 21 Sep 2005 10:11:36 +0800 (SGT)
20-Sep-2005 10:09:27.17 > Received: from rgandhi ([10.25.105.77]) by test.com with MailEnable ESMTP; Tue, 20 Sep 2005 10:11:32 +0800
========================================================
Mail from USER [email protected] --> [email protected]
========================================================
On MTA
=======
21-Sep-2005 10:12:48.69 tcp_local + O TCP|MTArouter_IP|25|Clt_extMailserver_DNS_IP|1326 SMTP
21-Sep-2005 10:12:48.74 tcp_local + C TCP|MTArouter_IP|25|Clt_extMailserver_DNS_IP|1326 SMTP
21-Sep-2005 10:12:53.89 tcp_local + O TCP|MTArouter_IP|25|Clt_extMailserver_DNS_IP|1327 SMTP
21-Sep-2005 10:12:53.95 tcp_auth tcp_scan EA 3 [email protected] rfc822;[email protected] [email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_scan/013/ZZ0IN50010ZA5HVL.01 <[email protected]> *[email protected] rgandhi (Clt_extMailserver [Clt_extMailserver_DNS_IP])
21-Sep-2005 10:12:53.95 tcp_scan - O TCP|MTArouter_IP|37718|AVscanner_IP|10024 SMTP/[AVscanner_IP]/[AVscanner_IP]
21-Sep-2005 10:12:53.96 tcp_auth tcp_scan EA 3 [email protected] rfc822;[email protected] [email protected] /iplanet/iMS52/msg-pxmta/imta/queue/tcp_scan/015/ZZ0IN500110A5HVL.00 <[email protected]> *[email protected] rgandhi (Clt_extMailserver [Clt_extMailserver_DNS_IP])
21-Sep-2005 10:12:53.96 tcp_local + C TCP|MTArouter_IP|25|Clt_extMailserver_DNS_IP|1327 SMTP
21-Sep-2005 10:12:53.97 tcp_scan - O TCP|MTArouter_IP|37719|AVscanner_IP|10024 SMTP/[AVscanner_IP]/[AVscanner_IP]
21-Sep-2005 10:12:53.97 tcp_local + O TCP|MTArouter_IP|25|AVscanner_IP|13930 SMTP
21-Sep-2005 10:12:54.01 tcp_local + O TCP|MTArouter_IP|25|AVscanner_IP|13931 SMTP
21-Sep-2005 10:12:54.16 tcp_local + C TCP|MTArouter_IP|25|AVscanner_IP|13930 SMTP
21-Sep-2005 10:12:54.64 tcp_local + C TCP|MTArouter_IP|25|AVscanner_IP|13931 SMTP
21-Sep-2005 10:12:54.64 tcp_scan D 3 [email protected] rfc822;[email protected] maile

Similar Messages

  • Sophos AV max scanning size / timeout

    Hi,
    I haven't found any changeable settings for max. scanning size or scanning timeout on a S160 v7.1.3 with Sophos AV.
    In the GUI under "Security Services-->Anti-Maleware"  it shows  "Object Scanning Limits: Max. Object Size:  32 MB".
    I'm not able to change it. This parameter seems not to belong to the Sophos AV.
    I can change it only after enableing Webroot or McAfee first.
    The CLI has no commands for adjusting AV settings.
    How can I control the max. scanning size or scanning timeout with Sophos-AV?
    Has it fixed values for it?
    Does anyone have an idea, how it works?
    Kind regards,
    Manfred

    With administrator rights, the value should be editable.  The object size is applied to all scanners which have been licensed and enabled on the appliance.
    ~Tim

  • I have what appears to be a virus on my Mac namely MAL/FAK AV-OQ how can I remove it? I have only discovered after running SOPHOS anti virus software???

    I have what appears to be a virus on my mac namely MAL/FAK AV-OQ I only discovered it after installing SOPHOS anti virus software.
    I cannot remove it automatically with this software it says it has to be done manually.
    Where do I start???
    Help req'd urgently

    That is Windows malware, and cannot affect your Mac. See:
    http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Ma l~FakeAV-OQ.aspx
    It may be attached to an e-mail message or could be something that was copied over from a Windows machine via flash drive or something similar. If it is attached to an e-mail message, simply delete the e-mail. (Do not let Sophos, or any other anti-virus software, quarantine the message or attachment! That can corrupt the mailbox that the message resides in.) If it isn't an e-mail message, you can let Sophos quarantine and delete the file or you can delete it yourself.

  • I just downloaded an update and my sophos anti-virus is going beserk.  It will not allow me to remove the threat when I unlock the quarantine manager and I have no idea of what to do

    I just downloaded an update and my sophos anti-virus is going beserk.  It will not allow me to remove the threat manually when I unlock the quarantine manager and I have no idea of what to do.

    The malware it's finding is probably Windows malware attached to e-mail messages. What are the names of some of those things? Assuming they're not Mac malware, allowing Sophos (or any other anti-virus software) to remove them could cause problems. For example, if they're attached to e-mail, removing them improperly by simply deleting the message file will leave the malware on the e-mail server, and it may very well end up getting re-downloaded when your mail client syncs with the server. It may also corrupt the mailbox.
    If you actually ever see a malware name starting with MacOS or OSX (I forget which one Sophos uses), then you will need to worry, and should not assume that the malware can be completely removed by anti-virus software of any kind.

  • Why does Sophos Antivirus and Skype crash when starting up?

