variant infiltrácie MSIL/Packed.Confuser.B
Napsal: 08 led 2013 17:54
Dobry den, chcel by som Vas poprosit o pomoc s touto infiltraciou:
Dakujem dopredu za Vas cas.
info.txt logfile of random's system information tool 1.09 2013-01-08 17:41:34
======Uninstall list======
-->MsiExec /X{9530AE42-DAE1-4619-9594-B23487285D17}
AC3Filter 2.5b-->"C:\Program Files (x86)\AC3Filter\unins000.exe"
Adobe Flash Player 11 ActiveX-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_5_502_135_ActiveX.exe -maintain activex
Adobe Reader XI - Slovak-->MsiExec.exe /I{AC76BA86-7AD7-1051-7B44-AB0000000001}
Any Video Converter 2.7.7-->"C:\Program Files (x86)\Any Video Converter\unins000.exe"
Assassin's Creed (R) III-->"C:\Program Files (x86)\InstallShield Installation Information\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}\setup.exe" -runfromtemp -l0x0005 -removeonly
Assassin's Creed Brotherhood-->"C:\Program Files (x86)\InstallShield Installation Information\{BE4BA698-8533-4F77-9559-C7F3F78C0B05}\setup.exe" -runfromtemp -l0x0005 -removeonly
Assassin's Creed II-->"C:\Program Files (x86)\InstallShield Installation Information\{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}\setup.exe" -runfromtemp -l0x0009 -removeonly
ASUS Gamer OSD-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{7F88C9E5-12BD-404F-AC6A-108BAAC9B708}\setup.exe" -l0x9 -removeonly
AVerMedia H830 USB Hybrid TV 10.0.64.24-->C:\Program Files (x86)\AVerMedia\AVerMedia H830 USB Hybrid TV\uninst.exe
AVerMedia Media Center Plug-ins 2.0.8.0-->C:\Program Files (x86)\AVerMedia\AVerMedia Media Center Plug-ins\uninst.exe
AVerTV-->C:\Program Files (x86)\InstallShield Installation Information\{E28B1E6F-E0AA-4228-AB89-DB4A0C89D426}\setup.exe -runfromtemp -l0x041b
AVI ReComp 1.5.1-->C:\Program Files (x86)\AVI ReComp\Uninstall.exe
AviSynth 2.5-->"C:\Program Files (x86)\AviSynth 2.5\Uninstall.exe"
Battlefield 3-->"C:\Games\Battlefield 3\unins000.exe"
Battlefield: Bad Company™ 2-->MsiExec.exe /X{3AC8457C-0385-4BEA-A959-E095F05D6D67}
BS.Player FREE-->"C:\Program Files (x86)\Webteh\BSplayer\uninstall.exe"
Canon Easy-PhotoPrint EX-->C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\uninst.exe Uninst.ini uinstrsc.dll
Canon Easy-WebPrint EX-->"C:\Program Files (x86)\Canon\Easy-WebPrint EX\Maint.exe" /UninstallRemove C:\Program Files (x86)\Canon\Easy-WebPrint EX\uninst.ini
Canon Inkjet Printer/Scanner/Fax Extended Survey Program-->C:\Program Files (x86)\Canon\IJPLM\SETUP.EXE -R
Canon MG5100 series MP Drivers-->"C:\Windows\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5100_series\DelDrv64.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5100_series /L0x0009
Canon MG5100 series User Registration-->C:\Program Files (x86)\Canon\IJEREG\MG5100 series\UNINST.EXE
Canon MP Navigator EX 4.0-->"C:\Program Files (x86)\Canon\MP Navigator EX 4.0\Maint.exe" /UninstallRemove C:\Program Files (x86)\Canon\MP Navigator EX 4.0\uninst.ini
Canon My Printer-->C:\Program Files\Canon\MyPrinter\uninst.exe uninst.ini uinstrsc.dll
Canon Solution Menu EX-->"C:\Program Files (x86)\Canon\Solution Menu EX\uninst.exe" /UninstallRemove C:\Program Files (x86)\Canon\Solution Menu EX\uninst.ini
ConvertXtoDVD 4.0.6.316-->"C:\Program Files (x86)\VSO\ConvertX\4\unins000.exe"
Cool & Quiet-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{1ADE1AA0-7F82-4BB1-B1BD-727DE438057B}\setup.exe" -l0x9
Crysis® 2-->MsiExec.exe /X{6033673D-2530-4587-8AD0-EB059FC263F9}
CyberLink PowerDirector-->"C:\Program Files (x86)\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\Setup.exe" /z-uninstall
CyberLink PowerDirector-->"C:\Program Files (x86)\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\Setup.exe" /z-uninstall
DAEMON Tools Lite-->C:\Program Files (x86)\DAEMON Tools Lite\uninst.exe
DesignPro 5-->C:\PROGRA~2\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{F82C6574-AD88-4B40-A432-970BC77F1BD2}
DownTango-->C:\Program Files (x86)\Red Sky\DownTango\Uninstaller.exe
