a varovanie dalšie
Event 1014,Dns Clients Events
+ System
- Provider
[ Name] Microsoft-Windows-DNS-Client
[ Guid] {1C95126E-7EEA-49A9-A3FE-A378B03DDB4D}
EventID 1014
Version 0
Level 3
Task 0
Opcode 0
Keywords 0x4000000000000000
- TimeCreated
[ SystemTime] 2011-08-03T19:45:43.370117100Z
EventRecordID 242441
Correlation
- Execution
[ ProcessID] 1368
[ ThreadID] 3236
Channel System
- Security
[ UserID] S-1-5-20
- EventData
QueryName
www.youtube.co
AddressLength 16
Address 02000035C0A800C80000000000000000
A User Profile Service
+ System
- Provider
[ Name] Microsoft-Windows-User Profiles Service
[ Guid] {89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}
EventID 1530
Version 0
Level 3
Task 0
Opcode 0
Keywords 0x8000000000000000
- TimeCreated
[ SystemTime] 2011-08-03T16:08:47.253906200Z
EventRecordID 24060
Correlation
- Execution
[ ProcessID] 1080
[ ThreadID] 872
Channel Application
- Security
[ UserID] S-1-5-18
- EventData
Detail 16 user registry handles leaked from \Registry\User\S-1-5-21-2077639707-384719932-3077192631-1000: Process 536 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-2077639707-384719932-3077192631-1000 Process 536 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-2077639707-384719932-3077192631-1000 Process 536 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-2077639707-384719932-3077192631-1000 Process 536 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-2077639707-384719932-3077192631-1000 Process 2028 (\Device\HarddiskVolume1\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe) has opened key \REGISTRY\USER\S-1-5-21-2077639707-384719932-3077192631-1000 Process 536 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-2077639707-384719932-3077192631-1000\Software\Microsoft\SystemCertificates\My Process 536 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-2077639707-384719932-3077192631-1000\Software\Microsoft\SystemCertificates\Root Process 536 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-2077639707-384719932-3077192631-1000\Software\Policies\Microsoft\SystemCertificates Process 536 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-2077639707-384719932-3077192631-1000\Software\Policies\Microsoft\SystemCertificates Process 536 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-2077639707-384719932-3077192631-1000\Software\Policies\Microsoft\SystemCertificates Process 536 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-2077639707-384719932-3077192631-1000\Software\Policies\Microsoft\SystemCertificates Process 536 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-2077639707-384719932-3077192631-1000\Software\Microsoft\SystemCertificates\CA Process 536 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-2077639707-384719932-3077192631-1000\Software\Microsoft\SystemCertificates\TrustedPeople Process 536 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-2077639707-384719932-3077192631-1000\Software\Microsoft\SystemCertificates\Disallowed Process 536 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-2077639707-384719932-3077192631-1000\Software\Microsoft\SystemCertificates\SmartCardRoot Process 536 (\Device\HarddiskVolume1\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-2077639707-384719932-3077192631-1000\Software\Microsoft\SystemCertificates\trust
Microsoft Antimalware
+ System
- Provider
[ Name] Microsoft Antimalware
- EventID 1002
[ Qualifiers] 0
Level 3
Task 0
Keywords 0x80000000000000
- TimeCreated
[ SystemTime] 2011-08-03T13:07:00.000000000Z
EventRecordID 242202
Channel System
Security
- EventData
%%860
3.0.8402.0
{A01B8769-BB2B-485A-BA30-6A91DB619BFB}
2
%%802
2
%%805
S-1-5-21-2077639707-384719932-3077192631-1000
Microsoft Antimalware scan has been stopped before comlection.
Scan ID:(A01B8767-BB2B-485A-BA30-6A91DB619BFB)
Scan Type:Antimalware
Scan Parameters: full Scan
User a moje meno tu ma byt napisane
Prepačte že ich je tolko