    Some apps like my Sophos Anti-virus and Skype have been crashing each time I try and open it. I could not find Sophos in safe-mode for some reason and was able to open Skype up in safe-mode; however, it does't work in normal mode still. Below is the crash report that I have when I try to open up Sophos. Any help is much appreciated. Thanks!
    Process:               SophosUIServer [1300]
    Path:                  /Library/Sophos Anti-Virus/SophosUIServer.app/Contents/MacOS/SophosUIServer
    Identifier:            SophosUIServer
    Version:               9.2.2 (???)
    Code Type:             X86 (Native)
    Parent Process:        ??? [1]
    Responsible:           SophosUIServer [1300]
    User ID:               502
    Date/Time:             2015-02-05 17:13:50.812 -0500
    OS Version:            Mac OS X 10.10.2 (14C109)
    Report Version:        11
    Anonymous UUID:        FD5DA797-05A7-CE4F-C1E7-E9D8B5903C7E
    Time Awake Since Boot: 1600 seconds
    Crashed Thread:        0  Dispatch queue: com.apple.main-thread
    Exception Type:        EXC_BAD_ACCESS (SIGSEGV)
    Exception Codes:       KERN_INVALID_ADDRESS at 0x0000000000000000
    VM Regions Near 0:
    -->
        __TEXT                 0000000000081000-000000000009d000 [  112K] r-x/rwx SM=COW  /Library/Sophos Anti-Virus/SophosUIServer.app/Contents/MacOS/SophosUIServer
    Thread 0 Crashed:: Dispatch queue: com.apple.main-thread
    0   com.apple.HIToolbox           0x91735383 GetEventDispatcherTarget + 0
    1   com.apple.AppKit               0x94bbb7bd NSApplicationLoad + 64
    2   com.sophos.ui                 0x0008286a -[UIServer backgroundServiceDidFinishLaunching:] + 34
    3   com.apple.Foundation           0x98c38213 __57-[NSNotificationCenter addObserver:selector:name:object:]_block_invoke + 50
    4   com.apple.CoreFoundation       0x99169714 __CFNOTIFICATIONCENTER_IS_CALLING_OUT_TO_AN_OBSERVER__ + 20
    5   com.apple.CoreFoundation       0x9904a451 _CFXNotificationPost + 3713
    6   com.apple.Foundation           0x98c26134 -[NSNotificationCenter postNotificationName:object:userInfo:] + 92
    7   com.apple.Foundation           0x98c449a2 -[NSNotificationCenter postNotificationName:object:] + 56
    8   com.sophos.macendpoint.SophosGenericsCore 0x000b6456 -[SGBackgroundService _finalizeLaunch] + 231
    9   com.sophos.macendpoint.SophosGenericsCore 0x000b67d7 __36-[SGBackgroundService _runWithArgs:]_block_invoke_0 + 318
    10  libdispatch.dylib             0x99ff20b5 dispatch_once_f + 251
    11  libdispatch.dylib             0x99ff30d8 dispatch_once + 31
    12  com.sophos.macendpoint.SophosGenericsCore 0x000b653b -[SGBackgroundService _runWithArgs:] + 101
    13  com.sophos.macendpoint.SophosGenericsCore 0x000b6bb1 SGBackgroundServiceMain + 753
    14  com.sophos.ui                 0x0008281b main + 125
    15  com.sophos.ui                 0x00082795 start + 53
    Thread 1:: Dispatch queue: com.apple.libdispatch-manager
    0   libsystem_kernel.dylib         0x906908ce kevent64 + 10
    1   libdispatch.dylib             0x99ff573f _dispatch_mgr_invoke + 245
    2   libdispatch.dylib             0x99ff53a2 _dispatch_mgr_thread + 52
    Thread 2:: Dispatch queue: com.apple.root.default-qos.overcommit
    0   libsystem_kernel.dylib         0x906899ce mach_msg_trap + 10
    1   libsystem_kernel.dylib         0x90688a70 mach_msg + 68
    2   libxpc.dylib                   0x99bc9b91 xpc_pipe_routine + 259
    3   libxpc.dylib                   0x99bd383b _xpc_interface_routine + 198
    4   libxpc.dylib                   0x99bd3b5e _xpc_domain_routine + 32
    5   libxpc.dylib                   0x99bd3cab _xpc_look_up_endpoint + 261
    6   libxpc.dylib                   0x99bcd91e _xpc_connection_bootstrap_look_up_slow + 357
    7   libxpc.dylib                   0x99bcd554 _xpc_connection_init + 845
    8   libxpc.dylib                   0x99bcd1fe _xpc_connection_resume_init + 14
    9   libdispatch.dylib             0x99ff5180 _dispatch_root_queue_drain + 898
    10  libdispatch.dylib             0x9a00463d _dispatch_worker_thread3 + 97
    11  libsystem_pthread.dylib       0x9000b1da _pthread_wqthread + 724
    12  libsystem_pthread.dylib       0x90008e2e start_wqthread + 30
    Thread 0 crashed with X86 Thread State (32-bit):
      eax: 0x00000000  ebx: 0xa0a46778  ecx: 0x33ef0135  edx: 0xa0916038
      edi: 0x94bbb78b  esi: 0x950816a1  ebp: 0xbff7f858  esp: 0xbff7f82c
       ss: 0x00000023  efl: 0x00010282  eip: 0x91735383   cs: 0x0000001b
       ds: 0x00000023   es: 0x00000023   fs: 0x00000000   gs: 0x0000000f
      cr2: 0x00000000
    Logical CPU:     2
    Error Code:      0x00000004
    Trap Number:     14
    Binary Images:
       0x81000 -    0x9cff3 +com.sophos.ui (9.2.2 - ???) <7F8903E8-0815-363F-B547-EF9910ABDDE3> /Library/Sophos Anti-Virus/SophosUIServer.app/Contents/MacOS/SophosUIServer
       0xb5000 -    0xb8ff7 +com.sophos.macendpoint.SophosGenericsCore (1.0 - 1) <189C07E2-8011-3EF9-86A9-5BBCA582D9A8> /Library/Frameworks/SophosGenericsCore.framework/Versions/A/SophosGenericsCore
       0xc2000 -    0xc3ffd +com.sophos.macendpoint.SophosGenericsCommon (1.0 - 1) <064CCC64-5AC1-308E-BBA4-5A8C7A72C7C4> /Library/Frameworks/SophosGenericsCommon.framework/Versions/A/SophosGenericsCom mon
       0xce000 -    0xdbfff  com.apple.Collaboration (71 - 71) <98E28676-C0F7-3FB1-8811-83B0FDD72CEE> /System/Library/Frameworks/Collaboration.framework/Versions/A/Collaboration
       0xe7000 -   0x34ffff  com.apple.AddressBook.framework (9.0 - 1563) <B350506E-C8A2-35BC-9391-E49096F91393> /System/Library/Frameworks/AddressBook.framework/Versions/A/AddressBook
      0x504000 -   0x535ffb  com.apple.securityinterface (10.0 - 55058) <95726911-E181-3115-8451-EE1FA35A2937> /System/Library/Frameworks/SecurityInterface.framework/Versions/A/SecurityInter face
      0x557000 -   0x562fff  com.apple.IntlPreferences (2.0 - 150.1) <D36A70DB-B54F-37A3-9F8D-2B7562B6FF59> /System/Library/PrivateFrameworks/IntlPreferences.framework/Versions/A/IntlPref erences
      0x56c000 -   0x58cffb  com.apple.addressbook.vCard (9.0 - 1563) <D2C15678-F4DC-3E12-9BD0-D3A439E9617A> /System/Library/PrivateFrameworks/vCard.framework/Versions/A/vCard
      0x5ac000 -   0x696ff7  com.apple.QuickLookUIFramework (5.0 - 675.13) <CB237A15-5CB5-38A8-91C1-DE32257B2D26> /System/Library/Frameworks/Quartz.framework/Versions/A/Frameworks/QuickLookUI.f ramework/Versions/A/QuickLookUI
      0x71b000 -   0x737ff7  com.apple.aps.framework (4.0 - 4.0) <115AA5F3-86DF-37AB-8546-3A63A3FD0507> /System/Library/PrivateFrameworks/ApplePushService.framework/Versions/A/ApplePu shService
      0x74f000 -   0x750ff7  com.apple.AddressBook.ContactsData (9.0 - 1563) <126E9B88-D396-3E63-B48C-B46F41296EC7> /System/Library/PrivateFrameworks/ContactsData.framework/Versions/A/ContactsDat a
      0x757000 -   0x765fff  com.apple.AddressBook.ContactsFoundation (9.0 - 1563) <6D7AED29-EA9A-36E6-826A-62A5EA01BE54> /System/Library/PrivateFrameworks/ContactsFoundation.framework/Versions/A/Conta ctsFoundation
      0x779000 -   0x783fff  com.apple.DirectoryService.Framework (10.10 - 187) <49B89287-2162-3B96-A7FC-987AB78DD611> /System/Library/Frameworks/DirectoryService.framework/Versions/A/DirectoryServi ce
      0x78e000 -   0x795ff3  com.apple.phonenumbers (1.1.1 - 105) <19A59F22-DD76-345E-AF7B-96405D71DB5A> /System/Library/PrivateFrameworks/PhoneNumbers.framework/Versions/A/PhoneNumber s
      0x79d000 -   0x79dfff  com.apple.quartzframework (1.5 - 1.5) <6D85B29E-D684-3DDE-8F02-D292D86A014F> /System/Library/Frameworks/Quartz.framework/Versions/A/Quartz
      0x7a0000 -   0x7a2ff7  com.apple.SafariServices.framework (10600 - 10600.3.18) <6375C6B2-6F73-3B05-ABB6-F2B7E76E0279> /System/Library/PrivateFrameworks/SafariServices.framework/Versions/A/SafariSer vices
      0x7aa000 -   0x80aff3  com.apple.QuickLookFramework (5.0 - 675.13) <B731ABD0-8B4A-350E-8EFF-5FD855622599> /System/Library/Frameworks/QuickLook.framework/Versions/A/QuickLook
      0x842000 -   0xdb5ff7  com.apple.QuartzComposer (5.1 - 325.1) <82DA95F6-1324-33A0-B253-3EBE1A3F5780> /System/Library/Frameworks/Quartz.framework/Versions/A/Frameworks/QuartzCompose r.framework/Versions/A/QuartzComposer
    0x101f000 -  0x10c9ff7  com.apple.PDFKit (3.1 - 3.1) <A580FC1A-7796-3D6C-8D50-DE1993AD7175> /System/Library/Frameworks/Quartz.framework/Versions/A/Frameworks/PDFKit.framew ork/Versions/A/PDFKit
    0x111a000 -  0x1140ff7  com.apple.quartzfilters (1.10.0 - 1.10.0) <5712F712-4A1C-35BF-AE1D-F55DA1D9877D> /System/Library/Frameworks/Quartz.framework/Versions/A/Frameworks/QuartzFilters .framework/Versions/A/QuartzFilters
    0x1161000 -  0x13ecfff  com.apple.imageKit (2.6.1 - 840) <41498F5D-1BEB-3426-9DE1-C2B78D6C423D> /System/Library/Frameworks/Quartz.framework/Versions/A/Frameworks/ImageKit.fram ework/Versions/A/ImageKit
    0x1596000 -  0x1599fff  com.apple.AppleSystemInfo (3.1 - 3.1) <F3BD3065-65F8-31BC-A01E-A922E51FAACD> /System/Library/PrivateFrameworks/AppleSystemInfo.framework/Versions/A/AppleSys temInfo
    0x15a1000 -  0x162bff3  com.apple.CorePDF (4.0 - 4) <DA26FFBC-901A-3EF5-AF2F-9699683CB185> /System/Library/PrivateFrameworks/CorePDF.framework/Versions/A/CorePDF
    0x166d000 -  0x1677fff  com.apple.DisplayServicesFW (2.9 - 372.1) <01C3D99D-7F75-3401-95E8-5175E028EE21> /System/Library/PrivateFrameworks/DisplayServices.framework/Versions/A/DisplayS ervices
    0x1681000 -  0x16d9ff3  com.apple.ImageCaptureCore (6.0 - 6.0) <FC5102A0-87F5-39F7-9725-0C74749BF918> /System/Library/Frameworks/ImageCaptureCore.framework/Versions/A/ImageCaptureCo re
    0x8febf000 - 0x8fef2e03  dyld (353.2.1) <06B1254D-9BB9-327C-BA15-8F18FFF97586> /usr/lib/dyld
    0x90008000 - 0x90010fff  libsystem_pthread.dylib (105.10.1) <4A229519-29A1-3ABF-8CEF-43BCE4ACDA06> /usr/lib/system/libsystem_pthread.dylib
    0x90011000 - 0x9004bfff  com.apple.AirPlaySupport (2.0 - 215.15) <A7147999-EE77-3BC9-BC26-506D026B5587> /System/Library/PrivateFrameworks/AirPlaySupport.framework/Versions/A/AirPlaySu pport
    0x9004c000 - 0x90060fff  com.apple.ImageCapture (9.0 - 9.0) <4B84B5D5-A5F3-3B35-93CE-568A73486B92> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/ImageCapture. framework/Versions/A/ImageCapture
    0x90061000 - 0x901a5fff  com.apple.ImageIO.framework (3.3.0 - 1232) <3C219D4C-9B88-3A4A-A266-AEA6C6495676> /System/Library/Frameworks/ImageIO.framework/Versions/A/ImageIO
    0x901a6000 - 0x90203ff3  com.apple.print.framework.PrintCore (10.0 - 451) <2563665B-7B7F-3B8A-83B1-E5AC8D389909> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ PrintCore.framework/Versions/A/PrintCore
    0x90204000 - 0x9036dfff  com.apple.avfoundation (2.0 - 889.102) <864AFE74-25CA-3704-9246-5BD9CB5AB360> /System/Library/Frameworks/AVFoundation.framework/Versions/A/AVFoundation
    0x9036e000 - 0x9041eff3  com.apple.Bluetooth (4.3.2 - 4.3.2f6) <FC787129-45BB-3B94-ACAD-A0CECEB77AEC> /System/Library/Frameworks/IOBluetooth.framework/Versions/A/IOBluetooth
    0x9041f000 - 0x90439ff7  liblzma.5.dylib (7) <D0BC984D-5B33-328C-8F1E-7E9C41813433> /usr/lib/liblzma.5.dylib
    0x9043a000 - 0x9043dfff  com.apple.xpc.ServiceManagement (1.0 - 1) <D0A00D0C-D37D-3CF1-9EE0-41A88BC112BB> /System/Library/Frameworks/ServiceManagement.framework/Versions/A/ServiceManage ment
    0x9043e000 - 0x90444ff7  libsystem_networkextension.dylib (167.1.10) <FC20E3AD-A53D-3346-AC71-829E82832AE8> /usr/lib/system/libsystem_networkextension.dylib
    0x90445000 - 0x9044dfff  libsystem_dnssd.dylib (561.1.1) <45CDAF46-03DE-33DB-A627-14F245993EF2> /usr/lib/system/libsystem_dnssd.dylib
    0x9044e000 - 0x90518ff7  com.apple.backup.framework (1.6.2 - 1.6.2) <AE8234C3-6BB3-317B-A4E7-EF3478445DFF> /System/Library/PrivateFrameworks/Backup.framework/Versions/A/Backup
    0x905a8000 - 0x905fdff7  com.apple.htmlrendering (77 - 1.1.4) <B85A63B9-C9DD-3ECC-B5DC-E12533C7FDF9> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/HTMLRendering .framework/Versions/A/HTMLRendering
    0x905fe000 - 0x90657ffb  libAVFAudio.dylib (118.3) <65762748-F772-3959-8D14-197AFB778132> /System/Library/Frameworks/AVFoundation.framework/Versions/A/Resources/libAVFAu dio.dylib
    0x90658000 - 0x9066bfff  com.apple.CoreBluetooth (1.0 - 1) <DF406F6F-C173-3598-8785-8A2014F770EF> /System/Library/Frameworks/CoreBluetooth.framework/Versions/A/CoreBluetooth
    0x9066c000 - 0x90675fff  libGFXShared.dylib (11.1.1) <9A7C1796-07E7-3856-8703-75559016EF98> /System/Library/Frameworks/OpenGL.framework/Versions/A/Libraries/libGFXShared.d ylib
    0x90676000 - 0x90695fff  libsystem_kernel.dylib (2782.10.72) <C88D4054-EF6D-31F9-A9DC-B74160B91C26> /usr/lib/system/libsystem_kernel.dylib
    0x90696000 - 0x90ac9ff3  com.apple.vision.FaceCore (3.1.6 - 3.1.6) <EF92C25B-3E33-379F-A862-75C2FCA8B386> /System/Library/PrivateFrameworks/FaceCore.framework/Versions/A/FaceCore
    0x90aca000 - 0x90ad1ff3  libunwind.dylib (35.3) <29D9343F-9A0A-3535-B0AE-E7CC761D95EE> /usr/lib/system/libunwind.dylib
    0x90ad2000 - 0x90be5fff  com.apple.MediaControlSender (2.0 - 215.15) <83A34306-9F4B-31B3-A395-3F3DF3F6BBED> /System/Library/PrivateFrameworks/MediaControlSender.framework/Versions/A/Media ControlSender
    0x90be6000 - 0x90be8ff7  libsystem_sandbox.dylib (358.1.1) <6031346B-57B0-36FB-911B-D355E1F98A9A> /usr/lib/system/libsystem_sandbox.dylib
    0x90be9000 - 0x90c08ffb  libresolv.9.dylib (57) <C2C3810A-A45E-3375-B41D-6E1BECE1BA3C> /usr/lib/libresolv.9.dylib
    0x90cab000 - 0x90cafff3  com.apple.TCC (1.0 - 1) <3E7036F2-9706-3116-8126-16F26AA2FC11> /System/Library/PrivateFrameworks/TCC.framework/Versions/A/TCC
    0x90cb0000 - 0x90cd9ff7  libsystem_info.dylib (459) <4F7A7111-7F0D-3891-9DC9-41F5D79949FE> /usr/lib/system/libsystem_info.dylib
    0x90d0f000 - 0x90d3bffb  libsandbox.1.dylib (358.1.1) <776BDC0D-F352-3F49-9B0A-8B6B0D164C6A> /usr/lib/libsandbox.1.dylib
    0x90d3c000 - 0x90da7ff7  com.apple.framework.CoreWiFi (3.0 - 300.4) <632A811D-4706-3ED7-85E3-DD2CDB47CF8F> /System/Library/PrivateFrameworks/CoreWiFi.framework/Versions/A/CoreWiFi
    0x90da8000 - 0x90dacffb  libcache.dylib (69) <55501A00-AF64-3554-8F46-8D5AFEDEC332> /usr/lib/system/libcache.dylib
    0x90dc5000 - 0x90ddcff3  libLinearAlgebra.dylib (1128) <B20FAAAA-1C76-3B20-B100-5FC90F7FE023> /System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.fr amework/Versions/A/libLinearAlgebra.dylib
    0x90ddd000 - 0x90e41ff7  com.apple.AE (681 - 681) <EEE62980-421B-33BD-BB88-6BDE269A3060> /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/AE.fram ework/Versions/A/AE
    0x90e42000 - 0x90eceff3  com.apple.PerformanceAnalysis (1.0 - 1) <7A9DD1C9-465D-37FA-957E-2B0F190CFC7C> /System/Library/PrivateFrameworks/PerformanceAnalysis.framework/Versions/A/Perf ormanceAnalysis
    0x90efd000 - 0x91072ff7  com.apple.QTKit (7.7.3 - 2890) <16C43187-DFFE-3BB3-AA2C-741FBEBB5585> /System/Library/Frameworks/QTKit.framework/Versions/A/QTKit
    0x91073000 - 0x910c9fff  libc++.1.dylib (120) <D8DE4962-66CD-3491-904E-9291EEE5E570> /usr/lib/libc++.1.dylib
    0x910ca000 - 0x910d4ffb  com.apple.audio.SoundManager (4.2 - 4.2) <4312D0A7-4B6F-3A1E-9A47-24C6E8C65E51> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/CarbonSound.f ramework/Versions/A/CarbonSound
