poprosim o kontrolu, ci tam nemam haved :)
Napsal: 27 led 2014 20:10
info.txt logfile of random's system information tool 1.08 2014-01-27 20:08:36
======Uninstall list======
64 Bit HP CIO Components Installer-->MsiExec.exe /I{FF21C3E6-97FD-474F-9518-8DCBE94C2854}
Adobe Bridge 1.0-->MsiExec.exe /I{B74D4E10-1033-0000-0000-000000000001}
Adobe Common File Installer-->MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5B39}
Adobe Flash Player 12 Plugin-->C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_12_0_0_43_Plugin.exe -maintain plugin
Adobe Help Center 1.0-->MsiExec.exe /I{E9787678-1033-0000-8E67-000000000001}
Adobe Photoshop CS2-->msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D}
Adobe Reader XI (11.0.06) - Slovak-->MsiExec.exe /I{AC76BA86-7AD7-1051-7B44-AB0000000001}
Adobe Stock Photos 1.0-->MsiExec.exe /I{786C5747-1033-0000-B58E-000000000001}
AMD Accelerated Video Transcoding-->MsiExec.exe /X{F800CF18-6470-D909-B460-73F2F41030B4}
AMD APP SDK Runtime-->MsiExec.exe /I{503F672D-6C84-448A-8F8F-4BC35AC83441}
AMD Catalyst Install Manager-->msiexec /q/x{F37A899E-1745-52F5-658F-9A4DA4D46BB7} REBOOT=ReallySuppress
Ashampoo Burning Studio 6 FREE v.6.83-->"C:\Program Files (x86)\Ashampoo\Ashampoo Burning Studio 6 FREE\unins000.exe"
ASUS Xonar U1 Audio-->"C:\Program Files (x86)\InstallShield Installation Information\{71B53BA8-4BE3-49AF-BC3E-07F392006302}\Setup.exe" -runfromtemp -l0x0409 -removeonly /Cmicheck
Bandicam-->"C:\Program Files (x86)\Bandicam\uninstall.exe"
Bandisoft MPEG-1 Decoder-->"C:\Program Files (x86)\BandiMPEG1\uninstall.exe"
Belkin Storage Manager-->MsiExec.exe /X{C12D7D54-7DE8-4DF7-AB2D-8A5ECFB2F89B}
BlueStacks App Player-->C:\Program Files (x86)\BlueStacks\HD-RuntimeUninstaller.exe
BlueStacks Notification Center-->MsiExec.exe /X{44181DF6-2751-48C7-B918-72F14508F127}
Catalyst Control Center - Branding-->MsiExec.exe /I{E72F1051-B87E-4EF4-AE9F-8FDD229CC438}
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
Connectify Hotspot-->C:\Program Files (x86)\Connectify\Uninstall.exe
Counter-Strike: Global Offensive-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/730
D3DX10-->MsiExec.exe /X{E09C4DB7-630C-4F06-A631-8EA7239923AF}
Definition Update for Microsoft Office 2013 (KB2760587) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{BED39C88-768C-4345-BF11-58436C984F2A}" "1051" "0"
Defraggler-->"C:\Program Files\Defraggler\uninst.exe"
Energy Management-->"C:\Program Files (x86)\InstallShield Installation Information\{D0956C11-0F60-43FE-99AD-524E833471BB}\setup.exe" -runfromtemp -l0x041b -removeonly
Energy Management-->MsiExec.exe /I{D0956C11-0F60-43FE-99AD-524E833471BB}
Fotogaléria-->MsiExec.exe /X{08466673-3905-4437-93E8-34A221B7CA4E}
Gunman Clive-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/262550
HiJackThis-->MsiExec.exe /X{45A66726-69BC-466B-A7A4-12FCBA4883D7}
HP Customer Participation Program 14.0-->C:\Program Files (x86)\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat -forcereboot
HP Deskjet F4200 All-In-One Driver Software 14.0 Rel. 6-->C:\Program Files (x86)\HP\Digital Imaging\{8C925017-72A8-4C4A-AF21-84901E26638F}\setup\hpzscr40.exe -datfile hposcr28.dat -onestop -forcereboot
HP Imaging Device Functions 14.0-->C:\Program Files (x86)\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP Solution Center 14.0-->C:\Program Files (x86)\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat -forcereboot
HP Update-->MsiExec.exe /X{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}
Java 7 Update 45-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83217045FF}
KMSpico 4.1-->"C:\Program Files\KMSpico\unins000.exe"
KMSpico v9.0.5.20131111-->"C:\Program Files\KMSpico\unins001.exe"
Left 4 Dead 2-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/550
Little Inferno-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/221260
Logitech Gaming Software 5.10-->MsiExec.exe /X{1444D2EE-C7AD-44A8-844F-2634B49353D1}
LOST PLANET 2-->MsiExec.exe /I{43430808-081A-4C0D-B7CC-601000018301}
LOST PLANET 2-->MsiExec.exe /I{43430808-081A-4C0D-B7CC-601000018302}
MATLAB R2010a-->C:\Program Files\MATLAB\R2010a\uninstall\uninstall.exe C:\Program Files\MATLAB\R2010a\
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack-->MsiExec.exe /X{D1D37853-0004-3E36-A7AA-74F4EEA35F64}
Microsoft .NET Framework 4.5.1 SDK-->MsiExec.exe /X{19A5926D-66E1-46FC-854D-163AA10A52D3}
Microsoft Access MUI (Slovak) 2013-->MsiExec.exe /X{90150000-0015-041B-1000-0000000FF1CE}
Microsoft DCF MUI (Slovak) 2013-->MsiExec.exe /X{90150000-0090-041B-1000-0000000FF1CE}
Microsoft Excel MUI (Slovak) 2013-->MsiExec.exe /X{90150000-0016-041B-1000-0000000FF1CE}
Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}
Microsoft Games for Windows Marketplace-->MsiExec.exe /X{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}
Microsoft Groove MUI (Slovak) 2013-->MsiExec.exe /X{90150000-00BA-041B-1000-0000000FF1CE}
Microsoft InfoPath MUI (Slovak) 2013-->MsiExec.exe /X{90150000-0044-041B-1000-0000000FF1CE}
Microsoft Lync MUI (Slovak) 2013-->MsiExec.exe /X{90150000-012B-041B-1000-0000000FF1CE}
Microsoft Office 2013 Professional Plus-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office 32-bit Components 2013-->MsiExec.exe /X{90150000-00C1-0000-1000-0000000FF1CE}
Microsoft Office Korrekturhilfen 2013 - Deutsch-->MsiExec.exe /X{90150000-001F-0407-1000-0000000FF1CE}
Microsoft Office Nyelvi ellenőrző eszközök 2013 – magyar-->MsiExec.exe /X{90150000-001F-040E-1000-0000000FF1CE}
Microsoft Office OSM MUI (Slovak) 2013-->MsiExec.exe /X{90150000-00E1-041B-1000-0000000FF1CE}
Microsoft Office OSM UX MUI (Slovak) 2013-->MsiExec.exe /X{90150000-00E2-041B-1000-0000000FF1CE}
Microsoft Office Professional Plus 2013-->MsiExec.exe /X{90150000-0011-0000-1000-0000000FF1CE}
Microsoft Office Proofing (Slovak) 2013-->MsiExec.exe /X{90150000-002C-041B-1000-0000000FF1CE}
Microsoft Office Proofing Tools 2013 - English-->MsiExec.exe /X{90150000-001F-0409-1000-0000000FF1CE}
Microsoft Office Shared 32-bit MUI (Slovak) 2013-->MsiExec.exe /X{90150000-00C1-041B-1000-0000000FF1CE}
Microsoft Office Shared MUI (Slovak) 2013-->MsiExec.exe /X{90150000-006E-041B-1000-0000000FF1CE}
Microsoft OneNote MUI (Slovak) 2013-->MsiExec.exe /X{90150000-00A1-041B-1000-0000000FF1CE}
Microsoft Outlook MUI (Slovak) 2013-->MsiExec.exe /X{90150000-001A-041B-1000-0000000FF1CE}
Microsoft PowerPoint MUI (Slovak) 2013-->MsiExec.exe /X{90150000-0018-041B-1000-0000000FF1CE}