E.M. Total Video Player 1.31-->"C:\Program Files (x86)\Total Video Player\unins000.exe"
EasyBCD 1.7.2-->C:\Program Files (x86)\NeoSmart Technologies\EasyBCD\uninstall.exe
Free DVD Decrypter version 1.5-->"C:\Program Files (x86)\DVDVideoSoft\Free DVD Decrypter\unins000.exe"
GOM Player-->"C:\Program Files (x86)\GRETECH\GomPlayer\Uninstall.exe"
GotClip Downloader-->"C:\Program Files (x86)\GotClip\uninstall.exe"
iLivid-->"C:\Users\Juraj Cordas\AppData\Local\iLivid\uninstall.exe"
Intel(R) Management Engine Components-->C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\Uninstall\setup.exe -uninstall
Internet Download Manager-->C:\Program Files (x86)\Internet Download Manager\Uninstall.exe
Java 7 Update 9-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83217009FF}
Mafia 2 version 1.0-->"C:\Program Files (x86)\Mafia 2\unins000.exe"
Mass Effect 2-->C:\Program Files (x86)\Common Files\BioWare\Uninstall Mass Effect 2.exe
Mass Effect™ 3-->"C:\Program Files (x86)\Common Files\EAInstaller\Mass Effect 3\Cleanup.exe" uninstall_game -autologging
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /x64 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}
Microsoft Office File Validation Add-In-->MsiExec.exe /I{90140000-2005-0000-0000-0000000FF1CE}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219-->MsiExec.exe /X{1D8E6291-B0D5-35EC-8441-6616F567A0F7}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219-->MsiExec.exe /X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
MPEG2 Codec(libmpeg2/mad)-->"C:\Program Files (x86)\GNU\MPEG2\Uninstall.exe"
MSVC90_x64-->MsiExec.exe /I{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}
MSVC90_x86-->MsiExec.exe /I{AF111648-99A1-453E-81DD-80DBBF6DAD0D}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
Nokia Connectivity Cable Driver-->MsiExec.exe /I{4AA68A73-DB9C-439D-9481-981C82BD008B}
Nokia PC Suite-->C:\ProgramData\Installations\{A97F28B2-3BA1-49B7-AEF6-CC8956ED8CAA}\Nokia_PC_Suite_slk.exe
Nokia PC Suite-->MsiExec.exe /I{A97F28B2-3BA1-49B7-AEF6-CC8956ED8CAA}
NVIDIA 3D Vision Driver 306.97-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.3DVision
NVIDIA Drivers-->C:\Program Files\NVIDIA Corporation\Uninstall\nvuninst.exe UninstallGUI
NVIDIA Graphics Driver 306.97-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.Driver
NVIDIA PhysX-->MsiExec.exe /X{9530AE42-DAE1-4619-9594-B23487285D17}
NVIDIA Stereoscopic 3D Driver-->"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvStInst.exe" /uninstall /ask
NVIDIA Update 1.10.8-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.Update
PC Connectivity Solution-->MsiExec.exe /I{A2AA4204-C05A-4013-888A-AD153139297F}
Picasa 3-->"C:\Program Files (x86)\Google\Picasa3\Uninstall.exe"
PlayReady PC Runtime amd64-->MsiExec.exe /X{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}
Popisovač CD/DVD 4.2-->"C:\Program Files (x86)\Popisovač CD-DVD 4\unins000.exe"
PunkBuster Services-->C:\Windows\system32\pbsvc.exe -u
Realtek Ethernet Controller Driver For Windows Vista and Later-->C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\Setup.exe -runfromtemp -removeonly
Revo Uninstaller Pro 2.2.0-->"C:\Program Files\VS Revo Group\Revo Uninstaller Pro\unins000.exe"
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {E720AD01-93D5-3E8E-BB8D-E4EF5AF4E5DD} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {BCD37DCB-F479-3D4D-A90E-A0F7575549C4} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {FF811680-AECE-3F35-A98C-1B84B6E09168} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {6AF6C62E-4E3D-33BF-A591-9E4D53BDF22F} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {5D45782A-1099-317E-ABCC-FF63D5B21386} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {E59B2174-E924-311F-8549-AD714C14664D} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {FDD13F1E-9C6B-311E-A0D9-D6E172FC28FF} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {DA36C2E5-6B34-3A6A-9C0A-7D1CC1C5A768} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {7B82A51A-768B-3A7B-ADFA-F777097A8079} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {E40184A4-4A61-3D2E-9035-CB6E1E610E07} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {4736E989-32D9-3B91-90D7-C68848E118CA} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {F1696E2F-4803-362F-A756-65B363483FE6} /parameterfolder Client