    0x91107000 - 0x91109fff  libCVMSPluginSupport.dylib (11.1.1) <2AEAFC0D-982C-3E26-B50B-B6EB12FE71F4> /System/Library/Frameworks/OpenGL.framework/Versions/A/Libraries/libCVMSPluginS upport.dylib
    0x9110a000 - 0x9114affb  libGLImage.dylib (11.1.1) <B49A6796-40A3-33D0-8199-6AED149ADFDF> /System/Library/Frameworks/OpenGL.framework/Versions/A/Libraries/libGLImage.dyl ib
    0x9117f000 - 0x91567ff7  libLAPACK.dylib (1128) <4E3D1289-2C98-3E53-BB8D-AD911357FF66> /System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.fr amework/Versions/A/libLAPACK.dylib
    0x91568000 - 0x915afff3  com.apple.AppleJPEG (1.0 - 1) <C14A2B49-A664-3EDE-9B9B-6A678ED7F8DE> /System/Library/PrivateFrameworks/AppleJPEG.framework/Versions/A/AppleJPEG
    0x915b0000 - 0x915cdffb  com.apple.Ubiquity (1.3 - 313) <9ED23769-0725-3D4B-B7F4-AF08020D73C3> /System/Library/PrivateFrameworks/Ubiquity.framework/Versions/A/Ubiquity
    0x915ce000 - 0x91700ffb  com.apple.UIFoundation (1.0 - 1) <00A59CFF-A217-3998-B22E-6E452278A302> /System/Library/PrivateFrameworks/UIFoundation.framework/Versions/A/UIFoundatio n
    0x91701000 - 0x91ad9ff7  com.apple.HIToolbox (2.1.1 - 757.3) <642A3B29-036D-3A87-AC81-935843AB6A32> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/HIToolbox.fra mework/Versions/A/HIToolbox
    0x91ada000 - 0x91cd0fff  libicucore.A.dylib (531.31) <430BD572-4521-3C85-B815-56514F9E2BBF> /usr/lib/libicucore.A.dylib
    0x91cd1000 - 0x91d10fff  com.apple.NavigationServices (3.8 - 215.1) <46D8B66D-CB59-36F5-BD26-FD8309337BB3> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/NavigationSer vices.framework/Versions/A/NavigationServices
    0x91d11000 - 0x91d26ffb  com.apple.MultitouchSupport.framework (262.33.1 - 262.33.1) <E8AF5A36-89A1-38CC-9905-D74A692D0898> /System/Library/PrivateFrameworks/MultitouchSupport.framework/Versions/A/Multit ouchSupport
    0x91d27000 - 0x91d37fff  libGL.dylib (11.1.1) <244536CD-5B87-3A3E-AD68-03BF04BD2D33> /System/Library/Frameworks/OpenGL.framework/Versions/A/Libraries/libGL.dylib
    0x91d38000 - 0x91d78fff  libauto.dylib (186) <1609D0F9-6E3A-3C67-87EF-BB0BD93EDAC9> /usr/lib/libauto.dylib
    0x91d79000 - 0x91f682ef  libobjc.A.dylib (647) <7648C174-3098-3B26-AD20-490DBFFD5D4C> /usr/lib/libobjc.A.dylib
    0x92035000 - 0x920a9fff  com.apple.Heimdal (4.0 - 2.0) <5BB21A72-99E6-3079-824E-935AA93D3981> /System/Library/PrivateFrameworks/Heimdal.framework/Versions/A/Heimdal
    0x920aa000 - 0x920afff7  libcompiler_rt.dylib (35) <6630682F-AB76-3E55-BE51-0A3E61B6CFC2> /usr/lib/system/libcompiler_rt.dylib
    0x920b0000 - 0x920c2ff7  libsasl2.2.dylib (193) <B5813595-A89D-39D4-BB06-F6013D3BD98C> /usr/lib/libsasl2.2.dylib
    0x920c3000 - 0x920d6fff  libcmph.dylib (1) <2449B048-208E-36FB-9DFA-47E0F3BCF132> /usr/lib/libcmph.dylib
    0x920d7000 - 0x920ddff7  libsystem_trace.dylib (72.1.3) <E1985F9C-78FC-3098-8683-81F0DCEE54BB> /usr/lib/system/libsystem_trace.dylib
    0x920de000 - 0x92158fff  com.apple.ApplicationServices.ATS (360 - 375) <4052B5D1-5F16-315A-A03B-14F0A112FC18> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ ATS.framework/Versions/A/ATS
    0x92159000 - 0x9215cfff  libpam.2.dylib (20) <E2F34522-448A-3392-BC1D-6625BEB612B9> /usr/lib/libpam.2.dylib
    0x9215d000 - 0x921d3fff  com.apple.securityfoundation (6.0 - 55126) <E7CBF2F4-2A0E-3C82-BE84-E09D21772AFB> /System/Library/Frameworks/SecurityFoundation.framework/Versions/A/SecurityFoun dation
    0x921d4000 - 0x923d8ff3  com.apple.CFNetwork (720.2.4 - 720.2.4) <2BDDB692-8973-3B53-A53C-71D42BDBABBF> /System/Library/Frameworks/CFNetwork.framework/Versions/A/CFNetwork
    0x92692000 - 0x92694fff  libsystem_configuration.dylib (699.1.5) <76B9BA28-179E-34FA-B10B-E625022A29CB> /usr/lib/system/libsystem_configuration.dylib
    0x926ae000 - 0x926fffff  com.apple.opencl (2.4.2 - 2.4.2) <327699CD-6BF9-3B63-999E-A5A56014E540> /System/Library/Frameworks/OpenCL.framework/Versions/A/OpenCL
    0x92700000 - 0x92709ff7  libsystem_notify.dylib (133.1.1) <B8503E99-214B-3AC3-A7CA-CC837ABD7B25> /usr/lib/system/libsystem_notify.dylib
    0x9270a000 - 0x9298ffff  com.apple.QuickTime (7.7.3 - 2890) <34289D2B-07CC-3D12-8F32-6F97D96DEE81> /System/Library/Frameworks/QuickTime.framework/Versions/A/QuickTime
    0x92990000 - 0x92a86ff7  libxml2.2.dylib (26) <2F37833C-4D55-3A09-9A0C-5904E8B6892A> /usr/lib/libxml2.2.dylib
    0x92d26000 - 0x92d26fff  libunc.dylib (29) <CE960997-9D4A-3848-BAC7-B2255E6765FD> /usr/lib/system/libunc.dylib
    0x92d27000 - 0x92d3eff7  com.apple.CoreMediaAuthoring (2.2 - 951) <02B870F3-BA89-3CFD-95E2-39359DF39D68> /System/Library/PrivateFrameworks/CoreMediaAuthoring.framework/Versions/A/CoreM ediaAuthoring
    0x92d93000 - 0x92d9cfff  com.apple.DiskArbitration (2.6 - 2.6) <D906604A-1D8C-31BF-8F22-EA219FFC858F> /System/Library/Frameworks/DiskArbitration.framework/Versions/A/DiskArbitration
    0x92d9d000 - 0x92dc3ff7  com.apple.IconServices (47.1 - 47.1) <9C537499-B375-3F84-BF4A-EEF757FC26A9> /System/Library/PrivateFrameworks/IconServices.framework/Versions/A/IconService s
    0x92dc4000 - 0x92ec4ff7  com.apple.LaunchServices (644.12.4 - 644.12.4) <D41066A1-FC8B-34A2-A980-4B011AA77F38> /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/LaunchS ervices.framework/Versions/A/LaunchServices
    0x92ec5000 - 0x92ec5fff  libkeymgr.dylib (28) <06DDCEF8-EB84-3F68-9E19-FD1A12B764FD> /usr/lib/system/libkeymgr.dylib
    0x92ec6000 - 0x92ec6fff  liblaunch.dylib (559.10.3) <DF6BB29C-8F20-3E04-81FF-19FFBC82BD46> /usr/lib/system/liblaunch.dylib
    0x92ec7000 - 0x92ee2ff7  com.apple.CFOpenDirectory (10.10 - 187) <5302DBFA-92CE-349C-981C-2BF6E9BEEBB0> /System/Library/Frameworks/OpenDirectory.framework/Versions/A/Frameworks/CFOpen Directory.framework/Versions/A/CFOpenDirectory
    0x92ee3000 - 0x92eecfff  libcopyfile.dylib (118.1.2) <FAF3268F-C580-33D3-A5B4-74B8A8713216> /usr/lib/system/libcopyfile.dylib
    0x92eed000 - 0x92ef3ff7  com.apple.MediaAccessibility (1.0 - 61) <81E9530E-882C-313C-A4D5-2F43EB569E4F> /System/Library/Frameworks/MediaAccessibility.framework/Versions/A/MediaAccessi bility
    0x92ef4000 - 0x92f23ff7  com.apple.DictionaryServices (1.2 - 229) <1F5C35C7-67AA-30A0-A366-EB4B361152A3> /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/Diction aryServices.framework/Versions/A/DictionaryServices
    0x92f24000 - 0x92f43ff7  com.apple.GenerationalStorage (2.0 - 209.11) <34CF76B2-8052-359D-816D-092608FB6919> /System/Library/PrivateFrameworks/GenerationalStorage.framework/Versions/A/Gene rationalStorage
    0x92f44000 - 0x9337ffeb  com.apple.vImage (8.0 - 8.0) <56F6B317-9D70-3DC5-9868-BB6D7CB6E55D> /System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vImage.fr amework/Versions/A/vImage
    0x93380000 - 0x93391ff3  libsystem_coretls.dylib (35.1.2) <139ECDA3-8A63-3D18-96FC-6A10242B8F6B> /usr/lib/system/libsystem_coretls.dylib
    0x93630000 - 0x93632fff  libsystem_coreservices.dylib (9) <20E66A47-8D67-344A-A393-73926F0E5FB2> /usr/lib/system/libsystem_coreservices.dylib
    0x93633000 - 0x93635ffb  libRadiance.dylib (1232) <F16794FD-4326-32CD-A578-3B2ADB27587D> /System/Library/Frameworks/ImageIO.framework/Versions/A/Resources/libRadiance.d ylib
    0x93636000 - 0x93722fe7  libvMisc.dylib (516) <8575A3B5-F6FB-35BF-9E50-E81BD0813100> /System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.fr amework/Versions/A/libvMisc.dylib
    0x93723000 - 0x93725fff  com.apple.SecCodeWrapper (4.0 - 238.10.1) <0622F76C-3C56-3ABD-924E-FBC75E7E6445> /System/Library/PrivateFrameworks/SecCodeWrapper.framework/Versions/A/SecCodeWr apper
    0x93726000 - 0x93854fff  com.apple.coreui (2.1 - 305.6.1) <6535A234-0DFF-3467-837B-118E2C9D2875> /System/Library/PrivateFrameworks/CoreUI.framework/Versions/A/CoreUI
    0x93855000 - 0x9385efff  com.apple.AppleSRP (5.0 - 1) <41C48FA8-C249-3800-A551-7F4AFA3E723F> /System/Library/PrivateFrameworks/AppleSRP.framework/Versions/A/AppleSRP
    0x9385f000 - 0x93b5dff7  com.apple.CoreServices.CarbonCore (1108.2 - 1108.2) <D3DD9764-A787-3B6B-9DAD-55CEED944DCF> /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/CarbonC ore.framework/Versions/A/CarbonCore
    0x93b5e000 - 0x93b69ff7  com.apple.NetAuth (5.0 - 5.0) <D6C31218-47E4-3553-9208-D1091A81044E> /System/Library/PrivateFrameworks/NetAuth.framework/Versions/A/NetAuth
    0x93b6a000 - 0x93b6afff  com.apple.Accelerate (1.10 - Accelerate 1.10) <C2367B5B-AE20-3084-A864-104743BE478E> /System/Library/Frameworks/Accelerate.framework/Versions/A/Accelerate
    0x93b6b000 - 0x93b8efff  libJPEG.dylib (1232) <C7B71F9A-E740-307B-A9FA-A83760EE747B> /System/Library/Frameworks/ImageIO.framework/Versions/A/Resources/libJPEG.dylib
    0x93b8f000 - 0x93b8ffff  com.apple.CoreServices (62 - 62) <FF296ED2-0F90-3055-BBE4-7BF9E42322EF> /System/Library/Frameworks/CoreServices.framework/Versions/A/CoreServices
    0x93b90000 - 0x93b93fff  libextension.dylib (55.1) <E0A4ADBE-596E-3363-8780-51D8AE39B755> /usr/lib/libextension.dylib
    0x93b94000 - 0x93badfff  libsystem_malloc.dylib (53.1.1) <58CD8BC7-55D1-3862-8E5D-728EE2EBE447> /usr/lib/system/libsystem_malloc.dylib
    0x93bae000 - 0x93c43fff  libsystem_c.dylib (1044.10.1) <584F66B1-ABBA-354C-8118-1DA5386A065E> /usr/lib/system/libsystem_c.dylib
    0x93c44000 - 0x93c99ff3  com.apple.audio.CoreAudio (4.3.0 - 4.3.0) <F5A586C3-A440-3E0E-966A-7841A182E5B2> /System/Library/Frameworks/CoreAudio.framework/Versions/A/CoreAudio
    0x93c9a000 - 0x93c9bfff  libsystem_blocks.dylib (65) <5D98F022-E863-31D4-8ADE-D53B2AE0D331> /usr/lib/system/libsystem_blocks.dylib
    0x93c9c000 - 0x93c9cfff  com.apple.Accelerate.vecLib (3.10 - vecLib 3.10) <F968D12F-F59D-3148-951D-76735C3C1B57> /System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.fr amework/Versions/A/vecLib
    0x93c9d000 - 0x93cd0fff  com.apple.CoreAVCHD (5.7.5 - 5750.4.1) <103A5EA0-9B75-3B23-BE72-C4DD52744A6A> /System/Library/PrivateFrameworks/CoreAVCHD.framework/Versions/A/CoreAVCHD
    0x93cd1000 - 0x93cdfff3  libxar.1.dylib (254) <D7C4FDEB-61AA-3FC1-8B7B-0AE3A3A64492> /usr/lib/libxar.1.dylib
    0x93ce0000 - 0x93d23fff  libGLU.dylib (11.1.1) <2DC476EE-5C4F-3353-A916-39F2FDB5D6B1> /System/Library/Frameworks/OpenGL.framework/Versions/A/Libraries/libGLU.dylib
    0x93d24000 - 0x941cbff7  com.apple.JavaScriptCore (10600 - 10600.3.13) <21BA75F3-8A70-3159-8696-7392EDEBEF70> /System/Library/Frameworks/JavaScriptCore.framework/Versions/A/JavaScriptCore
    0x94240000 - 0x94241fff  com.apple.TrustEvaluationAgent (2.0 - 25) <28BBD931-EF7C-3753-B50E-6568F4075086> /System/Library/PrivateFrameworks/TrustEvaluationAgent.framework/Versions/A/Tru stEvaluationAgent
    0x94242000 - 0x94246fff  libCoreVMClient.dylib (79) <85CBF1F3-3CE1-304F-88DF-15608C9A2367> /System/Library/Frameworks/OpenGL.framework/Versions/A/Libraries/libCoreVMClien t.dylib
    0x94247000 - 0x943d2ffb  com.apple.audio.toolbox.AudioToolbox (1.12 - 1.12) <44BCEAB8-306D-307F-92C8-6656F3578220> /System/Library/Frameworks/AudioToolbox.framework/Versions/A/AudioToolbox
    0x943d3000 - 0x943dfff3  libcommonCrypto.dylib (60061) <024B3913-15C6-3005-9E5A-EB24918F6977> /usr/lib/system/libcommonCrypto.dylib
    0x943e0000 - 0x943e3ff7  com.apple.help (1.3.3 - 46) <FDF183E4-3B95-3CBD-A390-2536C8E7E258> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/Help.framewor k/Versions/A/Help
    0x9440e000 - 0x94524ff7  com.apple.CoreText (352.0 - 454.3) <6448E389-AB2E-34EF-AE07-FE364ECC98E5> /System/Library/Frameworks/CoreText.framework/Versions/A/CoreText
    0x94525000 - 0x94532fff  com.apple.OpenDirectory (10.10 - 187) <14AA5E0C-238A-32C4-BAF3-81893750B5A9> /System/Library/Frameworks/OpenDirectory.framework/Versions/A/OpenDirectory
    0x94533000 - 0x94825ffb  com.apple.CoreImage (10.0.33) <75B23F45-8D99-3521-89AE-AF2AF4487096> /System/Library/Frameworks/QuartzCore.framework/Versions/A/Frameworks/CoreImage .framework/Versions/A/CoreImage
    0x94826000 - 0x9541bfff  com.apple.AppKit (6.9 - 1344.72) <B84FF828-3016-353A-BF86-C1547F448FB1> /System/Library/Frameworks/AppKit.framework/Versions/C/AppKit
    0x9541c000 - 0x95698ff7  com.apple.security (7.0 - 57031.10.10) <3EF32688-A176-33DD-BA59-25F37D6C08DA> /System/Library/Frameworks/Security.framework/Versions/A/Security
    0x95699000 - 0x9570fff7  com.apple.SearchKit (1.4.0 - 1.4.0) <B6F346D2-BF88-3925-B962-E59267FA2268> /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/SearchK it.framework/Versions/A/SearchKit
    0x95718000 - 0x9580fff7  libFontParser.dylib (134.1) <AF60B79A-410B-389E-9B24-09B5BC61E19F> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ ATS.framework/Versions/A/Resources/libFontParser.dylib
    0x95810000 - 0x95901ffb  libiconv.2.dylib (42) <4AF77F10-0BEC-3BE0-99DF-C5170EDB316B> /usr/lib/libiconv.2.dylib
    0x95902000 - 0x95903fff  libremovefile.dylib (35) <49DCAF7B-4466-3775-9E58-EA5D7CBA8AE0> /usr/lib/system/libremovefile.dylib
    0x95904000 - 0x9593eff7  com.apple.DebugSymbols (115 - 115) <D01FFA10-1734-31C5-B5A1-9CB61463FC15> /System/Library/PrivateFrameworks/DebugSymbols.framework/Versions/A/DebugSymbol s
    0x9593f000 - 0x95bd2fff  com.apple.CoreData (111 - 526.1) <74375077-8AE6-3D1B-B6A4-CF3B0724EB60> /System/Library/Frameworks/CoreData.framework/Versions/A/CoreData
    0x96557000 - 0x9655bffb  com.apple.IOSurface (97 - 97) <ADB57CD2-455A-317C-818E-6379BF427D10> /System/Library/Frameworks/IOSurface.framework/Versions/A/IOSurface
    0x9655c000 - 0x9658effb  com.apple.GSS (4.0 - 2.0) <680D3014-D2C6-30D4-9892-93B9E4172100> /System/Library/Frameworks/GSS.framework/Versions/A/GSS
    0x9658f000 - 0x96598ffb  com.apple.CommonAuth (4.0 - 2.0) <FFE760A3-FEF7-3009-92E8-893ABB3BC91A> /System/Library/PrivateFrameworks/CommonAuth.framework/Versions/A/CommonAuth
    0x96599000 - 0x9659afff  libSystem.B.dylib (1213) <BFFB2AB8-29F6-3779-B358-EE1F46520FC8> /usr/lib/libSystem.B.dylib
    0x9659b000 - 0x9661afff  com.apple.SystemConfiguration (1.14 - 1.14) <21296E7B-11A3-35C0-BDC7-838392DE8298> /System/Library/Frameworks/SystemConfiguration.framework/Versions/A/SystemConfi guration
    0x9661b000 - 0x9699eff7  com.apple.VideoToolbox (1.0 - 1562.107) <D9840509-340B-3503-BD58-4907AC4AAA51> /System/Library/Frameworks/VideoToolbox.framework/Versions/A/VideoToolbox
    0x969a2000 - 0x969f6fff  com.apple.HIServices (1.22 - 520.12) <8950B516-7DFD-3154-B34F-067809086832> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ HIServices.framework/Versions/A/HIServices
    0x969f7000 - 0x96a34ff7  libsystem_network.dylib (411.1) <EB71DD61-9515-3F6C-817E-25AF7F108CB8> /usr/lib/system/libsystem_network.dylib
    0x96b94000 - 0x96b9aff3  libsystem_platform.dylib (63) <509993B7-3F26-3360-B899-0BBB15152516> /usr/lib/system/libsystem_platform.dylib
    0x96b9b000 - 0x96c35fff  com.apple.ColorSync (4.9.0 - 4.9.0) <091CDCEC-1B25-3FE7-94C2-8AEFA6564E95> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ ColorSync.framework/Versions/A/ColorSync
    0x97be7000 - 0x97c3afff  com.apple.CoreMediaIO (601.0 - 4749) <0A48F432-BEB4-3420-B156-12F576A6C0FD> /System/Library/Frameworks/CoreMediaIO.framework/Versions/A/CoreMediaIO