Microsoft Publisher MUI (Slovak) 2013-->MsiExec.exe /X{90150000-0019-041B-1000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17-->MsiExec.exe /X{8220EEFE-38CD-377E-8595-13398D740ACE}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148-->MsiExec.exe /X{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161-->MsiExec.exe /X{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219-->MsiExec.exe /X{1D8E6291-B0D5-35EC-8441-6616F567A0F7}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219-->MsiExec.exe /X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727-->"C:\ProgramData\Package Cache\{15134cb0-b767-4960-a911-f2d16ae54797}\vcredist_x64.exe" /uninstall
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727-->"C:\ProgramData\Package Cache\{22154f09-719a-4619-bb71-5b3356999fbf}\vcredist_x86.exe" /uninstall
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106-->"C:\ProgramData\Package Cache\{8e70e4e1-06d7-470b-9f74-a51bef21088e}\vcredist_x86.exe" /uninstall
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727-->MsiExec.exe /X{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727-->MsiExec.exe /X{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727-->MsiExec.exe /X{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106-->MsiExec.exe /X{6C772996-BFF3-3C8C-860B-B3D48FF05D65}
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727-->MsiExec.exe /X{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106-->MsiExec.exe /X{E824E81C-80A4-3DFF-B5F9-4842A9FF5F7F}
Microsoft Word MUI (Slovak) 2013-->MsiExec.exe /X{90150000-001B-041B-1000-0000000FF1CE}
Microsoft XNA Framework Redistributable 4.0-->MsiExec.exe /I{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}
Movie Maker-->MsiExec.exe /X{45898170-E68C-4F02-AA35-C2186BF347A3}
Movie Maker-->MsiExec.exe /X{CFBFE244-6269-41DC-85B6-86F99C88ED02}
Mozilla Firefox 26.0 (x86 sk)-->"C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe"
MPC-HC 1.7.1 (64-bit)-->"C:\Program Files\MPC-HC\unins000.exe"
MSVCRT-->MsiExec.exe /I{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
MSVCRT110_amd64-->MsiExec.exe /I{E9FA781F-3E80-4399-825A-AD3E11C28C77}
MSVCRT110-->MsiExec.exe /I{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}
MSXML 4.0 SP3 Parser-->MsiExec.exe /I{196467F1-C11F-4F76-858B-5812ADC83B94}
Nástroje kontroly pravopisu pro Microsoft Office 2013 – čeština-->MsiExec.exe /X{90150000-001F-0405-1000-0000000FF1CE}
Nástroje korektúry balíka Microsoft Office 2013 - slovenčina-->MsiExec.exe /X{90150000-001F-041B-1000-0000000FF1CE}
OCR Software by I.R.I.S. 14.0-->C:\Program Files (x86)\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
OpenAL-->"C:\Program Files (x86)\OpenAL\openalweax.exe" /U
Photo Common-->MsiExec.exe /X{140754E1-C019-44A9-A81B-2D7625AABE8A}
Photo Gallery-->MsiExec.exe /X{0F929651-F516-4956-90F2-FFBD2CD5D30E}
PingPlotter Standard 3.41.0s-->MsiExec.exe /I{57CE9ADD-8C74-42EF-92CE-3A7736877FB4}
Race Driver 3-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{0297C87B-CC40-446F-865A-031B4FC0CF22}\setup.exe" -l0x9 -removeonly
RaceRoom Racing Experience -->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/211500
RaceRoom Racing Experience Launcher-->"C:\Program Files (x86)\Steam\steamapps\common\raceroom racing experience\Game\unins000.exe"
Secure Download Manager-->MsiExec.exe /I{E86B07AE-9F94-44D5-AD47-DC2716EA90D2}
Security Update for Microsoft Excel 2013 (KB2827238) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{41DF329D-1966-484D-8856-53E9491D998D}" "1051" "0"
Security Update for Microsoft Excel 2013 (KB2827238) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0016-041B-1000-0000000FF1CE}" "{3D587B45-A0E2-429B-A2C0-C2F51D959461}" "1051" "0"
Security Update for Microsoft Excel 2013 (KB2827238) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0018-041B-1000-0000000FF1CE}" "{3D587B45-A0E2-429B-A2C0-C2F51D959461}" "1051" "0"
Security Update for Microsoft Excel 2013 (KB2827238) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001B-041B-1000-0000000FF1CE}" "{3D587B45-A0E2-429B-A2C0-C2F51D959461}" "1051" "0"
Security Update for Microsoft Lync 2013 (KB2850057) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{AC8EFFF5-000D-4205-9164-34E346CC6009}" "1051" "0"
Security Update for Microsoft Lync 2013 (KB2850057) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{AC8EFFF5-000D-4205-9164-34E346CC6009}" "1051" "0"
Security Update for Microsoft Lync 2013 (KB2850057) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-012B-041B-1000-0000000FF1CE}" "{DC7B7C7D-DF6D-4E6C-98B6-E268467E5304}" "1051" "0"
Security Update for Microsoft Office 2013 (KB2768005) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-006E-041B-1000-0000000FF1CE}" "{46039EDC-E241-4720-95D6-93592A718538}" "1051" "0"
Security Update for Microsoft Office 2013 (KB2810009) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{D6F7BF27-F97C-4D16-9121-7C19A112EA5A}" "1051" "0"
Security Update for Microsoft Office 2013 (KB2850064) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{E1AECEC1-DB6E-4AEC-BBC7-9D0A7B953011}" "1051" "0"
Security Update for Microsoft Office 2013 (KB2850064) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-006E-041B-1000-0000000FF1CE}" "{CC5D6392-DF56-4D25-B5A1-3A1B7F70741B}" "1051" "0"
Security Update for Microsoft Office 2013 (KB2850064) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{E1AECEC1-DB6E-4AEC-BBC7-9D0A7B953011}" "1051" "0"
Security Update for Microsoft Word 2013 (KB2827224) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{D7763B39-229C-4059-8D29-A4CC1C85F5EE}" "1051" "0"
Security Update for Microsoft Word 2013 (KB2863834) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{64553791-813D-4D5B-8F17-A7A72BEB44CA}" "1051" "0"
Skype™ 6.9-->MsiExec.exe /X{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}
Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
TAP-Windows 9.9.2-->C:\Program Files\TAP-Windows\Uninstall.exe
TeamSpeak 3 Client-->"C:\Program Files\TeamSpeak 3 Client\uninstall.exe"
tools-freebsd-->MsiExec.exe /X{003BFBBD-6C67-419E-A24D-0DCAFC3A5249}
tools-linux-->MsiExec.exe /X{D102611A-6466-4101-A51D-51069303AC65}
tools-netware-->MsiExec.exe /X{197597A7-AD33-4898-9D8E-73066818B464}
tools-solaris-->MsiExec.exe /X{AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4}
tools-windows-->MsiExec.exe /X{FFD9383C-01D5-4897-A954-43AF599AED30}
tools-winPre2k-->MsiExec.exe /X{AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D}
Total Commander 64-bit (Remove or Repair)-->c:\totalcmd\tcunin64.exe
Update for Microsoft Access 2013 (KB2768008) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0015-041B-1000-0000000FF1CE}" "{279D6F0F-7988-4CD8-8E93-BA9E61C58672}" "1051" "0"
Update for Microsoft Access 2013 (KB2827233) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{614E655F-A0ED-435A-8E0C-A81EE4BA7BC7}" "1051" "0"