SnugTV Station-->MsiExec.exe /I{E633417D-E796-45E1-8DE1-CB5954DA4896}
Subtitle Workshop 2.51-->"C:\Program Files (x86)\URUSoft\Subtitle Workshop\uninstall.exe"
SureThing CD Labeler Deluxe-->"C:\Program Files (x86)\SureThing CD Labeler 5\unins000.exe"
Ubisoft Game Launcher-->"C:\Program Files (x86)\InstallShield Installation Information\{888F1505-C2B3-4FDE-835D-36353EBD4754}\setup.exe" -runfromtemp -l0x0409 -removeonly
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {29C7BE97-DE59-37A2-A687-2ADD5321948A} /parameterfolder Client
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {7D799A81-5661-3159-BF92-754161CED6E6} /parameterfolder Client
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {4DFA8287-EA36-3469-99FE-F568FEC81653} /parameterfolder Client
Uplay-->C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uninstall.exe
VIA Platform Device Manager-->C:\PROGRA~2\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{20D4A895-748C-4D88-871C-FDB1695B0169}
VLC media player 1.1.11-->C:\Program Files (x86)\VideoLAN\VLC\uninstall.exe
VobSub 2.23-->C:\Program Files (x86)\Gabest\VobSub\uninstall.exe
Vuze-->C:\Program Files\Vuze\uninstall.exe
Windows Driver Package - Nokia Modem (02/25/2011 4.7)-->C:\PROGRA~1\DIFX\0169CE3A95F06636\dpinst.exe /u C:\Windows\System32\DriverStore\FileRepository\nokia_bluetooth.inf_amd64_neutral_73c28da64803cefc\nokia_bluetooth.inf
Windows Driver Package - Nokia Modem (02/25/2011 7.01.0.9)-->C:\PROGRA~1\DIFX\0169CE3A95F06636\dpinst.exe /u C:\Windows\System32\DriverStore\FileRepository\nokbtmdm.inf_amd64_neutral_13826104cd8e800f\nokbtmdm.inf
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)-->C:\PROGRA~1\DIFX\F4092DA208C2C970\dpinst.exe /u C:\Windows\system32\DRVSTORE\pccsmcfdx6_8A3BAB842294F8D9255C3CF2A3B1CECAEEB8EA7E\pccsmcfdx64.inf
Windows Movie Maker 2.6-->MsiExec.exe /X{B3DAF54F-DB25-4586-9EF1-96D24BB14088}
WinRAR archivátor-->C:\Program Files (x86)\WinRAR\uninstall.exe
Wise Disk Cleaner 6.31-->"C:\Program Files (x86)\Wise Disk Cleaner\unins000.exe"
Wise Registry Cleaner 6.21-->"C:\Program Files (x86)\Wise Registry Cleaner\unins000.exe"
Xvid 1.2.2-->C:\Program Files (x86)\Xvid\unins000.exe
XviD MPEG-4 Video Codec-->C:\Windows\system32\rundll32.exe setupapi,InstallHinfSection Remove_XviD 132 C:\Windows\INF\xvid.inf
Zoner Photo Studio 14-->"C:\Program Files\Zoner\Photo Studio 14\unins000.exe" /SILENT
======System event log======
Computer Name: mojpocitac
Event Code: 51
Message: An error was detected on device \Device\Harddisk6\DR6 during a paging operation.
Record Number: 144419
Source Name: Disk
Time Written: 20121010142619.717745-000
Event Type: Warning
User:
Computer Name: mojpocitac
Event Code: 51
Message: An error was detected on device \Device\Harddisk6\DR6 during a paging operation.
Record Number: 144418
Source Name: Disk
Time Written: 20121010142619.717745-000
Event Type: Warning
User:
Computer Name: mojpocitac
Event Code: 51
Message: An error was detected on device \Device\Harddisk6\DR6 during a paging operation.
Record Number: 144417
Source Name: Disk
Time Written: 20121010142619.717745-000
Event Type: Warning
User:
Computer Name: mojpocitac
Event Code: 51
Message: An error was detected on device \Device\Harddisk6\DR6 during a paging operation.
Record Number: 144416
Source Name: Disk
Time Written: 20121010142619.717745-000
Event Type: Warning
User:
Computer Name: mojpocitac
Event Code: 51
Message: An error was detected on device \Device\Harddisk6\DR6 during a paging operation.