    0x97c3b000 - 0x97ca4ff7  libcorecrypto.dylib (233.1.2) <F188C1A7-E88F-3EC5-A6AA-22C02E3F0C93> /usr/lib/system/libcorecrypto.dylib
    0x985b5000 - 0x985e4fff  com.apple.CoreVideo (1.8 - 145.1) <A59466FC-6B5A-3B36-BDD4-AC9CD581B7A1> /System/Library/Frameworks/CoreVideo.framework/Versions/A/CoreVideo
    0x985e5000 - 0x985e5fff  libOpenScriptingUtil.dylib (162) <9872C464-DF90-37C2-9871-8A3F53C615EC> /usr/lib/libOpenScriptingUtil.dylib
    0x985e6000 - 0x985edfff  com.apple.speech.recognition.framework (5.0.9 - 5.0.9) <5D268178-3812-3777-92A6-D7D3395405B8> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/SpeechRecogni tion.framework/Versions/A/SpeechRecognition
    0x985ee000 - 0x98614ffb  libPng.dylib (1232) <576BCAB6-DBE2-36DB-A390-E945FC844118> /System/Library/Frameworks/ImageIO.framework/Versions/A/Resources/libPng.dylib
    0x98615000 - 0x9869cfff  com.apple.CoreServices.OSServices (640.3 - 640.3) <C53DBDE3-F9E0-3B90-963E-0FAEEF3DA225> /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/OSServi ces.framework/Versions/A/OSServices
    0x9869d000 - 0x986abff7  com.apple.SpeechRecognitionCore (2.0.32 - 2.0.32) <637E7AB2-1077-319C-A6A2-D0D0F01951BA> /System/Library/PrivateFrameworks/SpeechRecognitionCore.framework/Versions/A/Sp eechRecognitionCore
    0x986ac000 - 0x9870cfff  com.apple.AppleVAFramework (5.0.31 - 5.0.31) <45401678-26FE-3EFD-B1A1-88864B470871> /System/Library/PrivateFrameworks/AppleVA.framework/Versions/A/AppleVA
    0x987fe000 - 0x98800fff  com.apple.securityhi (9.0 - 55006) <5AF7E054-F6A1-38B4-B403-BAF8BE4DBA35> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/SecurityHI.fr amework/Versions/A/SecurityHI
    0x9882b000 - 0x9882bfff  com.apple.Cocoa (6.8 - 21) <6AF80DDB-C28E-36FF-BC11-D7D561AC52A9> /System/Library/Frameworks/Cocoa.framework/Versions/A/Cocoa
    0x9882c000 - 0x98c22ff3  com.apple.CoreGraphics (1.600.0 - 775.16) <5F7BDB0B-5324-3B7A-BC6B-E7A01A880D94> /System/Library/Frameworks/CoreGraphics.framework/Versions/A/CoreGraphics
    0x98c23000 - 0x98f82ffb  com.apple.Foundation (6.9 - 1152.14) <F74F139D-8789-3B60-ADF6-AB6F39444AC4> /System/Library/Frameworks/Foundation.framework/Versions/C/Foundation
    0x98f83000 - 0x9902bff7  com.apple.CoreMedia (1.0 - 1562.107) <A175F33D-8502-3D36-8C9C-0D74BA904CF2> /System/Library/Frameworks/CoreMedia.framework/Versions/A/CoreMedia
    0x9902c000 - 0x9903aff7  libz.1.dylib (55) <DF3B8F77-8931-3A6B-8BDF-DB67315050E6> /usr/lib/libz.1.dylib
    0x9903b000 - 0x993edff7  com.apple.CoreFoundation (6.9 - 1152) <93C32AF9-FD62-3DBD-85F7-35727E6CAA55> /System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation
    0x993ee000 - 0x99503ffb  com.apple.desktopservices (1.9.2 - 1.9.2) <DCA5B074-BD3C-35E9-BF11-628019FE3CC0> /System/Library/PrivateFrameworks/DesktopServicesPriv.framework/Versions/A/Desk topServicesPriv
    0x99504000 - 0x99504fff  com.apple.ApplicationServices (48 - 48) <76C301A4-705B-33DE-BA11-C89DCF1EDCDD> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Application Services
    0x99505000 - 0x9950cfff  com.apple.XPCService (2.0 - 1) <9A59D63D-446A-33A4-BB21-56E42417DA93> /System/Library/PrivateFrameworks/XPCService.framework/Versions/A/XPCService
    0x9950d000 - 0x99515ffb  com.apple.NetFS (6.0 - 4.0) <141BFE7E-634E-32A0-8EC9-0A1A4DFEA7D9> /System/Library/Frameworks/NetFS.framework/Versions/A/NetFS
    0x99516000 - 0x9952dffb  com.apple.AppContainer (4.0 - 238.10.1) <76D88956-AF52-35AA-8213-9B6285B623CD> /System/Library/PrivateFrameworks/AppContainer.framework/Versions/A/AppContaine r
    0x9952e000 - 0x99554ff3  libc++abi.dylib (125) <E9AF8CA1-D54D-37E3-8363-A3E8C0840F71> /usr/lib/libc++abi.dylib
    0x99555000 - 0x99564ff3  com.apple.opengl (11.1.1 - 11.1.1) <212B409C-AF1E-3C69-B4AA-57A39C35BB62> /System/Library/Frameworks/OpenGL.framework/Versions/A/OpenGL
    0x99565000 - 0x9964ffff  libcrypto.0.9.8.dylib (52.10.1) <DD3EA46B-C906-39AA-848E-7C7240EB31F9> /usr/lib/libcrypto.0.9.8.dylib
    0x99650000 - 0x9965bff7  com.apple.AppSandbox (4.0 - 238.10.1) <89DA7A61-B7F6-3365-8D49-65FA766EF720> /System/Library/PrivateFrameworks/AppSandbox.framework/Versions/A/AppSandbox
    0x9965c000 - 0x99bb8ff3  com.apple.MediaToolbox (1.0 - 1562.107) <AA1B8DFA-C1C3-3610-BBFD-3C26E063168F> /System/Library/Frameworks/MediaToolbox.framework/Versions/A/MediaToolbox
    0x99bb9000 - 0x99bc4ff7  com.apple.CrashReporterSupport (10.10 - 629) <BA5611B6-EF99-3A44-90DD-3305FDA4975E> /System/Library/PrivateFrameworks/CrashReporterSupport.framework/Versions/A/Cra shReporterSupport
    0x99bc5000 - 0x99bebffb  libxpc.dylib (559.10.3) <6C4CEB0F-0044-3B62-A286-5693C3FD239E> /usr/lib/system/libxpc.dylib
    0x99bfa000 - 0x99c4bfff  libcups.2.dylib (408) <08C5D411-533C-345A-B820-092C96215F2E> /usr/lib/libcups.2.dylib
    0x99c4c000 - 0x99d50ff7  libJP2.dylib (1232) <CD0012B6-D649-327B-B7FA-E52B0FC0067C> /System/Library/Frameworks/ImageIO.framework/Versions/A/Resources/libJP2.dylib
    0x99d51000 - 0x99d8dff3  com.apple.RemoteViewServices (2.0 - 99) <2839C2F1-88DA-3843-87BF-441A374A8967> /System/Library/PrivateFrameworks/RemoteViewServices.framework/Versions/A/Remot eViewServices
    0x99d91000 - 0x99d93ffb  libsystem_secinit.dylib (18) <3CBA3BD3-8BA2-358D-BD1A-A1C3DF5D84E6> /usr/lib/system/libsystem_secinit.dylib
    0x99d94000 - 0x99f23ff3  libsqlite3.dylib (168) <C3F78985-C19B-3320-9F71-543969632128> /usr/lib/libsqlite3.dylib
    0x99f24000 - 0x99f28fff  libheimdal-asn1.dylib (398.10.1) <6F113AF8-F5AD-330B-B029-F7AF28A93F28> /usr/lib/libheimdal-asn1.dylib
    0x99f29000 - 0x99f36ff7  com.apple.speech.synthesis.framework (5.3.3 - 5.3.3) <EB79D0BE-75B8-3570-9D91-AE07E42611BD> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ SpeechSynthesis.framework/Versions/A/SpeechSynthesis
    0x99f37000 - 0x99f3efff  libMatch.1.dylib (24) <428CD037-5261-39A6-83EE-A7D9ABF446EB> /usr/lib/libMatch.1.dylib
    0x99f3f000 - 0x99f73ffb  com.apple.frameworks.CoreDaemon (1.3 - 1.3) <F527DB82-0D3F-359E-979B-951DFF46D45C> /System/Library/PrivateFrameworks/CoreDaemon.framework/Versions/B/CoreDaemon
    0x99f74000 - 0x99fbdffb  libFontRegistry.dylib (134) <023BB8A2-8BBA-30DC-B0C2-A5F0AE3667D8> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ ATS.framework/Versions/A/Resources/libFontRegistry.dylib
    0x99fbe000 - 0x99fecff7  libarchive.2.dylib (30) <8758D35F-ADF8-30F6-8EB2-9B852876EAC8> /usr/lib/libarchive.2.dylib
    0x99fed000 - 0x99ff0fff  libdyld.dylib (353.2.1) <3E28E996-50B8-388B-8885-7299FBC978B1> /usr/lib/system/libdyld.dylib
    0x99ff1000 - 0x9a018fff  libdispatch.dylib (442.1.4) <B26A176C-39F7-3362-B128-27B1211068B9> /usr/lib/system/libdispatch.dylib
    0x9a02b000 - 0x9a03dfff  com.apple.Sharing (328.3.2 - 328.3.2) <4F0D4D68-B6A6-3E66-8A89-CDD9AFEA82EA> /System/Library/PrivateFrameworks/Sharing.framework/Versions/A/Sharing
    0x9a061000 - 0x9a08dfff  com.apple.ChunkingLibrary (2.1 - 163.1) <2B0CBB85-EF91-351A-8750-A185996E4CDB> /System/Library/PrivateFrameworks/ChunkingLibrary.framework/Versions/A/Chunking Library
    0x9a097000 - 0x9a0c1fff  libxslt.1.dylib (13) <0F55B64A-6C55-304E-ACE0-B531027AA066> /usr/lib/libxslt.1.dylib
    0x9a0c2000 - 0x9a0c4fff  com.apple.loginsupport (1.0 - 1) <8B651D8C-53D0-314D-BDD6-74147C4B2E73> /System/Library/PrivateFrameworks/login.framework/Versions/A/Frameworks/loginsu pport.framework/Versions/A/loginsupport
    0x9a1fd000 - 0x9a270ffb  com.apple.framework.CoreWLAN (5.0 - 500.35.2) <22CC0615-70EF-3155-8410-A1427793DBBC> /System/Library/Frameworks/CoreWLAN.framework/Versions/A/CoreWLAN
    0x9a271000 - 0x9a272fff  libDiagnosticMessagesClient.dylib (100) <3EE83437-AA9C-356B-810B-589346B73797> /usr/lib/libDiagnosticMessagesClient.dylib
    0x9a273000 - 0x9a2adfff  com.apple.LDAPFramework (2.4.28 - 194.5) <C3BD6DBA-5EE4-3992-A013-CF5333AAB648> /System/Library/Frameworks/LDAP.framework/Versions/A/LDAP
    0x9a2b3000 - 0x9a30efff  com.apple.LanguageModeling (1.0 - 1) <9B39E059-F48E-31AF-B1B3-B0872F362627> /System/Library/PrivateFrameworks/LanguageModeling.framework/Versions/A/Languag eModeling
    0x9a314000 - 0x9a316fff  libquarantine.dylib (76) <9ADD861F-A66E-3AD1-A77E-C622E91BD203> /usr/lib/system/libquarantine.dylib
    0x9a3d7000 - 0x9a40afe3  libsystem_m.dylib (3086.1) <951F633F-57B7-398B-912F-F6ED4DB1C597> /usr/lib/system/libsystem_m.dylib
    0x9a674000 - 0x9a67cfff  com.apple.CoreServices.FSEvents (1210 - 1210) <FC372799-6E8E-3290-9816-6981D39BC9D6> /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/FSEvent s.framework/Versions/A/FSEvents
    0x9a68b000 - 0x9a6e6ffb  libTIFF.dylib (1232) <E5A82202-E766-32DE-9706-86B3B2B73731> /System/Library/Frameworks/ImageIO.framework/Versions/A/Resources/libTIFF.dylib
    0x9a6e7000 - 0x9a784fff  com.apple.ink.framework (10.9 - 213) <F47949BC-ABEE-329B-B568-71C6FEF761F6> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/Ink.framework /Versions/A/Ink
    0x9a78e000 - 0x9a792ffb  libGIF.dylib (1232) <037E01F1-885C-3F4A-A353-87DB1F9CB504> /System/Library/Frameworks/ImageIO.framework/Versions/A/Resources/libGIF.dylib
    0x9a793000 - 0x9a798fff  com.apple.print.framework.Print (10.0 - 265) <7C3984BB-8337-3B90-A414-17C181A45744> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/Print.framewo rk/Versions/A/Print
    0x9a799000 - 0x9a816ff3  com.apple.framework.IOKit (2.0.2 - 1050.10.8) <60574F96-1CD6-34B8-A862-EA977FD058BF> /System/Library/Frameworks/IOKit.framework/Versions/A/IOKit
    0x9b1c6000 - 0x9b1cbff7  libmacho.dylib (862) <48DE74F8-09E3-344F-A82F-665083A3BF8F> /usr/lib/system/libmacho.dylib
    0x9b1cc000 - 0x9b243fff  com.apple.CoreUtils (1.0 - 101.1) <7169E4D1-0771-36AD-85C8-60CF37FFF16E> /System/Library/PrivateFrameworks/CoreUtils.framework/Versions/A/CoreUtils
    0x9b244000 - 0x9b2d6fff  com.apple.CoreSymbolication (3.1 - 57020) <EAC6745A-AB1D-38CC-A12C-99ECD8F071ED> /System/Library/PrivateFrameworks/CoreSymbolication.framework/Versions/A/CoreSy mbolication
    0x9b2d7000 - 0x9b2f4fff  libCRFSuite.dylib (34) <781A92EF-410E-39B2-953D-FEE12748D834> /usr/lib/libCRFSuite.dylib
    0x9b2f5000 - 0x9b2f6fff  liblangid.dylib (117) <34A0F807-755F-300B-B01F-AABAE3838451> /usr/lib/liblangid.dylib
    0x9b304000 - 0x9b4c8ff3  com.apple.QuartzCore (1.10 - 361.15) <4DD4BF91-26D4-3325-BB42-9642318307FA> /System/Library/Frameworks/QuartzCore.framework/Versions/A/QuartzCore
    0x9b4c9000 - 0x9b509fff  com.apple.Symbolication (1.4 - 56045) <BE1C4846-DA11-365D-9B46-3FF130401839> /System/Library/PrivateFrameworks/Symbolication.framework/Versions/A/Symbolicat ion
    0x9b631000 - 0x9b648fff  libsystem_asl.dylib (267) <85BD88AD-618E-3325-AC31-10DBAB8E9AF3> /usr/lib/system/libsystem_asl.dylib
    0x9b649000 - 0x9b659ff7  com.apple.LangAnalysis (1.7.0 - 1.7.0) <DBECFAD5-DB53-390C-AE92-09549733C861> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ LangAnalysis.framework/Versions/A/LangAnalysis
    0x9b6ae000 - 0x9ba06ff7  libmecabra.dylib (666.2) <DB0D4D7E-AA7B-3D2D-8936-07F03038F4DF> /usr/lib/libmecabra.dylib
    0x9ba07000 - 0x9baadfff  com.apple.Metadata (10.7.0 - 917.1) <0B19C2DD-A71C-3D2B-AB00-68FFC6CC606A> /System/Library/Frameworks/CoreServices.framework/Versions/A/Frameworks/Metadat a.framework/Versions/A/Metadata
    0x9baae000 - 0x9babaff7  libkxld.dylib (2782.10.72) <FF699F52-D950-3DAD-A37B-834EBF0D0FFD> /usr/lib/system/libkxld.dylib
    0x9babb000 - 0x9baccfff  libbsm.0.dylib (34) <C9F0C608-2794-3F6B-8078-583FC0046039> /usr/lib/libbsm.0.dylib
    0x9bacd000 - 0x9bae6fff  com.apple.Kerberos (3.0 - 1) <92735F11-CF1C-3FA6-8682-9A30AC9E2651> /System/Library/Frameworks/Kerberos.framework/Versions/A/Kerberos
    0x9bae7000 - 0x9bc58ffb  libBLAS.dylib (1128) <ACEF468C-5DB1-38F3-BCB2-6F3D7F2B2040> /System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.fr amework/Versions/A/libBLAS.dylib
    0x9bc59000 - 0x9bc59fff  com.apple.Carbon (154 - 157) <514DC1B6-3D3B-3A96-814D-71D6E022CB3D> /System/Library/Frameworks/Carbon.framework/Versions/A/Carbon
    0x9bc5a000 - 0x9bc67ff7  libbz2.1.0.dylib (36) <6BC7B049-8F03-3217-9840-B1804CCBF742> /usr/lib/libbz2.1.0.dylib
    0x9bc68000 - 0x9bd08fff  com.apple.QD (301 - 301) <4DFE3689-59DE-3FBC-806B-6A4056573E52> /System/Library/Frameworks/ApplicationServices.framework/Versions/A/Frameworks/ QD.framework/Versions/A/QD
    0x9bd09000 - 0x9be16fe3  libvDSP.dylib (516) <53F7A960-01E1-3B79-A7FD-67BD19471420> /System/Library/Frameworks/Accelerate.framework/Versions/A/Frameworks/vecLib.fr amework/Versions/A/libvDSP.dylib
    0x9be17000 - 0x9c12bfef  com.apple.CoreAUC (211.0.0 - 211.0.0) <78C567D8-532D-3A08-BF7D-0C25A859F64A> /System/Library/PrivateFrameworks/CoreAUC.framework/Versions/A/CoreAUC
    0x9c12c000 - 0x9c150ffb  com.apple.framework.Apple80211 (10.1 - 1010.64) <377A2686-2C1F-3257-8420-37DB5C8F33AD> /System/Library/PrivateFrameworks/Apple80211.framework/Versions/A/Apple80211
    0x9c151000 - 0x9c1bdff3  com.apple.datadetectorscore (6.0 - 396.1.1) <93F59488-6CA9-3C90-8E96-B0DE5942252F> /System/Library/PrivateFrameworks/DataDetectorsCore.framework/Versions/A/DataDe tectorsCore
    0x9c1be000 - 0x9c1c2fff  com.apple.CommonPanels (1.2.6 - 96) <955375E6-2416-38E1-AFC6-477827119329> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/CommonPanels. framework/Versions/A/CommonPanels
    0x9c1c3000 - 0x9c1c3fff  com.apple.audio.units.AudioUnit (1.12 - 1.12) <64ED443E-25D5-3A2C-A028-0D0C7FAF57C6> /System/Library/Frameworks/AudioUnit.framework/Versions/A/AudioUnit
    0x9c375000 - 0x9c390ff3  com.apple.openscripting (1.4 - 162) <EB1D1BA6-C0B0-3D3B-AE54-676324FFF3E6> /System/Library/Frameworks/Carbon.framework/Versions/A/Frameworks/OpenScripting .framework/Versions/A/OpenScripting
    External Modification Summary:
      Calls made by other processes targeting this process:
        task_for_pid: 0
        thread_create: 0
        thread_set_state: 0
      Calls made by this process:
        task_for_pid: 0
        thread_create: 0
        thread_set_state: 0
      Calls made by all processes on this machine:
        task_for_pid: 992
        thread_create: 0
        thread_set_state: 0
    VM Region Summary:
    ReadOnly portion of Libraries: Total=190.3M resident=16.9M(9%) swapped_out_or_unallocated=173.4M(91%)
    Writable regions: Total=52.2M written=3012K(6%) resident=3712K(7%) swapped_out=0K(0%) unallocated=48.5M(93%)
    REGION TYPE                      VIRTUAL
    ===========                      =======
    Kernel Alloc Once                     4K
    MALLOC                             41.1M
    MALLOC (admin)                       48K
    Stack                              64.6M
    VM_ALLOCATE                          12K
    VM_ALLOCATE (reserved)               16K        reserved VM address space (unallocated)
    __DATA                             8628K
    __IMAGE                             528K
    __LINKEDIT                         46.7M
    __OBJC                             3812K
    __TEXT                            143.7M
    __UNICODE                           544K
    mapped file                        73.7M
    shared memory                         4K
    ===========                      =======
    TOTAL                             382.9M
    TOTAL, minus reserved VM space    382.9M