Update for Microsoft InfoPath 2013 (KB2837648) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{5E759A69-FA72-4B3C-BE2F-D1194764D31E}" "1051" "0"
Update for Microsoft Lync 2013 (KB2817678) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-012B-041B-1000-0000000FF1CE}" "{27F1BD0D-3359-45EB-9FE8-A49D3FC4DD48}" "1051" "0"
Update for Microsoft Office 2013 (KB2726954) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{43EB1F58-DAA0-4F61-A4EE-C5651F85A047}" "1051" "0"
Update for Microsoft Office 2013 (KB2726954) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{43EB1F58-DAA0-4F61-A4EE-C5651F85A047}" "1051" "0"
Update for Microsoft Office 2013 (KB2726996) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{76CACE05-7A19-4EAC-87D7-5BFF63AF7CDF}" "1051" "0"
Update for Microsoft Office 2013 (KB2726996) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{76CACE05-7A19-4EAC-87D7-5BFF63AF7CDF}" "1051" "0"
Update for Microsoft Office 2013 (KB2738038) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{FEFF9FF6-FF61-455E-A8CC-3A1311A657AD}" "1051" "0"
Update for Microsoft Office 2013 (KB2760224) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{3FF4EA9F-3505-4726-A974-6593A968FFCC}" "1051" "0"
Update for Microsoft Office 2013 (KB2760242) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{9406D70B-2D9C-4613-A75A-F35B66BA8AFA}" "1051" "0"
Update for Microsoft Office 2013 (KB2760267) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{CA390537-AA88-450F-A240-5FB4648A124A}" "1051" "0"
Update for Microsoft Office 2013 (KB2760539) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{C8D57F4A-0824-4043-89E7-3C6280B67A47}" "1051" "0"
Update for Microsoft Office 2013 (KB2760553) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{AC4470FB-8011-4F16-B5D4-E0A34DE10C87}" "1051" "0"
Update for Microsoft Office 2013 (KB2760610) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{D8B3D175-48B8-413F-8484-4D81E744B51C}" "1051" "0"
Update for Microsoft Office 2013 (KB2767845) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{8587E5B1-6279-4396-B9AC-20B334F4FF88}" "1051" "0"
Update for Microsoft Office 2013 (KB2817314) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{C809B1D6-BD31-4496-BCFE-4567E0854F5F}" "1051" "0"
Update for Microsoft Office 2013 (KB2817316) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{4FD8F672-3206-469C-B9F0-D6E72F7ACAB2}" "1051" "0"
Update for Microsoft Office 2013 (KB2817316) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0016-041B-1000-0000000FF1CE}" "{856D47BC-036C-4692-8702-D6CCA8F428D0}" "1051" "0"
Update for Microsoft Office 2013 (KB2817316) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0016-041B-1000-0000000FF1CE}" "{ABA98B77-725D-486B-AE3F-1693C9BBA465}" "1051" "0"
Update for Microsoft Office 2013 (KB2817490) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{CA0554C4-62FE-4F66-BC87-1EE1EAC675EF}" "1051" "0"
Update for Microsoft Office 2013 (KB2817490) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{CA0554C4-62FE-4F66-BC87-1EE1EAC675EF}" "1051" "0"
Update for Microsoft Office 2013 (KB2817626) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{F33ABF6A-3007-47E8-8E38-506A18E54641}" "1051" "0"
Update for Microsoft Office 2013 (KB2826004) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{B38036CB-BAF6-41D4-8810-FD016453ABB9}" "1051" "0"
Update for Microsoft Office 2013 (KB2827225) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{2A286156-257B-4528-9DB5-B4D4D53211BC}" "1051" "0"
Update for Microsoft Office 2013 (KB2827227) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-0405-1000-0000000FF1CE}" "{80684D6D-09BB-4E1C-A47A-45068EBAAE5E}" "1051" "0"
Update for Microsoft Office 2013 (KB2827227) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-0407-1000-0000000FF1CE}" "{B5E3E636-7913-4775-BC9B-E4B56F4ED73B}" "1051" "0"
Update for Microsoft Office 2013 (KB2827227) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-0409-1000-0000000FF1CE}" "{92833C80-DC88-4A22-8630-407F810EF57B}" "1051" "0"
Update for Microsoft Office 2013 (KB2827227) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-040E-1000-0000000FF1CE}" "{92F6DDB7-0BC3-46C2-9E7F-4686247B38DA}" "1051" "0"
Update for Microsoft Office 2013 (KB2827227) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-041B-1000-0000000FF1CE}" "{4BE3996F-99D2-4917-87FF-6380CCFECF06}" "1051" "0"
Update for Microsoft Office 2013 (KB2827230) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{F2187E8D-C68A-4655-8551-1932878A5581}" "1051" "0"
Update for Microsoft Office 2013 (KB2827239) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{9353CD85-4B19-45C4-8DBA-1391926351F6}" "1051" "0"
Update for Microsoft Office 2013 (KB2827239) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{9353CD85-4B19-45C4-8DBA-1391926351F6}" "1051" "0"
Update for Microsoft Office 2013 (KB2837626) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{6EE51F51-57B1-4DC7-96C2-857DB7F0BE93}" "1051" "0"
Update for Microsoft Office 2013 (KB2837637) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{0A90C645-3F9A-4CF9-BF62-2609602E3DAB}" "1051" "0"
Update for Microsoft Office 2013 (KB2837638) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{3A48DE63-607B-4FEA-A862-B52669C4433C}" "1051" "0"
Update for Microsoft Office 2013 (KB2837655) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{C4B559C7-AA71-4B77-ACA3-50BEA8B4241B}" "1051" "0"
Update for Microsoft Office 2013 (KB2837655) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-006E-041B-1000-0000000FF1CE}" "{D770FC63-2A57-4BF0-82E2-0CD4A5BB6A64}" "1051" "0"
Update for Microsoft Office 2013 (KB2837655) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{C4B559C7-AA71-4B77-ACA3-50BEA8B4241B}" "1051" "0"
Update for Microsoft Office 2013 (KB2850066) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{000791D2-642D-418E-A3E9-96E72D8C67B8}" "1051" "0"
Update for Microsoft Office 2013 (KB2850066) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{000791D2-642D-418E-A3E9-96E72D8C67B8}" "1051" "0"
Update for Microsoft OneNote 2013 (KB2850063) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{CF6FBF49-BE22-4B98-9D7D-CB2A3236BC44}" "1051" "0"
Update for Microsoft OneNote 2013 (KB2850063) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00A1-041B-1000-0000000FF1CE}" "{AB85EA97-E873-4BB2-9CBB-5506B277BC9D}" "1051" "0"
Update for Microsoft OneNote 2013 (KB2850063) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{CF6FBF49-BE22-4B98-9D7D-CB2A3236BC44}" "1051" "0"