Record Number: 144415
Source Name: Disk
Time Written: 20121010142619.717745-000
Event Type: Warning
User:
=====Application event log=====
Computer Name: mojpocitac
Event Code: 63
Message: A provider, IntelMEProv, has been registered in the Windows Management Instrumentation namespace root\Intel_ME to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Record Number: 404
Source Name: Microsoft-Windows-WMI
Time Written: 20120117150205.000000-000
Event Type: Warning
User: mojpocitac\Juraj Cordas
Computer Name: mojpocitac
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-2897896145-2411329342-784474909-1000:
Process 516 (\Device\HarddiskVolume2\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-2897896145-2411329342-784474909-1000
Record Number: 369
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20120117121258.632818-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: mojpocitac
Event Code: 6001
Message: Odberateľ upozornení prihlásenia do systému Windows <GPClient> zlyhal pri udalosti upozornenia.
Record Number: 211
Source Name: Microsoft-Windows-Winlogon
Time Written: 20120117110022.000000-000
Event Type: Warning
User:
Computer Name: mojpocitac
Event Code: 1015
Message: Detailed HRESULT. Returned hr=0xC004F022, Original hr=0x80049E00
Record Number: 205
Source Name: Microsoft-Windows-Security-SPP
Time Written: 20120117105941.000000-000
Event Type: Warning
User:
Computer Name: mojpocitac
Event Code: 1008
Message: Služba Windows Search sa spúšťa a pokúša sa odstrániť starý index hľadania. {Dôvod: Full Index Reset}.
Record Number: 97
Source Name: Microsoft-Windows-Search
Time Written: 20120117105426.000000-000
Event Type: Warning
User:
=====Security event log=====
Computer Name: mojpocitac
Event Code: 4907
Message: Auditing settings on object were changed.
Subject:
Security ID: S-1-5-18
Account Name: MOJPOCITAC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Object:
Object Server: Security
Object Type: File
Object Name: C:\Windows\SysWOW64\en-US\ieunatt.exe.mui
Handle ID: 0x14
Process Information:
Process ID: 0x7e4
Process Name: C:\Windows\System32\poqexec.exe
Auditing Settings:
Original Security Descriptor:
New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 3381
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120117163446.028106-000
Event Type: Audit Success
User:
Computer Name: mojpocitac
Event Code: 4907
Message: Auditing settings on object were changed.
Subject:
Security ID: S-1-5-18
Account Name: MOJPOCITAC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Object:
Object Server: Security
Object Type: File
Object Name: C:\Windows\SysWOW64\en-US\iesetup.dll.mui
Handle ID: 0x14
Process Information:
Process ID: 0x7e4
Process Name: C:\Windows\System32\poqexec.exe
Auditing Settings:
Original Security Descriptor:
New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 3380
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120117163445.872106-000
Event Type: Audit Success
User:
Computer Name: mojpocitac
Event Code: 4907
Message: Auditing settings on object were changed.
Subject:
Security ID: S-1-5-18
Account Name: MOJPOCITAC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Object:
Object Server: Security
Object Type: File
Object Name: C:\Windows\SysWOW64\en-US\ie4uinit.exe.mui
Handle ID: 0x14
Process Information:
Process ID: 0x7e4
Process Name: C:\Windows\System32\poqexec.exe
Auditing Settings:
Original Security Descriptor:
New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 3379
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120117163445.872106-000
Event Type: Audit Success
User:
Computer Name: mojpocitac
Event Code: 4907
Message: Auditing settings on object were changed.
Subject:
Security ID: S-1-5-18
Account Name: MOJPOCITAC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Object:
Object Server: Security
Object Type: File
Object Name: C:\Windows\SysWOW64\en-US\wextract.exe.mui
Handle ID: 0x14
Process Information:
Process ID: 0x7e4
Process Name: C:\Windows\System32\poqexec.exe
Auditing Settings:
Original Security Descriptor:
New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 3378
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120117163445.872106-000
Event Type: Audit Success
User:
Computer Name: mojpocitac
Event Code: 4907
Message: Auditing settings on object were changed.
Subject:
Security ID: S-1-5-18
Account Name: MOJPOCITAC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Object:
Object Server: Security
Object Type: File
Object Name: C:\Windows\SysWOW64\en-US\mshtml.dll.mui
Handle ID: 0x14
Process Information:
Process ID: 0x7e4
Process Name: C:\Windows\System32\poqexec.exe
Auditing Settings:
Original Security Descriptor:
New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 3377
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120117163445.856506-000
Event Type: Audit Success
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=C:\Program Files (x86)\PC Connectivity Solution\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=4
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=Intel64 Family 6 Model 30 Stepping 5, GenuineIntel
"PROCESSOR_REVISION"=1e05
-----------------EOF-----------------
Dakujem dopredu za Vas cas.