    Start time: 15:43:24 02/06/15
    Revision: 1206
    Model Identifier: MacBookPro9,2
    System Version: OS X 10.10.2 (14C109)
    Kernel Version: Darwin 14.1.0
    Time since boot: 22:57
    UID: 502
    I/O wait time (us/s)
       kextd (UID 0): 3609
       Terminal (UID 502): 3751
    File opens (per sec)
       ReportCrash (UID 502) => /usr/lib (status 2): 5
       ReportCrash (UID 502) => /usr/lib (status 0): 6
       ReportCrash (UID 502) => /usr/lib/system (status 0): 7
       ReportCrash (UID 502) => /usr/lib/system (status 2): 7
    System errors (per sec)
       Google Chrome (UID 502, error 35): 189
       ReportCrash (UID 502, error 2): 221
       Google Chrome H (UID 502, error 35): 288
    Firewall: On
    DNS: 192.--.--.--
    TCP/IP
       Subnet mask: 255.---.---.-
    Listeners
       cupsd: ipp
       kdc: kerberos
       launchd: afpovertcp
       launchd: printer
    System caches/logs
       1203 MB: /System/Library/Caches/com.apple.coresymbolicationd/data
    Diagnostic reports
       1 2015-02-05 Safari hang
       2 2015-02-05 Skype crash
       2 2015-02-05 Sophos Anti-Virus crash
       19 2015-02-05 SophosUIServer crash
       1 2015-02-05 Spotify Helper crash
       1 2015-02-05 SpotifyWebHelper crash
       1 2015-02-05 TOCGenerator crash
       20 2015-02-05 mdworker32 crash
       1 2015-02-05 steamclean crash
       1 2015-02-05 uninstaller_macosr crash
       39 2015-02-06 BBLaunchAgent.app crash
       3 2015-02-06 CS5ServiceManager crash
       10 2015-02-06 GoogleSoftwareUpdateAgent crash
       3 2015-02-06 HP Scheduler crash
       1 2015-02-06 Install Adobe Reader crash
       40 2015-02-06 LogMeIn Hamachi Menubar crash
       1 2015-02-06 Microsoft Error Reporting crash
       2 2015-02-06 PluginProcess crash
       6 2015-02-06 Skype crash
       1 2015-02-06 Sophos Anti-Virus crash
       20 2015-02-06 SophosUIServer crash
       4 2015-02-06 SpotifyWebHelper crash
       2 2015-02-06 mdworker32 crash
       1 2015-02-06 steam_osx crash
       4 2015-02-06 steamclean crash
    I/O errors
       disk1: 8
    Volumes
       disk1: /
    Log
       Feb  5 23:15:14 memorystatus_thread: idle exiting pid 9123 [findmydeviced]
       Feb  5 23:15:15 memorystatus_thread: idle exiting pid 9126 [nsurlstoraged]
       Feb  5 23:15:16 memorystatus_thread: idle exiting pid 9127 [lsuseractivityd]
       Feb  5 23:15:17 memorystatus_thread: idle exiting pid 7396 [tccd]
       Feb  5 23:15:18 memorystatus_thread: idle exiting pid 7368 [com.apple.CodeSi]
       Feb  5 23:15:19 memorystatus_thread: idle exiting pid 7382 [diagnosticd]
       Feb  5 23:15:20 memorystatus_thread: idle exiting pid 9132 [secinitd]
       Feb  5 23:15:21 memorystatus_thread: idle exiting pid 9130 [backupd-helper]
       Feb  5 23:15:22 memorystatus_thread: idle exiting pid 9131 [soagent]
       Feb  5 23:15:23 memorystatus_thread: idle exiting pid 7366 [cfprefsd]
       Feb  5 23:15:24 memorystatus_thread: idle exiting pid 7370 [coresymbolicatio]
       Feb  5 23:15:25 memorystatus_thread: idle exiting pid 7363 [coreduetd]
       Feb  5 23:15:26 memorystatus_thread: idle exiting pid 9136 [nsurlstoraged]
       Feb  5 23:15:27 memorystatus_thread: idle exiting pid 9137 [findmydeviced]
       Feb  5 23:15:28 memorystatus_thread: idle exiting pid 9138 [lsuseractivityd]
       Feb  5 23:15:29 memorystatus_thread: idle exiting pid 7374 [cfprefsd]
       Feb  5 23:15:30 memorystatus_thread: idle exiting pid 9141 [com.apple.CodeSi]
       Feb  5 23:15:31 memorystatus_thread: idle exiting pid 9142 [diagnosticd]
       Feb  5 23:15:32 memorystatus_thread: idle exiting pid 9143 [nsurlstoraged]
       Feb  5 23:15:33 memorystatus_thread: idle exiting pid 9144 [backupd-helper]
       Feb  5 23:15:34 memorystatus_thread: idle exiting pid 9145 [systemstatsd]
       Feb  5 23:15:35 memorystatus_thread: idle exiting pid 9147 [secinitd]
       Feb  5 23:15:36 memorystatus_thread: idle exiting pid 9149 [tccd]
       Feb  6 09:28:23 pci pause: SDXC
       Feb  6 13:38:37 pci pause: SDXC
    Daemons
       com.adobe.SwitchBoard
       com.adobe.fpsaud
       com.allocinit.camtwist.dal
       com.apple.Kerberos.kdc
       - status: 1
       com.apple.aelwriter
       com.apple.installer.osmessagetracing
       com.logmein.hamachi
       com.microsoft.office.licensing.helper
       com.rim.BBDaemon
       com.rogueamoeba.hermes
       jp.co.canon.MasterInstaller
    Agents
       com.adobe.AAM.Scheduler-1.0
       com.adobe.ARM.UUID
       com.adobe.CS5ServiceManager
       - status: -11
       com.apple.AirPortBaseStationAgent
       com.apple.MailServiceAgent
       - status: -9
       com.apple.internetaccounts
       - status: -9
       com.google.keystone.user.agent
       - status: -11
       com.hp.help.tocgenerator
       - status: -11
       com.logmein.hamachimb
       - status: -11
       com.rim.BBLaunchAgent
       - status: -11
       com.spotify.webhelper
       - status: -11
       com.valvesoftware.steam.ipctool
       com.valvesoftware.steamclean
       - status: -11
    User overrides
       jp.co.canon.Inkjet_Extended_Survey_Agent
    Startup items
       /Library/StartupItems/HP IO/HP IO
       /Library/StartupItems/HP IO/Resources/version.plist
       /Library/StartupItems/HP IO/StartupParameters.plist
    Global login items
       /Applications/Kodak Share Button.app/Contents/MacOS/Kodak Share Button Agent.app
       /Library/Application Support/Hewlett-Packard/Software Update/HP Scheduler.app/
    User login items
       Kodak Share Button Agent
       - /Applications/Kodak Share Button.app/Contents/MacOS/Kodak Share Button Agent.app
       HP Scheduler
       - /Library/Application Support/Hewlett-Packard/Software Update/HP Scheduler.app
    Safari extensions
       AdBlock
       - com.betafish.adblockforsafari
       Reddit Enhancement Suite
       - com.honestbleeps.redditenhancementsuite
    Widgets
       Sports Fan
    iCloud errors
       CallHistorySyncHelper: 7
       Finder: 150
       bird: 265
       cloudd: 66
       com.apple.InputMethodKit.UserDictionary: 2
    Restricted files: 510
    Lockfiles: 17
    High file counts
       Desktop: 114
    Contents of /Library/LaunchAgents/com.hp.help.tocgenerator.plist
       - mod date: Jul 28 17:08:06 2009
       - checksum: 95484570
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>RunAtLoad</key>
        <true/>
        <key>WatchPaths</key>
        <array>
        <string>/Library/Documentation/Help/Hewlett-Packard</string>
        <string>/Library/Documentation/Help/Hewlett-Packard/</string>
        </array>
        <key>ProgramArguments</key>
        <array>
        <string>/Library/Documentation/Help/Hewlett-Packard/TOCGenerator.app/Contents/M acOS/TOCGenerator</string>
        </array>
        <key>Label</key>
        <string>com.hp.help.tocgenerator</string>
       </dict>
       </plist>
    Contents of /Library/LaunchAgents/com.logmein.hamachimb.plist
       - mod date: Dec 13 10:57:58 2014
       - checksum: 2358241344
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>OnDemand</key>
        <false/>
        <key>RunAtLoad</key>
        <true/>
        <key>Label</key>
        <string>com.logmein.hamachimb</string>
        <key>ProgramArguments</key>
        <array>
         <string>/Applications/LogMeIn Hamachi/LogMeIn Hamachi Menubar.app/Contents/MacOS/LogMeIn Hamachi Menubar</string>
        </array>
       </dict>
       </plist>
    Contents of /Library/LaunchAgents/com.rim.BBLaunchAgent.plist
       - mod date: Jul 28 10:22:20 2010
       - checksum: 908705504
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>KeepAlive</key>
        <true/>
        <key>Label</key>
        <string>com.rim.BBLaunchAgent</string>
        <key>OnDemand</key>
        <false/>
        <key>Program</key>
        <string>/Library/Application Support/BlackBerry/BBLaunchAgent.app</string>
        <key>ProgramArguments</key>
        <array>
        <string>BBLaunchAgent</string>
        </array>
        <key>RunAtLoad</key>
        <true/>
       </dict>
       </plist>
    Contents of /Library/LaunchDaemons/com.allocinit.camtwistassistant.plist
       - mod date: Jan  4 23:45:55 2013
       - checksum: 1451205268
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>Label</key>
        <string>com.allocinit.camtwist.dal</string>
        <key>Program</key>
        <string>/Library/CoreMediaIO/Plug-Ins/DAL/CamTwist.plugin/Contents/Resources/Ca mTwistAssistant</string>
               <key>MachServices</key>
               <dict>
                       <key>com.allocinit.camtwist.dal</key>
                       <true/>
               </dict>
       </dict>
       </plist>
    Contents of /Library/LaunchDaemons/com.apple.qmaster.qmasterd.plist
       - mod date: Oct 18 14:27:14 2012
       - checksum: 904438932
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>Label</key>
        <string>com.apple.qmaster.qmasterd</string>
        <key>OnDemand</key>
        <false/>
        <key>ProgramArguments</key>
        <array>
        <string>/usr/sbin/qmasterd</string>
        </array>
       </dict>
       </plist>
    Contents of /Library/LaunchDaemons/com.logmein.hamachi.plist
       - mod date: Dec 13 10:57:58 2014
       - checksum: 4265225024
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>Label</key>
        <string>com.logmein.hamachi</string>
        <key>OnDemand</key>
        <false/>
        <key>ProgramArguments</key>
        <array>
        <string>/Library/Application Support/LogMeIn Hamachi/bin/hamachid</string>
        </array>
        <key>RunAtLoad</key>
        <true/>
        <key>StandardErrorPath</key>
        <string>/Library/Logs/LogMeIn Hamachi/stderr.log</string>
        <key>StandardOutPath</key>
        <string>/Library/Logs/LogMeIn Hamachi/stdout.log</string>
        <key>WorkingDirectory</key>
        <string>/Library/Application Support/LogMeIn Hamachi/</string>
        <key>Debug</key>
        <true/>
       </dict>
       </plist>
    Contents of /Library/LaunchDaemons/com.microsoft.office.licensing.helper.plist
       - mod date: Nov 17 03:00:00 2014
       - checksum: 998894468
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>MachServices</key>
        <dict>
        <key>com.microsoft.office.licensing.helper.port</key>
        <true/>
        </dict>
        <key>Label</key>
        <string>com.microsoft.office.licensing.helper</string>
        <key>OnDemand</key>
        <true/>
        <key>ProgramArguments</key>
        <array>
        <string>/Library/PrivilegedHelperTools/com.microsoft.office.licensing.helper</s tring>
        </array>
        <key>ServiceIPC</key>
        <true/>
       </dict>
       </plist>
    Contents of /Library/LaunchDaemons/com.rim.BBDaemon.plist
       - mod date: Jul 28 10:22:20 2010
       - checksum: 4059782046
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC -//Apple Computer//DTD PLIST 1.0//EN
       http://www.apple.com/DTDs/PropertyList-1.0.dtd >
       <plist version="1.0">
       <dict>
        <key>Label</key>
        <string>com.rim.BBDaemon</string>
        <key>Program</key>
        <string>/Library/Application Support/BlackBerry/BBDaemon</string>
        <key>ProgramArguments</key>
        <array>
        <string>BBDaemon</string>
        </array>
        <key>KeepAlive</key>
        <true/>
        <key>OnDemand</key>
        <false/>
        <key>RunAtLoad</key>
        <true/>
        <key>Sockets</key>
        <dict>
        <key>Listeners</key>
        <dict>
        <key>SockType</key>
        <string>stream</string>
       ...and 8 more line(s)
    Contents of /Library/LaunchDaemons/com.rogueamoeba.hermes.plist
       - mod date: Feb  1 16:16:41 2011
       - checksum: 1539233627
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple Computer//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>GroupName</key>
        <string>wheel</string>
        <key>Label</key>
        <string>com.rogueamoeba.hermes</string>
        <key>ProgramArguments</key>
        <array>
        <string>/usr/local/hermes/bin/hermesctl</string>
        <string>update</string>
        </array>
        <key>RunAtLoad</key>
        <true/>
        <key>ServiceIPC</key>
        <true/>
        <key>UserName</key>
        <string>root</string>
        <key>WatchPaths</key>
        <array>
        <string>/usr/local/hermes/modules</string>
        </array>
       </dict>
       </plist>
    Contents of /Library/LaunchDaemons/jp.co.canon.MasterInstaller.plist
       - mod date: Aug 27 14:05:06 2014
       - checksum: 1894334785
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>Label</key>
        <string>jp.co.canon.MasterInstaller</string>
        <key>ProgramArguments</key>
        <array>
        <string>/Library/PrivilegedHelperTools/jp.co.canon.MasterInstaller</string>
        </array>
        <key>ServiceIPC</key>
        <true/>
        <key>Sockets</key>
        <dict>
        <key>MasterSocket</key>
        <dict>
        <key>SockFamily</key>
        <string>Unix</string>
        <key>SockPathMode</key>
        <integer>438</integer>
        <key>SockPathName</key>
        <string>/var/run/jp.co.canon.MasterInstaller.socket</string>
        <key>SockType</key>
        <string>Stream</string>
        </dict>
       ...and 3 more line(s)
    Contents of /System/Library/Security/authorization.plist
       - mod date: Jan  7 22:31:13 2015
       - checksum: 2720110640
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>comment</key>
        <string>The name of the requested right is matched against the keys.  An exact match has priority, otherwise the longest match from the start is used. Note that the right will only match wildcard rules (ending in a ".") during this reduction.
       allow rule: this is always allowed
       &lt;key&gt;com.apple.TestApp.benign&lt;/key&gt;
       &lt;string&gt;allow&lt;/string&gt;
       deny rule: this is always denied
       &lt;key&gt;com.apple.TestApp.dangerous&lt;/key&gt;
       &lt;string&gt;deny&lt;/string&gt;
       user rule: successful authentication as a user in the specified group(5) allows the associated right.
       The shared property specifies whether a credential generated on success is shared with other apps (i.e., those in the same "session"). This property defaults to false if not specified.
       The timeout property specifies the maximum age of a (cached/shared) credential accepted for this rule.
       The allow-root property specifies whether a right should be allowed automatically if the requesting process is running with uid == 0.  This defaults to false if not specified.
       See remaining rules for examples.
       </string>
        <key>rights</key>
        <dict>
        <key></key>
        <dict>
        <key>class</key>
        <string>rule</string>
        <key>comment</key>
       ...and 1850 more line(s)
    Contents of /private/etc/authorization.deprecated
       - mod date: Aug 27 14:05:06 2014
       - checksum: 1950149371
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>comment</key>
        <string>The name of the requested right is matched against the keys.  An exact match has priority, otherwise the longest match from the start is used. Note that the right will only match wildcard rules (ending in a ".") during this reduction.
       allow rule: this is always allowed
       &lt;key&gt;com.apple.TestApp.benign&lt;/key&gt;
       &lt;string&gt;allow&lt;/string&gt;
       deny rule: this is always denied
       &lt;key&gt;com.apple.TestApp.dangerous&lt;/key&gt;
       &lt;string&gt;deny&lt;/string&gt;
       user rule: successful authentication as a user in the specified group(5) allows the associated right.
       The shared property specifies whether a credential generated on success is shared with other apps (i.e., those in the same "session"). This property defaults to false if not specified.
       The timeout property specifies the maximum age of a (cached/shared) credential accepted for this rule.
       The allow-root property specifies whether a right should be allowed automatically if the requesting process is running with uid == 0.  This defaults to false if not specified.
       See remaining rules for examples.
       </string>
        <key>rights</key>
        <dict>
        <key></key>
        <dict>
        <key>class</key>
        <string>rule</string>
        <key>comment</key>
       ...and 9657 more line(s)
    Contents of /private/etc/hosts
       - mod date: May 20 09:13:57 2012
       - checksum: 342357820
       127.0.0.1 localhost
       255.255.255.255 broadcasthost
       ::1             localhost
       fe80::1%lo0 localhost
       127.0.0.1 activate.adobe.com
       127.0.0.1 practivate.adobe.com
       127.0.0.1 ereg.adobe.com
       127.0.0.1 activate.wip3.adobe.com
       127.0.0.1 wip3.adobe.com
       127.0.0.1 3dns-3.adobe.com
       127.0.0.1 3dns-2.adobe.com
       127.0.0.1 adobe-dns.adobe.com
       127.0.0.1 adobe-dns-2.adobe.com
       127.0.0.1 adobe-dns-3.adobe.com
       127.0.0.1 ereg.wip3.adobe.com
       127.0.0.1 activate-sea.adobe.com
       127.0.0.1 wwis-dubc1-vip60.adobe.com
       127.0.0.1 activate-sjc0.adobe.com
       127.0.0.1 hl2rcv.adobe.com
    Contents of Library/LaunchAgents/com.adobe.AAM.Updater-1.0.plist
       - mod date: Oct  6 19:02:20 2011
       - checksum: 2277476317
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>Label</key>
        <string>com.adobe.AAM.Scheduler-1.0</string>
        <key>Program</key>
        <string>/Library/Application Support/Adobe/OOBE/PDApp/UWA/UpdaterStartupUtility</string>
        <key>ProgramArguments</key>
        <array>
        <string>/Library/Application Support/Adobe/OOBE/PDApp/UWA/UpdaterStartupUtility</string>
        <string>-mode=scheduled</string>
        </array>
        <key>StartCalendarInterval</key>
        <dict>
        <key>Hour</key>
        <integer>2</integer>
        <key>Minute</key>
        <integer>0</integer>
        </dict>
       </dict>
       </plist>
    Contents of Library/LaunchAgents/com.adobe.ARM.UUID.plist
       - mod date: Jun  8 20:13:24 2011
       - checksum: 408149527
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>Label</key>
        <string>com.adobe.ARM.UUID</string>
        <key>ProgramArguments</key>
        <array>
        <string>/Applications/Adobe Reader.app/Contents/MacOS/Updater/Adobe Reader Updater Helper.app/Contents/MacOS/Adobe Reader Updater Helper</string>
        </array>
        <key>RunAtLoad</key>
        <true/>
        <key>StartInterval</key>
        <integer>12600</integer>
       </dict>
       </plist>
    Contents of Library/LaunchAgents/com.google.keystone.agent.plist
       - mod date: Nov 27 10:12:49 2014
       - checksum: 1026064984
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>Label</key>
        <string>com.google.keystone.user.agent</string>
        <key>LimitLoadToSessionType</key>
        <string>Aqua</string>
        <key>ProgramArguments</key>
        <array>
         <string>/Users/USER/Library/Google/GoogleSoftwareUpdate/GoogleSoftwareUpdate.bu ndle/Contents/Resources/GoogleSoftwareUpdateAgent.app/Contents/MacOS/GoogleSoftw areUpdateAgent</string>
         <string>-runMode</string>
         <string>ifneeded</string>
        </array>
        <key>RunAtLoad</key>
        <true/>
        <key>StartInterval</key>
        <integer>3523</integer>
        <key>StandardErrorPath</key>
        <string>/dev/null</string>
        <key>StandardOutPath</key>
        <string>/dev/null</string>
       </dict>
       </plist>
    Contents of Library/LaunchAgents/com.spotify.webhelper.plist
       - mod date: Feb  4 19:10:19 2015
       - checksum: 947417546
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple Computer//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>Label</key>
        <string>com.spotify.webhelper</string>
        <key>KeepAlive</key>
        <dict>
         <key>NetworkState</key>
         <true/>
        </dict>
        <key>RunAtLoad</key>
        <true/>
        <key>Program</key>
        <string>/Users/USER/Library/Application Support/Spotify/SpotifyWebHelper</string>
        <key>SpotifyPath</key>