Update for Microsoft Outlook 2013 (KB2850061) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{E8F64CB5-1419-47A8-9FCE-F6E4137F2D25}" "1051" "0"
Update for Microsoft Outlook 2013 (KB2850061) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001A-041B-1000-0000000FF1CE}" "{9C190EC8-21F6-40A0-A08D-4DF49D2C8783}" "1051" "0"
Update for Microsoft PowerPoint 2013 (KB2767850) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{6FF949A3-1C3F-41C2-9464-933E885ECB53}" "1051" "0"
Update for Microsoft PowerPoint 2013 (KB2767850) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0018-041B-1000-0000000FF1CE}" "{F3988C37-090B-45AB-895E-97215250FA5F}" "1051" "0"
Update for Microsoft Project 2013 (KB2727085) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{BBD4F4CE-65D4-4CEB-AE19-E5296A57AA6C}" "1051" "0"
Update for Microsoft Publisher 2013 (KB2837635) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{2837C624-A972-43CF-BCE5-0AE2EFED72E3}" "1051" "0"
Update for Microsoft Publisher 2013 (KB2837635) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0019-041B-1000-0000000FF1CE}" "{4BBDE72A-96E5-4619-861C-A35A860A4743}" "1051" "0"
Update for Microsoft SkyDrive Pro (KB2817495) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{A3417E9E-5B94-4BFF-AAA4-933B1AE46306}" "1051" "0"
Update for Microsoft SkyDrive Pro (KB2817495) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{A3417E9E-5B94-4BFF-AAA4-933B1AE46306}" "1051" "0"
Update for Microsoft SkyDrive Pro (KB2837652) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00BA-041B-1000-0000000FF1CE}" "{42BF90E0-1B49-4A35-A4F3-83ED52250403}" "1051" "0"
Update for Microsoft SkyDrive Pro (KB2837652) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-041B-1000-0000000FF1CE}" "{42BF90E0-1B49-4A35-A4F3-83ED52250403}" "1051" "0"
Update for Microsoft Visio 2013 (KB2817306) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{F16E7B82-23FE-4054-AB73-EAE53965251C}" "1051" "0"
Update for Microsoft Visio Viewer 2013 (KB2768338) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{D1F1940B-94DF-4DCB-BF82-9530D7FBB1BF}" "1051" "0"
Update for Microsoft Word 2013 (KB2837647) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001A-041B-1000-0000000FF1CE}" "{532F2B3B-E996-4BEC-AB32-BD45D3F6B93E}" "1051" "0"
Update for Microsoft Word 2013 (KB2837647) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001B-041B-1000-0000000FF1CE}" "{532F2B3B-E996-4BEC-AB32-BD45D3F6B93E}" "1051" "0"
Update for Microsoft Word 2013 (KB2837647) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-012B-041B-1000-0000000FF1CE}" "{532F2B3B-E996-4BEC-AB32-BD45D3F6B93E}" "1051" "0"
VLC media player 2.1.1-->C:\Program Files (x86)\VideoLAN\VLC\uninstall.exe
VMware Workstation-->"C:\ProgramData\VMware\VMware Workstation\Uninstaller\\uninstall.exe" -x -S "C:\ProgramData\VMware\VMware Workstation\Uninstaller\"
VMware Workstation-->MsiExec.exe /I{0D94F75A-0EA6-4951-B3AF-B145FA9E05C6}
War Thunder-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/236390
Windows 7 USB/DVD Download Tool-->MsiExec.exe /X{CCF298AF-9CE1-4B26-B251-486E98A34789}
Windows Driver Package - Lenovo (ACPIVPC) System (06/15/2012 8.1.0.1)-->C:\PROGRA~1\DIFX\8C6574~1\DPInst.exe /u C:\Windows\System32\DriverStore\FileRepository\vpc.inf_amd64_37c65821ee7b9e70\vpc.inf
Windows Driver Package - Lenovo (WUDFRd) LenovoVhid (06/19/2012 10.13.29.733)-->C:\PROGRA~1\DIFX\8C6574~1\DPInst.exe /u C:\Windows\System32\DriverStore\FileRepository\wudfvhidmini.inf_amd64_4f86ecaa9af0d5de\wudfvhidmini.inf
Windows Live Communications Platform-->MsiExec.exe /I{03D562B5-C4E2-4846-A920-33178788BE00}
Windows Live Essentials-->C:\Program Files (x86)\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{FA29B84F-8306-4A62-A340-F2C41305E7AF}
Windows Live Installer-->MsiExec.exe /I{5A0EE0F0-E909-4F3B-B437-AAD9252427CB}
Windows Live Photo Common-->MsiExec.exe /X{C6B0EE9E-2128-4448-B7AE-5E2B46E0F0E7}
Windows Live PIMT Platform-->MsiExec.exe /I{E3445598-4424-4EE2-B71C-C23325F7FB71}
Windows Live SOXE Definitions-->MsiExec.exe /I{0FF9CC94-EF23-401E-BDBD-37403D1A2B38}
Windows Live SOXE-->MsiExec.exe /I{6B6923B9-8719-425B-916C-CD2908F31AAF}
Windows Live UX Platform Language Pack-->MsiExec.exe /I{28950295-A98C-4081-AC82-045E9879945E}
Windows Live UX Platform-->MsiExec.exe /I{F0E58739-2B4C-498F-9B0D-FF0F2FD52B61}
Windows Mobile Device Updater Component-->MsiExec.exe /X{F2CB8C3C-9C9E-4FAB-9067-655601C5F748}
WinRAR 4.20 (64-bit)-->C:\Program Files\WinRAR\uninstall.exe
World of Tanks-->"D:\Games\WoT\unins000.exe"
Worms Revolution-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/200170
Zune Language Pack (CSY)-->MsiExec.exe /X{A8F2E50B-86E2-4D96-9BD2-9758BCC6F9B3}
Zune Language Pack (DAN)-->MsiExec.exe /X{8B112338-2B08-4851-AF84-E7CAD74CEB32}
Zune Language Pack (DEU)-->MsiExec.exe /X{BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}
Zune Language Pack (ELL)-->MsiExec.exe /X{3589A659-F732-4E65-A89A-5438C332E59D}
Zune Language Pack (ESP)-->MsiExec.exe /X{6B33492E-FBBC-4EC3-8738-09E16E395A10}
Zune Language Pack (FIN)-->MsiExec.exe /X{B4870774-5F3A-46D9-9DFE-06FB5599E26B}
Zune Language Pack (FRA)-->MsiExec.exe /X{C68D33B1-0204-4EBE-BC45-A6E432B1D13A}
Zune Language Pack (HUN)-->MsiExec.exe /X{C6BE19C6-B102-4038-B2A6-1C313872DBB4}
Zune Language Pack (CHS)-->MsiExec.exe /X{2A9DFFD8-4E09-4B91-B957-454805B0D7C4}
Zune Language Pack (CHT)-->MsiExec.exe /X{A5A53EA8-A11E-49F0-BDF5-AE536426A31A}
Zune Language Pack (IND)-->MsiExec.exe /X{92ECE3F9-591E-4C12-8A62-B9FCE38BF646}
Zune Language Pack (ITA)-->MsiExec.exe /X{C5D37FFA-7483-410B-982B-91E93FD3B7DA}
Zune Language Pack (JPN)-->MsiExec.exe /X{D8A781C9-3892-4E2E-9320-480CF896CFBB}
Zune Language Pack (KOR)-->MsiExec.exe /X{51C839E1-2BE4-4E77-A1BA-CCEA5DAFA741}
Zune Language Pack (MSL)-->MsiExec.exe /X{76BA306B-2AA0-47C0-AB6B-F313AB56C136}
Zune Language Pack (NLD)-->MsiExec.exe /X{6740BCB0-5863-47F4-80F4-44F394DE4FE2}
Zune Language Pack (NOR)-->MsiExec.exe /X{5DEFD397-4012-46C3-B6DA-E8013E660772}
Zune Language Pack (PLK)-->MsiExec.exe /X{8960A0A1-BB5A-479E-92CF-65AB9D684B43}
Zune Language Pack (PTB)-->MsiExec.exe /X{07EEE598-5F21-4B57-B40B-46592625B3D9}
Zune Language Pack (PTG)-->MsiExec.exe /X{5C93E291-A1CC-4E51-85C6-E194209FCDB4}
Zune Language Pack (RUS)-->MsiExec.exe /X{57C51D56-B287-4C11-9192-EC3C46EF76A4}
Zune Language Pack (SVE)-->MsiExec.exe /X{6EB931CD-A7DA-4A44-B74A-89C8EB50086F}
Zune-->C:\Program Files\Zune\ZuneSetup.exe /x
Zune-->MsiExec.exe /X{9B75648B-6C30-4A0D-9DE6-0D09D20AF5A5}
======System event log======
Computer Name: Lacko
Event Code: 28
Message: Lokálny adaptér nepodporuje funkciu nedostatku energie rozhrania Bluetooth.