info.txt logfile of random's system information tool 1.09 2013-01-08 17:41:34
======Uninstall list======
-->MsiExec /X{9530AE42-DAE1-4619-9594-B23487285D17}
AC3Filter 2.5b-->"C:\Program Files (x86)\AC3Filter\unins000.exe"
Adobe Flash Player 11 ActiveX-->C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_5_502_135_ActiveX.exe -maintain activex
Adobe Reader XI - Slovak-->MsiExec.exe /I{AC76BA86-7AD7-1051-7B44-AB0000000001}
Any Video Converter 2.7.7-->"C:\Program Files (x86)\Any Video Converter\unins000.exe"
Assassin's Creed (R) III-->"C:\Program Files (x86)\InstallShield Installation Information\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}\setup.exe" -runfromtemp -l0x0005 -removeonly
Assassin's Creed Brotherhood-->"C:\Program Files (x86)\InstallShield Installation Information\{BE4BA698-8533-4F77-9559-C7F3F78C0B05}\setup.exe" -runfromtemp -l0x0005 -removeonly
Assassin's Creed II-->"C:\Program Files (x86)\InstallShield Installation Information\{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}\setup.exe" -runfromtemp -l0x0009 -removeonly
ASUS Gamer OSD-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{7F88C9E5-12BD-404F-AC6A-108BAAC9B708}\setup.exe" -l0x9 -removeonly
AVerMedia H830 USB Hybrid TV 10.0.64.24-->C:\Program Files (x86)\AVerMedia\AVerMedia H830 USB Hybrid TV\uninst.exe
AVerMedia Media Center Plug-ins 2.0.8.0-->C:\Program Files (x86)\AVerMedia\AVerMedia Media Center Plug-ins\uninst.exe
AVerTV-->C:\Program Files (x86)\InstallShield Installation Information\{E28B1E6F-E0AA-4228-AB89-DB4A0C89D426}\setup.exe -runfromtemp -l0x041b
AVI ReComp 1.5.1-->C:\Program Files (x86)\AVI ReComp\Uninstall.exe
AviSynth 2.5-->"C:\Program Files (x86)\AviSynth 2.5\Uninstall.exe"
Battlefield 3-->"C:\Games\Battlefield 3\unins000.exe"
Battlefield: Bad Company™ 2-->MsiExec.exe /X{3AC8457C-0385-4BEA-A959-E095F05D6D67}
BS.Player FREE-->"C:\Program Files (x86)\Webteh\BSplayer\uninstall.exe"
Canon Easy-PhotoPrint EX-->C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\uninst.exe Uninst.ini uinstrsc.dll
Canon Easy-WebPrint EX-->"C:\Program Files (x86)\Canon\Easy-WebPrint EX\Maint.exe" /UninstallRemove C:\Program Files (x86)\Canon\Easy-WebPrint EX\uninst.ini
Canon Inkjet Printer/Scanner/Fax Extended Survey Program-->C:\Program Files (x86)\Canon\IJPLM\SETUP.EXE -R
Canon MG5100 series MP Drivers-->"C:\Windows\system32\CanonIJ Uninstaller Information\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5100_series\DelDrv64.exe" /U:{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5100_series /L0x0009
Canon MG5100 series User Registration-->C:\Program Files (x86)\Canon\IJEREG\MG5100 series\UNINST.EXE
Canon MP Navigator EX 4.0-->"C:\Program Files (x86)\Canon\MP Navigator EX 4.0\Maint.exe" /UninstallRemove C:\Program Files (x86)\Canon\MP Navigator EX 4.0\uninst.ini
Canon My Printer-->C:\Program Files\Canon\MyPrinter\uninst.exe uninst.ini uinstrsc.dll
Canon Solution Menu EX-->"C:\Program Files (x86)\Canon\Solution Menu EX\uninst.exe" /UninstallRemove C:\Program Files (x86)\Canon\Solution Menu EX\uninst.ini
ConvertXtoDVD 4.0.6.316-->"C:\Program Files (x86)\VSO\ConvertX\4\unins000.exe"
Cool & Quiet-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{1ADE1AA0-7F82-4BB1-B1BD-727DE438057B}\setup.exe" -l0x9
Crysis® 2-->MsiExec.exe /X{6033673D-2530-4587-8AD0-EB059FC263F9}
CyberLink PowerDirector-->"C:\Program Files (x86)\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\Setup.exe" /z-uninstall
CyberLink PowerDirector-->"C:\Program Files (x86)\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\Setup.exe" /z-uninstall
DAEMON Tools Lite-->C:\Program Files (x86)\DAEMON Tools Lite\uninst.exe
DesignPro 5-->C:\PROGRA~2\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{F82C6574-AD88-4B40-A432-970BC77F1BD2}
DownTango-->C:\Program Files (x86)\Red Sky\DownTango\Uninstaller.exe
E.M. Total Video Player 1.31-->"C:\Program Files (x86)\Total Video Player\unins000.exe"
EasyBCD 1.7.2-->C:\Program Files (x86)\NeoSmart Technologies\EasyBCD\uninstall.exe