        <string>/Applications/Spotify.app</string></dict>
       </plist>
    Contents of Library/LaunchAgents/com.valvesoftware.steamclean.plist
       - mod date: Feb  2 15:00:30 2015
       - checksum: 10439305
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>Label</key>
        <string>com.valvesoftware.steamclean</string>
        <key>Program</key>
        <string>/Users/USER/Library/Application Support/Steam/SteamApps/steamclean</string>
        <key>ProgramArguments</key>
        <array>
        <string>/Users/USER/Library/Application Support/Steam/SteamApps/steamclean</string>
        <string>Public</string>
        </array>
        <key>RunAtLoad</key>
        <true/>
        <key>SteamContentPaths</key>
        <array>
        <string>/Users/USER/Library/Application Support/Steam/SteamApps</string>
        </array>
        <key>ThrottleInterval</key>
        <integer>60</integer>
        <key>WatchPaths</key>
        <array>
        <string>/Applications/Steam.app</string>
        <string>/Users/USER/Desktop/Steam.app</string>
       ...and 3 more line(s)
    Contents of Library/LaunchAgents/jp.co.canon.Inkjet_Extended_Survey_Agent.plist
       - mod date: Aug 27 14:11:36 2014
       - checksum: 1116988227
       <?xml version="1.0" encoding="UTF-8"?>
       <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
       <plist version="1.0">
       <dict>
        <key>Label</key>
        <string>jp.co.canon.Inkjet_Extended_Survey_Agent</string>
        <key>OnDemand</key>
        <true/>
        <key>ProgramArguments</key>
        <array>
        <string>/Applications/Canon Utilities/Inkjet Extended Survey Program/Inkjet Extended Survey Program.app/Contents/Resources/Canon_Inkjet_Extended_Survey_Agent</string>
        </array>
        <key>RunAtLoad</key>
        <true/>
        <key>StartInterval</key>
        <integer>86400</integer>
       </dict>
       </plist>
    Extensions
       /Library/Extensions/ham.kext
       - com.logmein.hamachi
       /Library/Extensions/hamns.kext
       - com.logmein.hamachi
       /System/Library/Extensions/EyeTVAfaTechHidBlock.kext
       - com.elgato.driver.DontMatchAfaTech
       /System/Library/Extensions/EyeTVCinergy450AudioBlock.kext
       - com.elgato.driver.DontMatchCinergy450
       /System/Library/Extensions/EyeTVCinergyXSAudioBlock.kext
       - com.elgato.driver.DontMatchCinergyXS
       /System/Library/Extensions/EyeTVEmpiaAudioBlock.kext
       - com.elgato.driver.DontMatchEmpia
       /System/Library/Extensions/EyeTVVoyagerAudioBlock.kext
       - com.elgato.driver.DontMatchVoyager
       /System/Library/Extensions/JMicronATA.kext
       - com.jmicron.JMicronATA
       /System/Library/Extensions/RIMBBUSB.kext
       - com.rim.driver.BlackBerryUSBDriverInt
       /System/Library/Extensions/RIMBBVSP.kext
       - com.rim.driver.BlackBerryUSBDriverVSP
       /System/Library/Extensions/Soundflower.kext
       - com.Cycling74.driver.Soundflower
       /System/Library/Extensions/hamns.kext
       - com.logmein.hamachi
    Applications
       /Applications/Adobe Reader.app
       - com.adobe.Reader
       /Applications/Adobe/Adobe Help.app
       - chc.UUID.1
       /Applications/Adobe/Flash Media Live Encoder 3.2/FlashMediaLiveEncoder.app
       - com.yourcompany.FlashMediaLiveEncoder
       /Applications/Adobe/Flash Media Live Encoder 3.2/Frameworks/LogTransport2.app
       - com.adobe.headlights.LogTransport2App
       /Applications/Audio Hijack Pro.app
       - com.rogueamoeba.AudioHijackPro2
       /Applications/BlackBerry Desktop Manager.app
       - com.rim.blackberrydesktopmanager
       /Applications/CamTwist/CamTwist.app
       - com.allocinit.CamTwist
       /Applications/Canon Utilities/Inkjet Extended Survey Program/Inkjet Extended Survey Program.app
       - jp.co.canon.InkjetExtendedSurveyProgram
       /Applications/Citrix/Dazzle.app
       - com.Citrix.Citrix_Dazzle
       /Applications/EyeTV.app
       - com.elgato.eyetv
       /Applications/Fastest Free YouTube Downloader.app
       - N/A
       /Applications/Firefox.app
       - org.mozilla.firefox
       /Applications/Game Capture HD.app
       - com.elgato.GameCaptureHD
       /Applications/Google Chrome.app
       - com.google.Chrome
       /Applications/Gyazo GIF.app
       - net.gifzo.Gyazo-GIF
       /Applications/Gyazo.app
       - com.gyazo.mac
       /Applications/Hewlett-Packard/Device Utilities/HP All-in-One Device Chooser.app
       - com.hp.deviceChooser
       /Applications/Hewlett-Packard/Device Utilities/HP Fax Setup Utility.app
       - com.hp.aio.faxutility
       /Applications/Hewlett-Packard/Device Utilities/HP Registration Assistant.app
       - com.hp.RegistrationAssistant
       /Applications/Hewlett-Packard/Device Utilities/HP Scan Destinations.app
       - com.hp.photosmart.scandestinations
       /Applications/Hewlett-Packard/Device Utilities/HP Send Fax.app
       - com.hp.hp_send_fax
       /Applications/Hewlett-Packard/HP Device Manager.app
       - com.hp.Device.Manager
       /Applications/Hewlett-Packard/HP Photosmart Create.app
       - com.hp.Photosmart.Create
       /Applications/Hewlett-Packard/HP Photosmart Print.app
       - com.hp.Photosmart.Print
       /Applications/Hewlett-Packard/HP Photosmart Share.app
       - com.hp.Photosmart.Share
       /Applications/Hewlett-Packard/HP Photosmart Stitch.app
       - com.hp.Photosmart.Stitch
       /Applications/Hewlett-Packard/HP Photosmart Studio.app
       - com.hp.Photosmart.Studio
       /Applications/Hewlett-Packard/HP Scan 3.app
       - com.hp.scan.app
       /Applications/Hewlett-Packard/HP Scan Pro.app
       - com.hp.scanpro
       /Applications/Hewlett-Packard/HP Software Update.app
       - com.hp.softwareupdate
       /Applications/Hewlett-Packard/HP Uninstaller.app
       - com.hp.Uninstaller
       /Applications/Kodak Share Button.app
       - com.kodak.ShareButton
       /Applications/LineIn-1.app
       - com.rogueamoeba.LineIn2
       /Applications/LineIn.app
       - com.rogueamoeba.LineIn2
       /Applications/LogMeIn Hamachi/HamachiUninstaller.app
       - com.logmein.hamachi.HamachiUninstaller
       /Applications/LogMeIn Hamachi/LogMeIn Hamachi Menubar.app
       - com.logmein.hamachimb
       /Applications/LogMeIn Hamachi/LogMeIn Hamachi.app
       - com.logmein.hamachi
       /Applications/Microsoft Messenger.app
       - com.microsoft.Messenger
       /Applications/Microsoft Office 2011/Additional Tools/Microsoft Language Register/Microsoft Language Register.app
       - com.microsoft.languageregister
       /Applications/Microsoft Office 2011/Microsoft Document Connection.app
       - com.microsoft.DocumentConnection
       /Applications/Microsoft Office 2011/Microsoft Excel.app
       - com.microsoft.Excel
       /Applications/Microsoft Office 2011/Microsoft Outlook.app
       - com.microsoft.Outlook
       /Applications/Microsoft Office 2011/Microsoft PowerPoint.app
       - com.microsoft.Powerpoint
       /Applications/Microsoft Office 2011/Microsoft Word.app
       - com.microsoft.Word
       /Applications/Microsoft Office 2011/Office/Add-Ins/Solver.app
       - com.microsoft.ASApplication
       /Applications/Microsoft Office 2011/Office/Equation Editor.app
       - com.microsoft.EquationEditor
       /Applications/Microsoft Office 2011/Office/Microsoft Alerts Daemon.app
       - com.microsoft.alerts.daemon
       /Applications/Microsoft Office 2011/Office/Microsoft Chart Converter.app
       - com.microsoft.openxml.chart.app
       /Applications/Microsoft Office 2011/Office/Microsoft Clip Gallery.app
       - com.microsoft.ClipGallery
       /Applications/Microsoft Office 2011/Office/Microsoft Database Daemon.app
       - com.microsoft.outlook.databasedaemon
       /Applications/Microsoft Office 2011/Office/Microsoft Database Utility.app
       - com.microsoft.outlook.databaseutility
       /Applications/Microsoft Office 2011/Office/Microsoft Graph.app
       - com.microsoft.Graph
       /Applications/Microsoft Office 2011/Office/Microsoft Office Reminders.app
       - com.microsoft.outlook.officereminders
       /Applications/Microsoft Office 2011/Office/Microsoft Office Setup Assistant.app
       - com.microsoft.office.setupassistant
       /Applications/Microsoft Office 2011/Office/Microsoft Query.app
       - com.microsoft.Query
       /Applications/Microsoft Office 2011/Office/Microsoft Upload Center.app
       - com.microsoft.office.uploadcenter
       /Applications/Microsoft Office 2011/Office/My Day.app
       - com.microsoft.myday
       /Applications/Microsoft Office 2011/Office/Office365Service.app
       - com.microsoft.Office365Service
       /Applications/Microsoft Office 2011/Office/Open XML for Excel.app
       - com.microsoft.openxml.excel.app
       /Applications/Microsoft Office 2011/Office/SyncServicesAgent.app
       - com.microsoft.SyncServicesAgent
       /Applications/Mumble.app
       - net.sourceforge.mumble.Mumble
       /Applications/Remote Desktop Connection.app
       - com.microsoft.rdc
       /Applications/Screenium.app
       - com.synium.screenium
       /Applications/Skype.app
       - com.skype.skype
       /Applications/Soundflower/Soundflowerbed.app
       - com.cycling74.Soundflowerbed
       /Applications/Spotify.app
       - com.spotify.client
       /Applications/Steam.app
       - com.valvesoftware.steam
       /Applications/Utilities/Adobe AIR Application Installer.app
       - com.adobe.air.ApplicationInstaller
       /Applications/Utilities/Adobe AIR Uninstaller.app
       - com.adobe.air.Installer
       /Applications/Utilities/Adobe Flash Player Install Manager.app
       - com.adobe.flashplayer.installmanager
       /Applications/Utilities/Adobe Utilities-CS5.localized/ExtendScript Toolkit CS5/ExtendScript Toolkit.app
       - com.adobe.estoolkit-3.5
       /Applications/Utilities/Bluetooth Firmware Update.app
       - com.apple.updaters.btfirmwareupdate20
       /Applications/Utilities/MacBook Pro EFI Firmware Update.app
       - com.apple.updaters.macbookpro.efifirmwareupdater170
       /Applications/XBMC.app
       - com.teamxbmc.xbmc
       /Library/Application Support/Adobe/CS5ServiceManager/CS5ServiceManager.app
       - com.adobe.csi.CS5ServiceManager
       /Library/Application Support/Adobe/OOBE/PDApp/DWA/Setup.app
       - com.adobe.Installers.Setup
       /Library/Application Support/Adobe/OOBE/PDApp/DWA/resources/uninstall/Uninstall Product.app
       - N/A
       /Library/Application Support/Adobe/OOBE/PDApp/LWA/AAM Registration Notifier.app
       - com.adobe.PDApp.AAMRegistrationNotifier
       /Library/Application Support/Adobe/OOBE/PDApp/LWA/adobe_licutil.app
       - com.adobe.adobe_licutil
       /Library/Application Support/Adobe/OOBE/PDApp/UWA/AAM Updates Notifier.app
       - com.adobe.PDApp.AAMUpdatesNotifier
       /Library/Application Support/Adobe/OOBE/PDApp/UWA/LogTransport2.app
       - com.adobe.headlights.LogTransport2App
       /Library/Application Support/Adobe/OOBE/PDApp/core/Adobe Application Manager.app
       - com.adobe.PDApp
       /Library/Application Support/Adobe/SwitchBoard/SwitchBoard.app
       - com.adobe.switchboard-2.0
       /Library/Application Support/Adobe/Uninstall/{UUID}.app
       - N/A
       /Library/Application Support/Adobe/Uninstall/{UUID}.app
       - N/A
       /Library/Application Support/BlackBerry/BBLaunchAgent.app
       - N/A
       /Library/Application Support/BlackBerry/IPModemPasswordDialog.app
       - com.rim.IPModemPasswordHelper
       /Library/Application Support/Citrix/Citrix Online Plug-in.app
       - com.citrix.XenAppViewer
       /Library/Application Support/Citrix/Citrix Online Web Plug-in.app
       - com.citrix.ICAClient
       /Library/Application Support/Citrix/DazzleMe.app
       - com.citrix.DazzleMe
       /Library/Application Support/Citrix/Desktop Viewer.app
       - com.citrix.XenDesktopViewer
       /Library/Application Support/Citrix/DockApplication.app
       - com.Citrix.DockApplication
       /Library/Application Support/Citrix/Uninstall Citrix Online Plug-in.app
       - N/A
       /Library/Application Support/Hewlett-Packard/HP Scan Pro/DPE/DPE 11.6.app
       - com.irislink.mac.DPE
       /Library/Application Support/Hewlett-Packard/HP Scan Pro/DPE/Register DPE.app
       - com.irislink.mac.RegisterDPE
       /Library/Application Support/Hewlett-Packard/Software Update/HP Rules Processor.app
       - com.hp.rulesprocessor
       /Library/Application Support/Hewlett-Packard/Software Update/HP Scheduler.app
       - com.hp.HPScheduler
       /Library/Application Support/Hewlett-Packard/Software Update/HP Software Updater
       - com.MindVision.VISEX
       /Library/Application Support/Hewlett-Packard/Software Update/HP Software Updater/Contents/MacOSClassic/HP Software Updater
       - N/A
       /Library/Application Support/Hewlett-Packard/Software Update/HPSUSelfUpdatePostScript.app
       - N/A
       /Library/Application Support/Hewlett-Packard/hpAutomation.app
       - com.hp.Automation
       /Library/Application Support/Hewlett-Packard/iPhoto Support/Jpeg to iPhoto.app
       - com.hp.photo.jpgtoiphoto
       /Library/Application Support/Microsoft/MAU2.0/Microsoft AutoUpdate.app
       - com.microsoft.autoupdate2
       /Library/Application Support/Microsoft/MERP2.0/Microsoft Error Reporting.app
       - com.microsoft.error_reporting
       /Library/Application Support/Microsoft/MERP2.0/Microsoft Ship Asserts.app
       - com.microsoft.netlib.shipassertprocess
       /Library/Application Support/Microsoft/Silverlight/OutOfBrowser/SLLauncher.app
       - com.microsoft.silverlight.sllauncher
       /Library/Application Support/Script Editor/Templates/Cocoa-AppleScript Applet.app
       - com.apple.ScriptEditor.id.cocoa-applet-template
       /Library/Application Support/Script Editor/Templates/Droplets/Droplet with Settable Properties.app
       - com.apple.ScriptEditor.id.droplet-with-settable-properties-template
       /Library/Application Support/Script Editor/Templates/Droplets/Recursive File Processing Droplet.app
       - com.apple.ScriptEditor.id.file-processing-droplet-template
       /Library/Application Support/Script Editor/Templates/Droplets/Recursive Image File Processing Droplet.app
       - com.apple.ScriptEditor.id.image-file-processing-droplet-template
       /Library/Documentation/Help/Hewlett-Packard/TOCGenerator.app
       - com.hp.dynamicTOCGenerator
       /Library/Documentation/Help/Hewlett-Packard/shrd/flashplayer
       - N/A
       /Library/Documentation/Help/Hewlett-Packard/shrd/fscommand/inkjet23_clean_adf.a pp
       - N/A
       /Library/Documentation/Help/Hewlett-Packard/shrd/fscommand/inkjet23_insert_card .app
       - N/A
       /Library/Documentation/Help/Hewlett-Packard/shrd/fscommand/inkjet23_jams.app
       - N/A
       /Library/Documentation/Help/Hewlett-Packard/shrd/fscommand/inkjet23_load_adf.ap p
       - N/A
       /Library/Documentation/Help/Hewlett-Packard/shrd/fscommand/inkjet23_load_envelo pes.app
       - N/A
       /Library/Documentation/Help/Hewlett-Packard/shrd/fscommand/inkjet23_load_glass. app
       - N/A
       /Library/Documentation/Help/Hewlett-Packard/shrd/fscommand/inkjet23_load_small. app
       - N/A
       /Library/Documentation/Help/Hewlett-Packard/shrd/fscommand/inkjet23_load_standa rd.app
       - N/A
       /Library/Documentation/Help/Hewlett-Packard/shrd/fscommand/inkjet23_replace_car tridge.app
       - N/A
       /Library/Documentation/Help/Hewlett-Packard/shrd/fscommand/inkjet23_scan_card.a pp
       - N/A
       /Library/Documentation/Help/Hewlett-Packard/shrd/fscommand/inkjet23_transfer_sc anner.app
       - N/A
       /Library/Documentation/User Guides And Information.localized/Apple Hardware Test Read Me.app
       - com.apple.AppleHardwareTestReadMe
       /Library/Frameworks/Adobe AIR.framework/Versions/1.0/Adobe AIR Application Installer.app
       - com.adobe.air.ApplicationInstaller
       /Library/Frameworks/Adobe AIR.framework/Versions/1.0/Resources/Adobe AIR Updater.app
       - com.adobe.air.Installer
       /Library/Frameworks/Adobe AIR.framework/Versions/1.0/Resources/Template.app
       - com.adobe.air.Template
       /Library/Image Capture/Devices/Canon IJScanner13f.app
       - jp.co.canon.ij.ica.scanner13f
       /Library/Image Capture/Devices/Canon IJScanner14s.app
       - jp.co.canon.ij.ica.scanner14s
       /Library/Image Capture/Devices/Canon IJScanner2.app
       - jp.co.canon.ijscanner2.scanner.ica
       /Library/Image Capture/Devices/Canon IJScanner3.app
       - jp.co.canon.ij.ica.scanner3
       /Library/Image Capture/Devices/Canon IJScanner4.app
       - jp.co.canon.ij.ica.scanner4
       /Library/Image Capture/Devices/EPSON Scanner.app
       - com.epson.scanner.ica
       /Library/Image Capture/Devices/HP Scanner 3.app
       - com.hp.scanModule3
       /Library/Printers/Canon/BJPrinter/Utilities/CIJAutoSetupTool.app
       - jp.co.canon.ij.print.cijautosetuptool
       /Library/Printers/Canon/BJPrinter/Utilities/CanonIJPrinterUtility.app
       - jp.co.canon.bj.print.app.canonijprinterutility
       /Library/Printers/hp/Fax/fax.backend
       - com.hp.fax
       /Library/Printers/hp/Fax/rastertofax.filter
       - com.hp.rastertofax
       /Library/Printers/hp/Utilities/HP Utility.app
       - com.hp.printerutility
       /Library/Printers/hp/Utilities/HP Utility.app/Contents/Applications/HP Event Status.app
       - com.hp.event.status.handler.generic
       /Library/Printers/hp/Utilities/HP Utility.app/Contents/Applications/LegacyScanEventHandler.app
       - com.hp.scan.button.handler.legacy
       /Library/Printers/hp/Utilities/HP Utility.app/Contents/Library/LoginItems/HP Device Monitor.app
       - com.hp.devicemonitor
       /Library/Printers/hp/Utilities/HP Utility.app/Contents/Library/LoginItems/HP Device Monitor.app/Contents/Library/LoginItems/HP Device Monitor.app
       - com.hp.devicemonitor
       /Library/Printers/hp/Utilities/Handlers/ScanEventHandler.app
       - com.hp.scan.button.handler.generic
       /Library/Printers/hp/cups/filters/commandtohp.filter
       - com.hp.print.cups.filter.commandtohp
       /Library/Printers/hp/cups/filters/pdftopdf.filter
       - com.hp.print.cups.filter.pdftopdf
       /Library/Printers/hp/cups/tools/autosetup.tool
       - com.hp.print.autosetup
       /Library/Printers/hp/filter/hpPreProcessing.filter
       - com.hp.print.cups.filter.hpPreProcessing
       /Users/USER/Applications/CamTwist/CamTwist.app
       - com.allocinit.CamTwist
       /Users/USER/Applications/Counter-Strike Source.app
       - N/A
       /Users/USER/Applications/Garry's Mod.app
       - N/A
       /Users/USER/Applications/Left 4 Dead 2.app
       - N/A
       /Users/USER/Applications/Screenium.app
       - com.synium.screenium
       /Users/USER/Applications/Team Fortress 2.app
       - N/A
       /Users/USER/Desktop/Audacity.app
       - net.sourceforge.audacity
       /Users/USER/Desktop/Counter-Strike Global Offensive.app
       - N/A
       /Users/USER/Desktop/EyeTV.app
       - com.elgato.eyetv
       /Users/USER/Desktop/Google Earth.app
       - com.Google.GoogleEarthPlus
       /Users/USER/Desktop/Steam.app
       - com.valvesoftware.steam
       /Users/USER/Desktop/Team Fortress 2.app
       - N/A
       /Users/USER/Downloads/ASTRO_Device_Manager-OSX-1.app
       - N/A
       /Users/USER/Downloads/ASTRO_Device_Manager-OSX.app
       - N/A
       /Users/USER/Downloads/Audio Hijack Pro-5.app
       - com.rogueamoeba.AudioHijackPro2
       /Users/USER/Downloads/Audio Hijack Pro.app
       - com.rogueamoeba.AudioHijackPro2
       /Users/USER/Downloads/Flash Player Debugger.app
       - N/A
       /Users/USER/Downloads/Flash Player.app
       - N/A
       /Users/USER/Downloads/OBS Studio.app
       - com.obsproject.obs-studio
       /Users/USER/Downloads/OBS.app
       - com.obsproject.obs-studio
       /Users/USER/Downloads/savosx_he_r 2/Sophos Anti-Virus Home Edition.app
       - com.sophos.macendpoint.InstallationDeployer
       /Users/USER/Downloads/savosx_he_r/Sophos Anti-Virus Home Edition.app
       - com.sophos.macendpoint.InstallationDeployer
       /Users/USER/Library/Application Support/Google/Chrome/Default/Web Ap