Record Number: 154
Source Name: BTHUSB
Time Written: 20130816200148.664446-000
Event Type: Warning
User:
Computer Name: windows-e3tqq9a
Event Code: 28
Message: Lokálny adaptér nepodporuje funkciu nedostatku energie rozhrania Bluetooth.
Record Number: 86
Source Name: BTHUSB
Time Written: 20130816200022.241145-000
Event Type: Warning
User:
Computer Name: windows-e3tqq9a
Event Code: 7023
Message: Služba Služba zoznamu sietí bola ukončená s nasledujúcou chybou:
Zariadenie nie je pripravené.
Record Number: 39
Source Name: Service Control Manager
Time Written: 20130816200005.798609-000
Event Type: Error
User:
Computer Name: windows-e3tqq9a
Event Code: 7023
Message: Služba IP Helper bola ukončená s nasledujúcou chybou:
Služba sa nedá spustiť, pretože je vypnutá, alebo nemá priradené žiadne zapnuté zariadenia.
Record Number: 37
Source Name: Service Control Manager
Time Written: 20130816200004.238595-000
Event Type: Error
User:
Computer Name: windows-e3tqq9a
Event Code: 46
Message: Crash dump initialization failed!
Record Number: 14
Source Name: volmgr
Time Written: 20130816195910.449304-000
Event Type: Error
User:
=====Application event log=====
Computer Name: Lacko
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. No user action is required.
DETAIL -
62 user registry handles leaked from \Registry\User\S-1-5-21-3352856905-2808976808-1590191317-1001:
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\MY
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\CA
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\CA
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\CA
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\CA
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\TrustedPeople
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\TrustedPeople
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\TrustedPeople
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\Root
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\Root
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\Root
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\Root
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\Disallowed
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\Disallowed
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\Disallowed
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\Disallowed
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\trust
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\trust
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\trust
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\trust
Record Number: 326
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20130816202752.922781-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: Lacko
Event Code: 3006
Message: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Record Number: 75
Source Name: Microsoft-Windows-LoadPerf
Time Written: 20130816200749.571324-000
Event Type: Error
User: NT AUTHORITY\SYSTEM
Computer Name: Lacko
Event Code: 3006
Message: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Record Number: 73
Source Name: Microsoft-Windows-LoadPerf
Time Written: 20130816200749.493320-000
Event Type: Error
User: NT AUTHORITY\SYSTEM
Computer Name: Lacko
Event Code: 1008
Message: Služba Windows Search sa spúšťa a pokúša sa odstrániť starý index hľadania. {Dôvod: Full Index Reset}.
Record Number: 42
Source Name: Microsoft-Windows-Search
Time Written: 20130816200407.000000-000
Event Type: Warning
User:
Computer Name: Lacko
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. No user action is required.
DETAIL -
14 user registry handles leaked from \Registry\User\S-1-5-21-3352856905-2808976808-1590191317-1001:
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\CA
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\TrustedPeople
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\Root
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\Disallowed
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\trust
Record Number: 40
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20130816200402.573443-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
=====Security event log=====
Computer Name: Lacko
Event Code: 4907
Message: Auditing settings on object were changed.
Subject:
Security ID: S-1-5-18
Account Name: LACKO$
Account Domain: WORKGROUP
Logon ID: 0x3E7
Object:
Object Server: Security
Object Type: File
Object Name: C:\Windows\System32\mfasfsrcsnk.dll
Handle ID: 0x34
Process Information:
Process ID: 0x740
Process Name: C:\Windows\System32\poqexec.exe
Auditing Settings:
Original Security Descriptor: S:AI
New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 5246
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20130821073526.853524-000
Event Type: Audit Success
User:
Computer Name: Lacko
Event Code: 4907
Message: Auditing settings on object were changed.
Subject:
Security ID: S-1-5-18
Account Name: LACKO$
Account Domain: WORKGROUP
Logon ID: 0x3E7
Object:
Object Server: Security
Object Type: File
Object Name: C:\Windows\System32\vdsutil.dll
Handle ID: 0x34
Process Information:
Process ID: 0x740
Process Name: C:\Windows\System32\poqexec.exe
Auditing Settings:
Original Security Descriptor: S:AI
New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 5245
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20130821073526.837900-000
Event Type: Audit Success
User:
Computer Name: Lacko
Event Code: 4907
Message: Auditing settings on object were changed.
Subject:
Security ID: S-1-5-18
Account Name: LACKO$
Account Domain: WORKGROUP
Logon ID: 0x3E7
Object:
Object Server: Security
Object Type: File
Object Name: C:\Windows\System32\samsrv.dll
Handle ID: 0x34
Process Information:
Process ID: 0x740
Process Name: C:\Windows\System32\poqexec.exe
Auditing Settings:
Original Security Descriptor: S:AI
New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 5244
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20130821073526.806690-000
Event Type: Audit Success
User:
Computer Name: Lacko
Event Code: 4907
Message: Auditing settings on object were changed.
Subject:
Security ID: S-1-5-18
Account Name: LACKO$
Account Domain: WORKGROUP
Logon ID: 0x3E7
Object:
Object Server: Security
Object Type: File
Object Name: C:\Windows\System32\audiosrv.dll
Handle ID: 0x34
Process Information:
Process ID: 0x740
Process Name: C:\Windows\System32\poqexec.exe
Auditing Settings:
Original Security Descriptor: S:AI
New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 5243
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20130821073526.775524-000
Event Type: Audit Success
User:
Computer Name: Lacko
Event Code: 4907
Message: Auditing settings on object were changed.