Free DVD Decrypter version 1.5-->"C:\Program Files (x86)\DVDVideoSoft\Free DVD Decrypter\unins000.exe"
GOM Player-->"C:\Program Files (x86)\GRETECH\GomPlayer\Uninstall.exe"
GotClip Downloader-->"C:\Program Files (x86)\GotClip\uninstall.exe"
iLivid-->"C:\Users\Juraj Cordas\AppData\Local\iLivid\uninstall.exe"
Intel(R) Management Engine Components-->C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\Uninstall\setup.exe -uninstall
Internet Download Manager-->C:\Program Files (x86)\Internet Download Manager\Uninstall.exe
Java 7 Update 9-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83217009FF}
Mafia 2 version 1.0-->"C:\Program Files (x86)\Mafia 2\unins000.exe"
Mass Effect 2-->C:\Program Files (x86)\Common Files\BioWare\Uninstall Mass Effect 2.exe
Mass Effect™ 3-->"C:\Program Files (x86)\Common Files\EAInstaller\Mass Effect 3\Cleanup.exe" uninstall_game -autologging
Microsoft .NET Framework 4 Client Profile-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\Setup.exe /repair /x86 /x64 /parameterfolder Client
Microsoft .NET Framework 4 Client Profile-->MsiExec.exe /X{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}
Microsoft Office File Validation Add-In-->MsiExec.exe /I{90140000-2005-0000-0000-0000000FF1CE}
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219-->MsiExec.exe /X{1D8E6291-B0D5-35EC-8441-6616F567A0F7}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219-->MsiExec.exe /X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
MPEG2 Codec(libmpeg2/mad)-->"C:\Program Files (x86)\GNU\MPEG2\Uninstall.exe"
MSVC90_x64-->MsiExec.exe /I{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}
MSVC90_x86-->MsiExec.exe /I{AF111648-99A1-453E-81DD-80DBBF6DAD0D}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
Nokia Connectivity Cable Driver-->MsiExec.exe /I{4AA68A73-DB9C-439D-9481-981C82BD008B}
Nokia PC Suite-->C:\ProgramData\Installations\{A97F28B2-3BA1-49B7-AEF6-CC8956ED8CAA}\Nokia_PC_Suite_slk.exe
Nokia PC Suite-->MsiExec.exe /I{A97F28B2-3BA1-49B7-AEF6-CC8956ED8CAA}
NVIDIA 3D Vision Driver 306.97-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.3DVision
NVIDIA Drivers-->C:\Program Files\NVIDIA Corporation\Uninstall\nvuninst.exe UninstallGUI
NVIDIA Graphics Driver 306.97-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.Driver
NVIDIA PhysX-->MsiExec.exe /X{9530AE42-DAE1-4619-9594-B23487285D17}
NVIDIA Stereoscopic 3D Driver-->"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvStInst.exe" /uninstall /ask
NVIDIA Update 1.10.8-->"C:\Windows\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\installer.0\NVI2.DLL",UninstallPackage Display.Update
PC Connectivity Solution-->MsiExec.exe /I{A2AA4204-C05A-4013-888A-AD153139297F}
Picasa 3-->"C:\Program Files (x86)\Google\Picasa3\Uninstall.exe"
PlayReady PC Runtime amd64-->MsiExec.exe /X{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}
Popisovač CD/DVD 4.2-->"C:\Program Files (x86)\Popisovač CD-DVD 4\unins000.exe"
PunkBuster Services-->C:\Windows\system32\pbsvc.exe -u
Realtek Ethernet Controller Driver For Windows Vista and Later-->C:\Program Files (x86)\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\Setup.exe -runfromtemp -removeonly
Revo Uninstaller Pro 2.2.0-->"C:\Program Files\VS Revo Group\Revo Uninstaller Pro\unins000.exe"
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {E720AD01-93D5-3E8E-BB8D-E4EF5AF4E5DD} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {BCD37DCB-F479-3D4D-A90E-A0F7575549C4} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {FF811680-AECE-3F35-A98C-1B84B6E09168} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {6AF6C62E-4E3D-33BF-A591-9E4D53BDF22F} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {5D45782A-1099-317E-ABCC-FF63D5B21386} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {E59B2174-E924-311F-8549-AD714C14664D} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {FDD13F1E-9C6B-311E-A0D9-D6E172FC28FF} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {DA36C2E5-6B34-3A6A-9C0A-7D1CC1C5A768} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {7B82A51A-768B-3A7B-ADFA-F777097A8079} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {E40184A4-4A61-3D2E-9035-CB6E1E610E07} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {4736E989-32D9-3B91-90D7-C68848E118CA} /parameterfolder Client