  • Zbot and other issues after sophos scan

    bot-gal.ide  zbot-gap.ide  zbot-gay.ide zbot-gbf.ide
    zbot-gbi.ide  zbot-gbj.ide zbot-gbm.ide  zbot-gbn.ide  zbot-gbq.ide  zbot-gby.ide  zbot-gcb.ide zbot-gch.ide  zbot-gcl.ide
    zbot-gcm.ide  zegos-cc.ide zeleff-a.ide
    Scan name: "Scan Local Drives"
    Scan items:
    Configuration:
    Scan inside archives and compressed files: Yes
    Automatically clean up threats: No
    Action on infected files: Report only
    Live Protection enabled: Yes
    Scan started at 2013-08-29 13:57:24 +0200
    New volume detected at /
    2013-08-29 14:11:06 +0200 Encrypted file: /Users/Downloads/AdobeFlashPlayerInstaller_11_ltrosxd_aaa_aih-1.dmg
    2013-08-29 14:11:06 +0200 Encrypted file: /Users/Downloads/AdobeFlashPlayerInstaller_11_ltrosxd_aaa_aih-2.dmg
    2013-08-29 14:11:06 +0200 Encrypted file: /Users/Downloads/AdobeFlashPlayerInstaller_11_ltrosxd_aaa_aih.dmg
    Scan completed at 2013-08-29 14:13:08 +0200.
    308531 items scanned, 0 threats detected, 3 issues

    I don't know how you got rid of Sophos, but here are directions to make sure you got all related files.
    Sophos Uninstaller

  • How do I remove OSX/FkCodec-A  from my Mac mini? I am running Yosemite and the path and file name is /Volumes/macvexe/macvexe.app/Contents/MacOS/mac.installer. Sophos was unble to remove and it will not go to trash.

    Sophos found this on my mac mini (early 2009) - OSX/FkCodec-A and could not clean it up. I am running Yosemite 10.10 and the path and filename for this Trojan is   /Volumes/macvexe/macvexe.app/Contents/MacOS/mac.installer. Could someone please tell me how to get rid of it as Sophos is unable to remove and Trash can remove it.

    outdoor,
    How did you originally install iWork on the Mac Pro?  was it preinstalled?  The machine seems old enough that you should have an original install DVD that came with the mac pro.
    Amazon has the install DVDs for iWork '09:
    http://www.amazon.com/s/ref=nb_sb_noss_1?url=search-alias%3Daps&field-keywords=i Work+%2709
    To move tables between sheets you can select the table, copy, then paste after activating (by clicking) the destination sheet.  If you really mean move, then use the cut command (rather than copy).
    To copy... use the menu item "Edit > Copy"
    To cut... use the menu item "Edit > Cut"
    Then paste in the destination

  • InterCheck takes up to 192% process time when I start Firefox (Safari or Sophos, or...). Why is this?

    Dear Fellows,
    I was surprise, as I realized that MacBook Pro was running InterChech from the Sophos Anti-Virus folder using near to 192% process time...
    The fan was running on 100% all time long.
    It was a big piece of work to start annother application.
    I contacted Sophos support asking what to do. I didn't get a conclusive statement.
    So, I'm asking you.
    Anyway, after a while I killed the process.
    What is the matter with InterCheck? How is possible to avoid such situations?
    Thank you.
    Regards,
    IOS

    That is not normal behavior for Sophos. Something is wrong. Did you try removing and reinstalling it? Run the Sophos Remove application (which should be in the Applications folder) to completely remove all components. Then download the most current version from the Sophos web site and reinstall it.
    Alternately, you are probably fine to just remove it, provided you are following all the necessary security procedures to protect yourself from malware. See my Mac Malware Guide.

  • Sophos stopped working message, greyed out icon and On-Access Scanning disabled

    Hi, I've started to get an error message from Sophos saying that Sophos has stopped working, the icon in the menu bar is greyed out and the On-Access Scanner is diasbled. I've opened preferences to turn the scanner back on but just get "stopping". I've uninstalled Sophos and re-installed as this issue has occured a number of times. OSX 10.10.4 and SAV 9.2.7

    Hi DJJD,
    Sorry, I started a reply yesterday but I just noticed now I didn't actually post it. 
    The first thing I wonder is, have you tried uninstalling and reinstalling? It sounds like your install is pretty broken, so that will likely be your fastest fix. To do that, follow the steps below:
    1. Browse to this page and download a new copy of the installer (Click "Get Started" and follow the prompts)
    2.  Use the "Remove Sophos Antivirus" app to uninstall. You will find this in finder under Applications > Remove Sophos Antivirus
    3. Restart your Mac 4. Double-click the install app you downloaded in step 1 (The file is called savosx_he_r)
    5. Follow the on-screen prompts until the install is complete  
    Hopefully that will get you back up and running, but if you have any questions don't hesitate to let us know!

  • When i download a file from the web i get "Anti-Virus Program not found " message. This has been happening since I change anti-virus programs for CA etrust to Sophos. How do I get Firefox to recognise my new Anti-virus program?

    every time i download a file from the web (ie. a PDF file) i get "Anti-Virus Program not found " message. This has been happening since I changed anti-virus programs for CA etrust to Sophos. How do I get Firefox to recognise my new Anti-virus program?