Subject:
Security ID: S-1-5-18
Account Name: LACKO$
Account Domain: WORKGROUP
Logon ID: 0x3E7
Object:
Object Server: Security
Object Type: File
Object Name: C:\Windows\System32\MbaeParserTask.exe
Handle ID: 0x34
Process Information:
Process ID: 0x740
Process Name: C:\Windows\System32\poqexec.exe
Auditing Settings:
Original Security Descriptor: S:AI
New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 5242
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20130821073526.728723-000
Event Type: Audit Success
User:
======Environment variables======
"FP_NO_HOST_CHECK"=NO
"USERNAME"=SYSTEM
"ComSpec"=%SystemRoot%\system32\cmd.exe
"TMP"=%SystemRoot%\TEMP
"OS"=Windows_NT
"windir"=%SystemRoot%
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=3
"PROCESSOR_LEVEL"=16
"PROCESSOR_IDENTIFIER"=AMD64 Family 16 Model 5 Stepping 3, AuthenticAMD
"PROCESSOR_REVISION"=0503
"Path"=C:\Program Files (x86)\AMD APP\bin\x86_64;C:\Program Files (x86)\AMD APP\bin\x86;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\MATLAB\R2010a\runtime\win64;C:\Program Files\MATLAB\R2010a\bin;C:\Program Files (x86)\Windows Live\Shared
"AMDAPPSDKROOT"=C:\Program Files (x86)\AMD APP\
-----------------EOF-----------------
======Uninstall list======
64 Bit HP CIO Components Installer-->MsiExec.exe /I{FF21C3E6-97FD-474F-9518-8DCBE94C2854}
Adobe Bridge 1.0-->MsiExec.exe /I{B74D4E10-1033-0000-0000-000000000001}
Adobe Common File Installer-->MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5B39}
Adobe Flash Player 12 Plugin-->C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_12_0_0_43_Plugin.exe -maintain plugin
Adobe Help Center 1.0-->MsiExec.exe /I{E9787678-1033-0000-8E67-000000000001}
Adobe Photoshop CS2-->msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D}
Adobe Reader XI (11.0.06) - Slovak-->MsiExec.exe /I{AC76BA86-7AD7-1051-7B44-AB0000000001}
Adobe Stock Photos 1.0-->MsiExec.exe /I{786C5747-1033-0000-B58E-000000000001}
AMD Accelerated Video Transcoding-->MsiExec.exe /X{F800CF18-6470-D909-B460-73F2F41030B4}
AMD APP SDK Runtime-->MsiExec.exe /I{503F672D-6C84-448A-8F8F-4BC35AC83441}
AMD Catalyst Install Manager-->msiexec /q/x{F37A899E-1745-52F5-658F-9A4DA4D46BB7} REBOOT=ReallySuppress
Ashampoo Burning Studio 6 FREE v.6.83-->"C:\Program Files (x86)\Ashampoo\Ashampoo Burning Studio 6 FREE\unins000.exe"
ASUS Xonar U1 Audio-->"C:\Program Files (x86)\InstallShield Installation Information\{71B53BA8-4BE3-49AF-BC3E-07F392006302}\Setup.exe" -runfromtemp -l0x0409 -removeonly /Cmicheck
Bandicam-->"C:\Program Files (x86)\Bandicam\uninstall.exe"
Bandisoft MPEG-1 Decoder-->"C:\Program Files (x86)\BandiMPEG1\uninstall.exe"
Belkin Storage Manager-->MsiExec.exe /X{C12D7D54-7DE8-4DF7-AB2D-8A5ECFB2F89B}
BlueStacks App Player-->C:\Program Files (x86)\BlueStacks\HD-RuntimeUninstaller.exe
BlueStacks Notification Center-->MsiExec.exe /X{44181DF6-2751-48C7-B918-72F14508F127}
Catalyst Control Center - Branding-->MsiExec.exe /I{E72F1051-B87E-4EF4-AE9F-8FDD229CC438}
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
Connectify Hotspot-->C:\Program Files (x86)\Connectify\Uninstall.exe
Counter-Strike: Global Offensive-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/730
D3DX10-->MsiExec.exe /X{E09C4DB7-630C-4F06-A631-8EA7239923AF}
Definition Update for Microsoft Office 2013 (KB2760587) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{BED39C88-768C-4345-BF11-58436C984F2A}" "1051" "0"
Defraggler-->"C:\Program Files\Defraggler\uninst.exe"
Energy Management-->"C:\Program Files (x86)\InstallShield Installation Information\{D0956C11-0F60-43FE-99AD-524E833471BB}\setup.exe" -runfromtemp -l0x041b -removeonly
Energy Management-->MsiExec.exe /I{D0956C11-0F60-43FE-99AD-524E833471BB}
Fotogaléria-->MsiExec.exe /X{08466673-3905-4437-93E8-34A221B7CA4E}
Gunman Clive-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/262550
HiJackThis-->MsiExec.exe /X{45A66726-69BC-466B-A7A4-12FCBA4883D7}
HP Customer Participation Program 14.0-->C:\Program Files (x86)\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat -forcereboot
HP Deskjet F4200 All-In-One Driver Software 14.0 Rel. 6-->C:\Program Files (x86)\HP\Digital Imaging\{8C925017-72A8-4C4A-AF21-84901E26638F}\setup\hpzscr40.exe -datfile hposcr28.dat -onestop -forcereboot
HP Imaging Device Functions 14.0-->C:\Program Files (x86)\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP Solution Center 14.0-->C:\Program Files (x86)\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat -forcereboot
HP Update-->MsiExec.exe /X{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}
Java 7 Update 45-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83217045FF}
KMSpico 4.1-->"C:\Program Files\KMSpico\unins000.exe"
KMSpico v9.0.5.20131111-->"C:\Program Files\KMSpico\unins001.exe"
Left 4 Dead 2-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/550
Little Inferno-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/221260
Logitech Gaming Software 5.10-->MsiExec.exe /X{1444D2EE-C7AD-44A8-844F-2634B49353D1}
LOST PLANET 2-->MsiExec.exe /I{43430808-081A-4C0D-B7CC-601000018301}
LOST PLANET 2-->MsiExec.exe /I{43430808-081A-4C0D-B7CC-601000018302}
MATLAB R2010a-->C:\Program Files\MATLAB\R2010a\uninstall\uninstall.exe C:\Program Files\MATLAB\R2010a\
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack-->MsiExec.exe /X{D1D37853-0004-3E36-A7AA-74F4EEA35F64}
Microsoft .NET Framework 4.5.1 SDK-->MsiExec.exe /X{19A5926D-66E1-46FC-854D-163AA10A52D3}
Microsoft Access MUI (Slovak) 2013-->MsiExec.exe /X{90150000-0015-041B-1000-0000000FF1CE}
Microsoft DCF MUI (Slovak) 2013-->MsiExec.exe /X{90150000-0090-041B-1000-0000000FF1CE}
Microsoft Excel MUI (Slovak) 2013-->MsiExec.exe /X{90150000-0016-041B-1000-0000000FF1CE}
Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}
Microsoft Games for Windows Marketplace-->MsiExec.exe /X{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}
Microsoft Groove MUI (Slovak) 2013-->MsiExec.exe /X{90150000-00BA-041B-1000-0000000FF1CE}
Microsoft InfoPath MUI (Slovak) 2013-->MsiExec.exe /X{90150000-0044-041B-1000-0000000FF1CE}
Microsoft Lync MUI (Slovak) 2013-->MsiExec.exe /X{90150000-012B-041B-1000-0000000FF1CE}
Microsoft Office 2013 Professional Plus-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office 32-bit Components 2013-->MsiExec.exe /X{90150000-00C1-0000-1000-0000000FF1CE}
Microsoft Office Korrekturhilfen 2013 - Deutsch-->MsiExec.exe /X{90150000-001F-0407-1000-0000000FF1CE}
Microsoft Office Nyelvi ellenőrző eszközök 2013 – magyar-->MsiExec.exe /X{90150000-001F-040E-1000-0000000FF1CE}
Microsoft Office OSM MUI (Slovak) 2013-->MsiExec.exe /X{90150000-00E1-041B-1000-0000000FF1CE}
Microsoft Office OSM UX MUI (Slovak) 2013-->MsiExec.exe /X{90150000-00E2-041B-1000-0000000FF1CE}
Microsoft Office Professional Plus 2013-->MsiExec.exe /X{90150000-0011-0000-1000-0000000FF1CE}
Microsoft Office Proofing (Slovak) 2013-->MsiExec.exe /X{90150000-002C-041B-1000-0000000FF1CE}
Microsoft Office Proofing Tools 2013 - English-->MsiExec.exe /X{90150000-001F-0409-1000-0000000FF1CE}
Microsoft Office Shared 32-bit MUI (Slovak) 2013-->MsiExec.exe /X{90150000-00C1-041B-1000-0000000FF1CE}
Microsoft Office Shared MUI (Slovak) 2013-->MsiExec.exe /X{90150000-006E-041B-1000-0000000FF1CE}
Microsoft OneNote MUI (Slovak) 2013-->MsiExec.exe /X{90150000-00A1-041B-1000-0000000FF1CE}
Microsoft Outlook MUI (Slovak) 2013-->MsiExec.exe /X{90150000-001A-041B-1000-0000000FF1CE}
Microsoft PowerPoint MUI (Slovak) 2013-->MsiExec.exe /X{90150000-0018-041B-1000-0000000FF1CE}