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {F1696E2F-4803-362F-A756-65B363483FE6} /parameterfolder Client
SnugTV Station-->MsiExec.exe /I{E633417D-E796-45E1-8DE1-CB5954DA4896}
Subtitle Workshop 2.51-->"C:\Program Files (x86)\URUSoft\Subtitle Workshop\uninstall.exe"
SureThing CD Labeler Deluxe-->"C:\Program Files (x86)\SureThing CD Labeler 5\unins000.exe"
Ubisoft Game Launcher-->"C:\Program Files (x86)\InstallShield Installation Information\{888F1505-C2B3-4FDE-835D-36353EBD4754}\setup.exe" -runfromtemp -l0x0409 -removeonly
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {29C7BE97-DE59-37A2-A687-2ADD5321948A} /parameterfolder Client
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {7D799A81-5661-3159-BF92-754161CED6E6} /parameterfolder Client
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\Client\setup.exe /uninstallpatch {4DFA8287-EA36-3469-99FE-F568FEC81653} /parameterfolder Client
Uplay-->C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uninstall.exe
VIA Platform Device Manager-->C:\PROGRA~2\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{20D4A895-748C-4D88-871C-FDB1695B0169}
VLC media player 1.1.11-->C:\Program Files (x86)\VideoLAN\VLC\uninstall.exe
VobSub 2.23-->C:\Program Files (x86)\Gabest\VobSub\uninstall.exe
Vuze-->C:\Program Files\Vuze\uninstall.exe
Windows Driver Package - Nokia Modem (02/25/2011 4.7)-->C:\PROGRA~1\DIFX\0169CE3A95F06636\dpinst.exe /u C:\Windows\System32\DriverStore\FileRepository\nokia_bluetooth.inf_amd64_neutral_73c28da64803cefc\nokia_bluetooth.inf
Windows Driver Package - Nokia Modem (02/25/2011 7.01.0.9)-->C:\PROGRA~1\DIFX\0169CE3A95F06636\dpinst.exe /u C:\Windows\System32\DriverStore\FileRepository\nokbtmdm.inf_amd64_neutral_13826104cd8e800f\nokbtmdm.inf
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)-->C:\PROGRA~1\DIFX\F4092DA208C2C970\dpinst.exe /u C:\Windows\system32\DRVSTORE\pccsmcfdx6_8A3BAB842294F8D9255C3CF2A3B1CECAEEB8EA7E\pccsmcfdx64.inf
Windows Movie Maker 2.6-->MsiExec.exe /X{B3DAF54F-DB25-4586-9EF1-96D24BB14088}
WinRAR archivátor-->C:\Program Files (x86)\WinRAR\uninstall.exe
Wise Disk Cleaner 6.31-->"C:\Program Files (x86)\Wise Disk Cleaner\unins000.exe"
Wise Registry Cleaner 6.21-->"C:\Program Files (x86)\Wise Registry Cleaner\unins000.exe"
Xvid 1.2.2-->C:\Program Files (x86)\Xvid\unins000.exe
XviD MPEG-4 Video Codec-->C:\Windows\system32\rundll32.exe setupapi,InstallHinfSection Remove_XviD 132 C:\Windows\INF\xvid.inf
Zoner Photo Studio 14-->"C:\Program Files\Zoner\Photo Studio 14\unins000.exe" /SILENT
======System event log======
Computer Name: mojpocitac
Event Code: 51
Message: An error was detected on device \Device\Harddisk6\DR6 during a paging operation.
Record Number: 144419
Source Name: Disk
Time Written: 20121010142619.717745-000
Event Type: Warning
User:
Computer Name: mojpocitac
Event Code: 51
Message: An error was detected on device \Device\Harddisk6\DR6 during a paging operation.
Record Number: 144418
Source Name: Disk
Time Written: 20121010142619.717745-000
Event Type: Warning
User:
Computer Name: mojpocitac
Event Code: 51
Message: An error was detected on device \Device\Harddisk6\DR6 during a paging operation.
Record Number: 144417
Source Name: Disk
Time Written: 20121010142619.717745-000
Event Type: Warning
User:
Computer Name: mojpocitac
Event Code: 51
Message: An error was detected on device \Device\Harddisk6\DR6 during a paging operation.
Record Number: 144416
Source Name: Disk
Time Written: 20121010142619.717745-000
Event Type: Warning
User:
Computer Name: mojpocitac
Event Code: 51
Message: An error was detected on device \Device\Harddisk6\DR6 during a paging operation.