    That is a very good warning provided by the Download Statusbar extension. Something like that should been built into Firefox. I filed this Bug report a couple of years ago, about the lack of a warning like that. <br />
    https://bugzilla.mozilla.org/show_bug.cgi?id=480855 <br />
    I have looked everywhere that I can think of to find a list of '''IOfficeAntiVirus providers''' ''(as mentioned in the Bug report)'' that will work with Firefox, so I can't answer that for you.
    You might want to ask the developer of the Download Statusbar extension about it. He might know which AV programs are compatible with the Windows API that Firefox uses for the download scan. <br />
    http://dlstatusbar.proboards.com/index.cgi? <br />

  • Wccp and Sophos Web Appliance

    I am new to WCCP and I am having trouble getting the Sophos Web Appliance to Connect to a 6509e port channel. The Web app is on a VM host and the host is connected to the 6509 by two interfaces on a port channel.
    Here are the wccp parts of the config:
    ip wccp web-cache group-list 98 password
    Standard IP access list 98
        10 permit 172.18.4.55 (1403 matches) (host)
    sh ip wccp
    Global WCCP information:
        Router information:
            Router Identifier:                   10.1.18.251
            Protocol Version:                    2.0
        Service Identifier: web-cache
            Number of Service Group Clients:     0
            Number of Service Group Routers:     0
            Total Packets s/w Redirected:        0
              Process:                           0
              CEF:                               0
            Redirect access-list:                -none-
            Total Packets Denied Redirect:       0
            Total Packets Unassigned:            0
            Group access-list:                   98
            Total Messages Denied to Group:      0
            Total Authentication failures:       735
            Total Bypassed Packets Received:     0
    sh ip wccp web-cache view
        WCCP Routers Informed of:
            -none-
        WCCP Clients Visible:
            -none-
        WCCP Clients NOT Visible:
           -none-
    #sho ip wccp web-cache det
    WCCP Client information:
            WCCP Client ID:          172.18.4.55
            Protocol Version:        2.0
            State:                   NOT Usable (Initializing)
            Redirection:             L2
            Packet Return:           L2
            Packets Redirected:    0
            Connect Time:          00:00:04
            Assignment:            MASK
            At one time I had the Server listed in WCCP Clients visible but, now it's gone. I am concerned about the State:                   NOT Usable (Initializing) statment. It is not changing. Has anyone had this problem? Of course Sophos said it was easy!
    Thank you in advance.

    The fix is to white list download.acrocomcontent.com for future reference.
    Bye!

  • Sophos Antivirus version 10 or higher not included in PRUs?

    Hello Novell-Forums.
    My request regards an update for the ZCMs PRUs in order to discover Sophos Antivirus version 10 or higher.
    At the moment the Asset Management discovers Sophos only up to version 9,5. All higher Sophos-versions
    are to be found within the "Software Files by Manufacturer"-Report under the label "Sophos Limited", but
    are not discovered by the Asset Management.
    I guess the Manufacturer-label is the reason, why newer versions of Sophos aren't discovered:
    Previous versions of Sophos were distributed under the Manufacturer-label "Sophos Tld", since version 10
    Sophos Antivirus is published under the Manufacturer-label "Sophos Limited".
    I would prefer if the PRUs could be updated instead of just creating Local Software Products, because our admins would
    have to update theses definitions every time a new version of Sophos is available. If I guessed this wrong
    and there is a way to create dynamic Local Software Products, ones which are not influenced by a minor
    software-update, please give me a hint!
    Otherwise, if I have to send my request to a specific department, please let me know.
    Thank You a lot and best regards,
    Hans-Peter Klein

    kleinhp,
    It appears that in the past few days you have not received a response to your
    posting. That concerns us, and has triggered this automated reply.
    Has your problem been resolved? If not, you might try one of the following options:
    - Visit http://support.novell.com and search the knowledgebase and/or check all
    the other self support options and support programs available.
    - You could also try posting your message again. Make sure it is posted in the
    correct newsgroup. (http://forums.novell.com)
    Be sure to read the forum FAQ about what to expect in the way of responses:
    http://forums.novell.com/faq.php
    If this is a reply to a duplicate posting, please ignore and accept our apologies
    and rest assured we will issue a stern reprimand to our posting bot.
    Good luck!
    Your Novell Product Support Forums Team
    http://forums.novell.com/

  • Workaround for Sophos anti-virus blocking remote panel

    Hello, I was hoping if anyone had some suggestions regarding working around an antivirus.
    I'm trying to have a PC act as a web server for some Labview embedded remote panels. Unfortunately whenever I tried to load it in browser on both the local host and other computers connected to the network (even very simple test VIs), I get the 0% downloaded problem people have had in the past. Since I have admin privileges on the host computer I have discovered that by disabling the antivirus (Sophos Endpoint Security and Control, ver. 10.2) completely fixed the problem for that machine.
    My problem is that I intend for students to use the VIs and they do not have the access rights to disable Sophos so they too will be able to use the panel. Faculty IT are unwilling to modify the antivirus for the computer lab PCs so it is down to what I can do on the server PC to fix this problem.
    Does anyone have any suggestions to work around it? I've tried a couple of different ports for the web server (8000 & 5000) with no luck. Snapshots come through fine, it is only the embedded ones that get blocked.
    Any help would be appreciated.
    Specs:
    Labview 2011 with Run-Time Engine 6.1
    Windows 7 (64 bit)
    Anti virus: Sophos Endpoint Security and Control, ver. 10.2. On-access scanning is causing the issue.

    I guess you have to ask IT which ports you can use, e.g. 8080, from the top of my mind.
    /Y
    LabVIEW 8.2 - 2014
    "Only dead fish swim downstream" - "My life for Kudos!" - "Dumb people repeat old mistakes - smart ones create new ones."
    G# - Free award winning reference based OOP for LV

  • Help! Sophos popup leads to generally useless computer...

    Hi all! I have a pretty strange situation going on on my parents' computer.
    My mom claims that she didn't install Sophos (an anti-virus program) on her iMac, yet when she logged onto the computer today, a window saying "Threat detected by Sohpos Anti-Virus" popped up. I closed it, and it continued to pop up. I then deleted the Sophos app from Finder. I then tried to open Safari, and a window came up saying "You can't use this version of the application Safari with this version of Mac OS X. You have OS X 10.6. The application requires 10.6 or later," which made very little sense to me. I got the same notification for the Mail app, and various other applications. When I tried to open Disk Utility, I got the same error. I then restarted the computer in Internet Recovery Mode, and repaired the disk and its permissions. Still nothing. I then rebooted in Safe Boot, and I didn't get the Sophos popup, but the computer refused to connect to the Internet, claiming there was no airport card installed.
    The virus detected by Sophos is "mal/nix-A," which when I looked up, apparently usually comes from a certain email. I looked through my mom's email on my computer, and couldn't find anything fishy. I'm very confused by what's going on, and my parents' computer is essentially useless as of now. Any help or guidance would be much appreciated. Thanks!

    actually i believe it is part of the installation disc. this article talks about it a little. http://support.apple.com/kb/HT2956
    but anyways, WOW! my computer is on crack... after trying everything i could think of for the last couple of days, i decided not to touch it tonight after i got home from work, instead i got on here to write apple a message asking for help, and while i was writing that message i decided i should turn the computer on to make sure i had everything it was saying word for word.... and when i got to destination selection, its allowing my hard drive now! which is weird, cause i didn't do anything different to it, and i didn't touch it before work and it didn't work last night. odd. but it is still installing as i type this.... hopefully no install problems....
    anyways, i thank you all for your help and ideas. they were much appreciated.
    and on a final note, i am going to leave this thread as unsolved, because i did not actually find out what the problem was. however i believe that the "volumecheck tool error" lies with the install disc.

  • Installer processs DRAINS ALL RAM (sophos problem too..)

    Hello!
    My system suddenly runs REALLY SLOW, then I have to delete the installer process and it gets better. FOllowing is my system report. As you can see I have sophos which I would love to UNINSTALL YET, I cant..... Why? Because I deleted the app from the trash bin, yet all this inner processes do not stop happening. I tried downloading another antivirus or even sophos again to uninstall it and it SHUTS ME DOWN, saying "OH you ALREADY HAVE SOPHOS SO YOU CANNOT DO THAT............."
    Let me know if you can help! I can follow any instructions, I appreciate thanks in ADVANCE!!
    PS: as you can see installer takes 87% of my RAM.... *** >.< ..... Oh and I already uninstalled the malware Genio with the use of TMS adware removal.
    I need urgent help! Im having the same problem. PLEASE THANK!
    HERES THE REPORT:
    Hardware Information:
              MacBook Pro (13-inch, Late 2011)
              MacBook Pro - model: MacBookPro8,1
              1 2.4 GHz Intel Core i5 CPU: 2 cores
              4 GB RAM
    Video Information:
              Intel HD Graphics 3000 - VRAM: 384 MB
    System Software:
              OS X 10.9.2 (13C64) - Uptime: 3 days 0:35:16
    Disk Information:
              ST9500325ASG disk0 : (500.11 GB)
                        EFI (disk0s1) <not mounted>: 209.7 MB
                        Macintosh HD (disk0s2) / [Startup]: 499.25 GB (199 GB free)
                        Recovery HD (disk0s3) <not mounted>: 650 MB
              MATSHITADVD-R   UJ-8A8
    USB Information:
              Apple Inc. FaceTime HD Camera (Built-in)
              Apple Inc. Apple Internal Keyboard / Trackpad
              Apple Inc. BRCM2070 Hub
                        Apple Inc. Bluetooth USB Host Controller
              Logitech USB Receiver
              Apple Computer, Inc. IR Receiver
    Thunderbolt Information:
              Apple Inc. thunderbolt_bus
    Gatekeeper:
              Mac App Store and identified developers
    Kernel Extensions:
              [not loaded] com.devguru.driver.SamsungACMControl (1.2.58 - SDK 10.6) Support
              [not loaded] com.devguru.driver.SamsungACMData (1.2.58 - SDK 10.6) Support
              [not loaded] com.devguru.driver.SamsungComposite (1.2.58 - SDK 10.6) Support
              [not loaded] com.devguru.driver.SamsungMTP (1.2.58 - SDK 10.5) Support
              [not loaded] com.devguru.driver.SamsungSerial (1.2.58 - SDK 10.6) Support
    Problem System Launch Daemons:
              [failed] com.apple.AOSNotificationOSX.plist
              [failed] com.apple.installd.plist
              [failed] com.apple.softwareupdated.plist
              [failed] com.apple.wdhelper.plist
    Launch Daemons:
              [loaded] com.adobe.fpsaud.plist Support
              [loaded] com.microsoft.office.licensing.helper.plist Support
              [running] com.sophos.autoupdate.plist Support
              [running] com.sophos.intercheck.plist Support
              [running] com.sophos.managementagent.plist Support
              [running] com.sophos.messagerouter.plist Support
              [running] com.sophos.notification.plist Support
              [loaded] com.spotflux.Spotflux.plist Support
    User Launch Agents:
              [loaded] com.adobe.ARM.[...].plist Support
              [running] com.akamai.single-user-client.plist Support
              [failed] com.apple.CSConfigDotMacCert-[...]@me.com-SharedServices.Agent.plist
              [loaded] com.facebook.videochat.[redacted].plist Support
              [running] com.genieo.completer.download.plist Support
              [loaded] com.genieo.completer.update.plist Support
              [failed] com.google.GoogleContactSyncAgent.plist Support
              [loaded] com.google.keystone.agent.plist Support
              [loaded] com.macpaw.CleanMyMac.helperTool.plist Support
              [loaded] com.macpaw.CleanMyMac.volumeWatcher.plist Support
    User Login Items:
              iTunesHelper
              Music Manager
              AdobeResourceSynchronizer
              TuneupMyMac
              KiesAgent
              KiesViaWiFiAgent
              SophosUIServer
    Internet Plug-ins:
              FlashPlayer-10.6: Version: 13.0.0.206 - SDK 10.6 Support
              QuickTime Plugin: Version: 7.7.3
              AdobePDFViewerNPAPI: Version: 11.0.02 - SDK 10.6 Support
              AdobePDFViewer: Version: 11.0.02 - SDK 10.6 Support
              Flash Player: Version: 13.0.0.206 - SDK 10.6 Support
              Default Browser: Version: 537 - SDK 10.9
              SharePointBrowserPlugin: Version: 14.0.0 Support
              JavaAppletPlugin: Version: 14.9.0 - SDK 10.7 Check version
    Safari Extensions:
              Omnibar: Version: 1.2
              Cuevana Stream: Version: 3.1.5
    Audio Plug-ins:
              BluetoothAudioPlugIn: Version: 1.0 - SDK 10.9
              AirPlay: Version: 2.0 - SDK 10.9
              AppleAVBAudio: Version: 203.2 - SDK 10.9
              iSightAudio: Version: 7.7.3 - SDK 10.9
    iTunes Plug-ins:
              Quartz Composer Visualizer: Version: 1.4 - SDK 10.9
    User Internet Plug-ins:
              bjnplugin_2.4.143.8: Version: bjnplugin 2.4.143.8 - SDK 10.8 Support
              bjninstallplugin_2.4.143.8: Version: bjninstallplugin 2.4.143.8 - SDK 10.8 Support
    3rd Party Preference Panes:
              Akamai NetSession Preferences  Support
              Flash Player  Support
              Growl  Support
              MusicManager  Support
    Time Machine:
              Mobile backups: OFF
              Auto backup: NO - Auto backup turned off
              Volumes being backed up:
              Destinations:
                        Harrick [Local] (Last used)
                        Total size: 0 B
                        Total number of backups: (null)
                        Size of backup disk: Excellent
                                  Backup size 0 B > (Disk size 0 B X 3)
              Time Machine details may not be accurate.
              All volumes being backed up may not be listed.
    Top Processes by CPU:
                  86%          Installer
                   7%          AdobeReader
                   3%          com.apple.internetaccounts
                   1%          WindowServer
                   1%          accountsd
    Top Processes by Memory:
              686 MB          Installer
              55 MB          AdobeReader
              33 MB          Finder
              33 MB          Google Chrome
              20 MB          WindowServer
    Virtual Memory Information:
              13 MB          Free RAM
              589 MB          Active RAM
              586 MB          Inactive RAM
              1.04 GB          Wired RAM
              24.10 GB          Page-ins
              950 MB          Page-outs

    So... Thanks for your help, although Heres my issue! I reinstalled sophos to try to do uninstall it properly. Now first I did not see a sophos removal package, so I used the appzapper to remove it. Neverthelesss I am at the same place I was before. When I go on activity monitor and type sophos... Look what comes out
    I literally CANNOT get rid of these... SOPHOS files dont even come up on my spotlight search. Seriously I need like a special tool to remove this, and when you click on them to check the path.. they are rooted to the kernel. I believe you cant mess with the kernel because its unstoppable,,
    please help thanks!
    SophosUIServer
    7.4 MB
    7
    170
    236
    harrick007
    0.0
    1.22
    0
    0 bytes
    0 bytes
    0
    0
    No
    No
    0 bytes
    0 bytes
    32 Bit
    0 bytes
    0 bytes
    0 bytes
    No
    No
    0 bytes
    SophosMessageRouter
    3.5 MB
    17
    35
    66
    root
    0.1
    0.81
    0
    39 KB
    27 KB
    53
    39
    No
    No
    0 bytes
    0 bytes
    32 Bit
    0 bytes
    0 bytes
    0 bytes
    No
    No
    0 bytes
    SophosManagementAgent
    88.8 MB
    12
    69
    67
    root
    0.1
    7.04
    1
    22 KB
    9 KB
    26
    15
    No
    No
    0 bytes
    0 bytes
    32 Bit
    0 bytes
    0 bytes
    0 bytes
    No
    No
    0 bytes
    SophosAutoUpdate
    1.1 MB
    5
    57
    69
    root
    0.0
    0.06
    0
    0 bytes
    0 bytes
    0
    0
    No
    No
    0 bytes
    0 bytes
    32 Bit
    0 bytes
    0 bytes
    0 bytes
    No
    No
    0 bytes
    SophosAntiVirus
    1.5 MB
    6
    64
    65
    root
    0.0
    0.17
    0
    0 bytes
    0 bytes
    0
    0
    No
    No
    0 bytes
    0 bytes
    32 Bit
    0 bytes
    0 bytes
    0 bytes
    No
    No
    0 bytes

Maybe you are looking for