Microsoft Publisher MUI (Slovak) 2013-->MsiExec.exe /X{90150000-0019-041B-1000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17-->MsiExec.exe /X{8220EEFE-38CD-377E-8595-13398D740ACE}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148-->MsiExec.exe /X{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161-->MsiExec.exe /X{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219-->MsiExec.exe /X{1D8E6291-B0D5-35EC-8441-6616F567A0F7}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219-->MsiExec.exe /X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727-->"C:\ProgramData\Package Cache\{15134cb0-b767-4960-a911-f2d16ae54797}\vcredist_x64.exe" /uninstall
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727-->"C:\ProgramData\Package Cache\{22154f09-719a-4619-bb71-5b3356999fbf}\vcredist_x86.exe" /uninstall
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106-->"C:\ProgramData\Package Cache\{8e70e4e1-06d7-470b-9f74-a51bef21088e}\vcredist_x86.exe" /uninstall
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727-->MsiExec.exe /X{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727-->MsiExec.exe /X{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727-->MsiExec.exe /X{FDB30193-FDA0-3DAA-ACCA-A75EEFE53607}
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106-->MsiExec.exe /X{6C772996-BFF3-3C8C-860B-B3D48FF05D65}
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727-->MsiExec.exe /X{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106-->MsiExec.exe /X{E824E81C-80A4-3DFF-B5F9-4842A9FF5F7F}
Microsoft Word MUI (Slovak) 2013-->MsiExec.exe /X{90150000-001B-041B-1000-0000000FF1CE}
Microsoft XNA Framework Redistributable 4.0-->MsiExec.exe /I{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}
Movie Maker-->MsiExec.exe /X{45898170-E68C-4F02-AA35-C2186BF347A3}
Movie Maker-->MsiExec.exe /X{CFBFE244-6269-41DC-85B6-86F99C88ED02}
Mozilla Firefox 26.0 (x86 sk)-->"C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe"
MPC-HC 1.7.1 (64-bit)-->"C:\Program Files\MPC-HC\unins000.exe"
MSVCRT-->MsiExec.exe /I{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
MSVCRT110_amd64-->MsiExec.exe /I{E9FA781F-3E80-4399-825A-AD3E11C28C77}
MSVCRT110-->MsiExec.exe /I{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}
MSXML 4.0 SP3 Parser-->MsiExec.exe /I{196467F1-C11F-4F76-858B-5812ADC83B94}
Nástroje kontroly pravopisu pro Microsoft Office 2013 – čeština-->MsiExec.exe /X{90150000-001F-0405-1000-0000000FF1CE}
Nástroje korektúry balíka Microsoft Office 2013 - slovenčina-->MsiExec.exe /X{90150000-001F-041B-1000-0000000FF1CE}
OCR Software by I.R.I.S. 14.0-->C:\Program Files (x86)\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
OpenAL-->"C:\Program Files (x86)\OpenAL\openalweax.exe" /U
Photo Common-->MsiExec.exe /X{140754E1-C019-44A9-A81B-2D7625AABE8A}
Photo Gallery-->MsiExec.exe /X{0F929651-F516-4956-90F2-FFBD2CD5D30E}
PingPlotter Standard 3.41.0s-->MsiExec.exe /I{57CE9ADD-8C74-42EF-92CE-3A7736877FB4}
Race Driver 3-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{0297C87B-CC40-446F-865A-031B4FC0CF22}\setup.exe" -l0x9 -removeonly
RaceRoom Racing Experience -->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/211500
RaceRoom Racing Experience Launcher-->"C:\Program Files (x86)\Steam\steamapps\common\raceroom racing experience\Game\unins000.exe"
Secure Download Manager-->MsiExec.exe /I{E86B07AE-9F94-44D5-AD47-DC2716EA90D2}
Security Update for Microsoft Excel 2013 (KB2827238) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{41DF329D-1966-484D-8856-53E9491D998D}" "1051" "0"
Security Update for Microsoft Excel 2013 (KB2827238) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0016-041B-1000-0000000FF1CE}" "{3D587B45-A0E2-429B-A2C0-C2F51D959461}" "1051" "0"
Security Update for Microsoft Excel 2013 (KB2827238) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0018-041B-1000-0000000FF1CE}" "{3D587B45-A0E2-429B-A2C0-C2F51D959461}" "1051" "0"
Security Update for Microsoft Excel 2013 (KB2827238) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001B-041B-1000-0000000FF1CE}" "{3D587B45-A0E2-429B-A2C0-C2F51D959461}" "1051" "0"
Security Update for Microsoft Lync 2013 (KB2850057) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{AC8EFFF5-000D-4205-9164-34E346CC6009}" "1051" "0"
Security Update for Microsoft Lync 2013 (KB2850057) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{AC8EFFF5-000D-4205-9164-34E346CC6009}" "1051" "0"
Security Update for Microsoft Lync 2013 (KB2850057) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-012B-041B-1000-0000000FF1CE}" "{DC7B7C7D-DF6D-4E6C-98B6-E268467E5304}" "1051" "0"
Security Update for Microsoft Office 2013 (KB2768005) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-006E-041B-1000-0000000FF1CE}" "{46039EDC-E241-4720-95D6-93592A718538}" "1051" "0"
Security Update for Microsoft Office 2013 (KB2810009) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{D6F7BF27-F97C-4D16-9121-7C19A112EA5A}" "1051" "0"
Security Update for Microsoft Office 2013 (KB2850064) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{E1AECEC1-DB6E-4AEC-BBC7-9D0A7B953011}" "1051" "0"
Security Update for Microsoft Office 2013 (KB2850064) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-006E-041B-1000-0000000FF1CE}" "{CC5D6392-DF56-4D25-B5A1-3A1B7F70741B}" "1051" "0"
Security Update for Microsoft Office 2013 (KB2850064) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{E1AECEC1-DB6E-4AEC-BBC7-9D0A7B953011}" "1051" "0"
Security Update for Microsoft Word 2013 (KB2827224) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{D7763B39-229C-4059-8D29-A4CC1C85F5EE}" "1051" "0"
Security Update for Microsoft Word 2013 (KB2863834) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{64553791-813D-4D5B-8F17-A7A72BEB44CA}" "1051" "0"
Skype™ 6.9-->MsiExec.exe /X{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}
Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
TAP-Windows 9.9.2-->C:\Program Files\TAP-Windows\Uninstall.exe
TeamSpeak 3 Client-->"C:\Program Files\TeamSpeak 3 Client\uninstall.exe"
tools-freebsd-->MsiExec.exe /X{003BFBBD-6C67-419E-A24D-0DCAFC3A5249}
tools-linux-->MsiExec.exe /X{D102611A-6466-4101-A51D-51069303AC65}
tools-netware-->MsiExec.exe /X{197597A7-AD33-4898-9D8E-73066818B464}
tools-solaris-->MsiExec.exe /X{AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4}
tools-windows-->MsiExec.exe /X{FFD9383C-01D5-4897-A954-43AF599AED30}
tools-winPre2k-->MsiExec.exe /X{AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D}
Total Commander 64-bit (Remove or Repair)-->c:\totalcmd\tcunin64.exe
Update for Microsoft Access 2013 (KB2768008) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0015-041B-1000-0000000FF1CE}" "{279D6F0F-7988-4CD8-8E93-BA9E61C58672}" "1051" "0"
Update for Microsoft Access 2013 (KB2827233) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{614E655F-A0ED-435A-8E0C-A81EE4BA7BC7}" "1051" "0"
Update for Microsoft InfoPath 2013 (KB2837648) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{5E759A69-FA72-4B3C-BE2F-D1194764D31E}" "1051" "0"
Update for Microsoft Lync 2013 (KB2817678) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-012B-041B-1000-0000000FF1CE}" "{27F1BD0D-3359-45EB-9FE8-A49D3FC4DD48}" "1051" "0"
Update for Microsoft Office 2013 (KB2726954) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{43EB1F58-DAA0-4F61-A4EE-C5651F85A047}" "1051" "0"
Update for Microsoft Office 2013 (KB2726954) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{43EB1F58-DAA0-4F61-A4EE-C5651F85A047}" "1051" "0"
Update for Microsoft Office 2013 (KB2726996) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{76CACE05-7A19-4EAC-87D7-5BFF63AF7CDF}" "1051" "0"