Record Number: 144415
Source Name: Disk
Time Written: 20121010142619.717745-000
Event Type: Warning
User:
=====Application event log=====
Computer Name: mojpocitac
Event Code: 63
Message: A provider, IntelMEProv, has been registered in the Windows Management Instrumentation namespace root\Intel_ME to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Record Number: 404
Source Name: Microsoft-Windows-WMI
Time Written: 20120117150205.000000-000
Event Type: Warning
User: mojpocitac\Juraj Cordas
Computer Name: mojpocitac
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-2897896145-2411329342-784474909-1000:
Process 516 (\Device\HarddiskVolume2\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-2897896145-2411329342-784474909-1000
Record Number: 369
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20120117121258.632818-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: mojpocitac
Event Code: 6001
Message: Odberateľ upozornení prihlásenia do systému Windows <GPClient> zlyhal pri udalosti upozornenia.
Record Number: 211
Source Name: Microsoft-Windows-Winlogon
Time Written: 20120117110022.000000-000
Event Type: Warning
User:
Computer Name: mojpocitac
Event Code: 1015
Message: Detailed HRESULT. Returned hr=0xC004F022, Original hr=0x80049E00
Record Number: 205
Source Name: Microsoft-Windows-Security-SPP
Time Written: 20120117105941.000000-000
Event Type: Warning
User:
Computer Name: mojpocitac
Event Code: 1008
Message: Služba Windows Search sa spúšťa a pokúša sa odstrániť starý index hľadania. {Dôvod: Full Index Reset}.
Record Number: 97
Source Name: Microsoft-Windows-Search
Time Written: 20120117105426.000000-000
Event Type: Warning
User:
=====Security event log=====
Computer Name: mojpocitac
Event Code: 4907
Message: Auditing settings on object were changed.
Subject:
Security ID: S-1-5-18
Account Name: MOJPOCITAC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Object:
Object Server: Security
Object Type: File
Object Name: C:\Windows\SysWOW64\en-US\ieunatt.exe.mui
Handle ID: 0x14
Process Information:
Process ID: 0x7e4
Process Name: C:\Windows\System32\poqexec.exe
Auditing Settings:
Original Security Descriptor:
New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 3381
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120117163446.028106-000
Event Type: Audit Success
User:
Computer Name: mojpocitac
Event Code: 4907
Message: Auditing settings on object were changed.
Subject:
Security ID: S-1-5-18
Account Name: MOJPOCITAC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Object:
Object Server: Security
Object Type: File
Object Name: C:\Windows\SysWOW64\en-US\iesetup.dll.mui
Handle ID: 0x14
Process Information:
Process ID: 0x7e4
Process Name: C:\Windows\System32\poqexec.exe
Auditing Settings:
Original Security Descriptor:
New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 3380
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120117163445.872106-000
Event Type: Audit Success
User:
Computer Name: mojpocitac
Event Code: 4907
Message: Auditing settings on object were changed.
Subject:
Security ID: S-1-5-18
Account Name: MOJPOCITAC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Object:
Object Server: Security
Object Type: File
Object Name: C:\Windows\SysWOW64\en-US\ie4uinit.exe.mui
Handle ID: 0x14
Process Information:
Process ID: 0x7e4
Process Name: C:\Windows\System32\poqexec.exe
Auditing Settings:
Original Security Descriptor:
New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 3379
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120117163445.872106-000
Event Type: Audit Success
User:
Computer Name: mojpocitac
Event Code: 4907
Message: Auditing settings on object were changed.
Subject:
Security ID: S-1-5-18
Account Name: MOJPOCITAC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Object:
Object Server: Security
Object Type: File
Object Name: C:\Windows\SysWOW64\en-US\wextract.exe.mui
Handle ID: 0x14
Process Information:
Process ID: 0x7e4
Process Name: C:\Windows\System32\poqexec.exe
Auditing Settings:
Original Security Descriptor:
New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 3378
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120117163445.872106-000
Event Type: Audit Success
User:
Computer Name: mojpocitac
Event Code: 4907
Message: Auditing settings on object were changed.
Subject:
Security ID: S-1-5-18
Account Name: MOJPOCITAC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Object:
Object Server: Security
Object Type: File
Object Name: C:\Windows\SysWOW64\en-US\mshtml.dll.mui
Handle ID: 0x14
Process Information:
Process ID: 0x7e4
Process Name: C:\Windows\System32\poqexec.exe
Auditing Settings:
Original Security Descriptor:
New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 3377
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20120117163445.856506-000
Event Type: Audit Success
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=C:\Program Files (x86)\PC Connectivity Solution\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=4
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=Intel64 Family 6 Model 30 Stepping 5, GenuineIntel
"PROCESSOR_REVISION"=1e05
-----------------EOF-----------------