Update for Microsoft Office 2013 (KB2726996) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{76CACE05-7A19-4EAC-87D7-5BFF63AF7CDF}" "1051" "0"
Update for Microsoft Office 2013 (KB2738038) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{FEFF9FF6-FF61-455E-A8CC-3A1311A657AD}" "1051" "0"
Update for Microsoft Office 2013 (KB2760224) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{3FF4EA9F-3505-4726-A974-6593A968FFCC}" "1051" "0"
Update for Microsoft Office 2013 (KB2760242) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{9406D70B-2D9C-4613-A75A-F35B66BA8AFA}" "1051" "0"
Update for Microsoft Office 2013 (KB2760267) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{CA390537-AA88-450F-A240-5FB4648A124A}" "1051" "0"
Update for Microsoft Office 2013 (KB2760539) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{C8D57F4A-0824-4043-89E7-3C6280B67A47}" "1051" "0"
Update for Microsoft Office 2013 (KB2760553) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{AC4470FB-8011-4F16-B5D4-E0A34DE10C87}" "1051" "0"
Update for Microsoft Office 2013 (KB2760610) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{D8B3D175-48B8-413F-8484-4D81E744B51C}" "1051" "0"
Update for Microsoft Office 2013 (KB2767845) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{8587E5B1-6279-4396-B9AC-20B334F4FF88}" "1051" "0"
Update for Microsoft Office 2013 (KB2817314) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{C809B1D6-BD31-4496-BCFE-4567E0854F5F}" "1051" "0"
Update for Microsoft Office 2013 (KB2817316) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{4FD8F672-3206-469C-B9F0-D6E72F7ACAB2}" "1051" "0"
Update for Microsoft Office 2013 (KB2817316) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0016-041B-1000-0000000FF1CE}" "{856D47BC-036C-4692-8702-D6CCA8F428D0}" "1051" "0"
Update for Microsoft Office 2013 (KB2817316) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0016-041B-1000-0000000FF1CE}" "{ABA98B77-725D-486B-AE3F-1693C9BBA465}" "1051" "0"
Update for Microsoft Office 2013 (KB2817490) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{CA0554C4-62FE-4F66-BC87-1EE1EAC675EF}" "1051" "0"
Update for Microsoft Office 2013 (KB2817490) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{CA0554C4-62FE-4F66-BC87-1EE1EAC675EF}" "1051" "0"
Update for Microsoft Office 2013 (KB2817626) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{F33ABF6A-3007-47E8-8E38-506A18E54641}" "1051" "0"
Update for Microsoft Office 2013 (KB2826004) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{B38036CB-BAF6-41D4-8810-FD016453ABB9}" "1051" "0"
Update for Microsoft Office 2013 (KB2827225) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{2A286156-257B-4528-9DB5-B4D4D53211BC}" "1051" "0"
Update for Microsoft Office 2013 (KB2827227) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-0405-1000-0000000FF1CE}" "{80684D6D-09BB-4E1C-A47A-45068EBAAE5E}" "1051" "0"
Update for Microsoft Office 2013 (KB2827227) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-0407-1000-0000000FF1CE}" "{B5E3E636-7913-4775-BC9B-E4B56F4ED73B}" "1051" "0"
Update for Microsoft Office 2013 (KB2827227) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-0409-1000-0000000FF1CE}" "{92833C80-DC88-4A22-8630-407F810EF57B}" "1051" "0"
Update for Microsoft Office 2013 (KB2827227) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-040E-1000-0000000FF1CE}" "{92F6DDB7-0BC3-46C2-9E7F-4686247B38DA}" "1051" "0"
Update for Microsoft Office 2013 (KB2827227) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001F-041B-1000-0000000FF1CE}" "{4BE3996F-99D2-4917-87FF-6380CCFECF06}" "1051" "0"
Update for Microsoft Office 2013 (KB2827230) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{F2187E8D-C68A-4655-8551-1932878A5581}" "1051" "0"
Update for Microsoft Office 2013 (KB2827239) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{9353CD85-4B19-45C4-8DBA-1391926351F6}" "1051" "0"
Update for Microsoft Office 2013 (KB2827239) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{9353CD85-4B19-45C4-8DBA-1391926351F6}" "1051" "0"
Update for Microsoft Office 2013 (KB2837626) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{6EE51F51-57B1-4DC7-96C2-857DB7F0BE93}" "1051" "0"
Update for Microsoft Office 2013 (KB2837637) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{0A90C645-3F9A-4CF9-BF62-2609602E3DAB}" "1051" "0"
Update for Microsoft Office 2013 (KB2837638) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{3A48DE63-607B-4FEA-A862-B52669C4433C}" "1051" "0"
Update for Microsoft Office 2013 (KB2837655) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{C4B559C7-AA71-4B77-ACA3-50BEA8B4241B}" "1051" "0"
Update for Microsoft Office 2013 (KB2837655) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-006E-041B-1000-0000000FF1CE}" "{D770FC63-2A57-4BF0-82E2-0CD4A5BB6A64}" "1051" "0"
Update for Microsoft Office 2013 (KB2837655) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{C4B559C7-AA71-4B77-ACA3-50BEA8B4241B}" "1051" "0"
Update for Microsoft Office 2013 (KB2850066) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{000791D2-642D-418E-A3E9-96E72D8C67B8}" "1051" "0"
Update for Microsoft Office 2013 (KB2850066) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{000791D2-642D-418E-A3E9-96E72D8C67B8}" "1051" "0"
Update for Microsoft OneNote 2013 (KB2850063) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{CF6FBF49-BE22-4B98-9D7D-CB2A3236BC44}" "1051" "0"
Update for Microsoft OneNote 2013 (KB2850063) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00A1-041B-1000-0000000FF1CE}" "{AB85EA97-E873-4BB2-9CBB-5506B277BC9D}" "1051" "0"
Update for Microsoft OneNote 2013 (KB2850063) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{CF6FBF49-BE22-4B98-9D7D-CB2A3236BC44}" "1051" "0"
Update for Microsoft Outlook 2013 (KB2850061) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{E8F64CB5-1419-47A8-9FCE-F6E4137F2D25}" "1051" "0"
Update for Microsoft Outlook 2013 (KB2850061) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001A-041B-1000-0000000FF1CE}" "{9C190EC8-21F6-40A0-A08D-4DF49D2C8783}" "1051" "0"
Update for Microsoft PowerPoint 2013 (KB2767850) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{6FF949A3-1C3F-41C2-9464-933E885ECB53}" "1051" "0"
Update for Microsoft PowerPoint 2013 (KB2767850) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0018-041B-1000-0000000FF1CE}" "{F3988C37-090B-45AB-895E-97215250FA5F}" "1051" "0"
Update for Microsoft Project 2013 (KB2727085) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{BBD4F4CE-65D4-4CEB-AE19-E5296A57AA6C}" "1051" "0"
Update for Microsoft Publisher 2013 (KB2837635) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{2837C624-A972-43CF-BCE5-0AE2EFED72E3}" "1051" "0"
Update for Microsoft Publisher 2013 (KB2837635) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0019-041B-1000-0000000FF1CE}" "{4BBDE72A-96E5-4619-861C-A35A860A4743}" "1051" "0"
Update for Microsoft SkyDrive Pro (KB2817495) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{A3417E9E-5B94-4BFF-AAA4-933B1AE46306}" "1051" "0"
Update for Microsoft SkyDrive Pro (KB2817495) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-0000-1000-0000000FF1CE}" "{A3417E9E-5B94-4BFF-AAA4-933B1AE46306}" "1051" "0"
Update for Microsoft SkyDrive Pro (KB2837652) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00BA-041B-1000-0000000FF1CE}" "{42BF90E0-1B49-4A35-A4F3-83ED52250403}" "1051" "0"
Update for Microsoft SkyDrive Pro (KB2837652) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-00C1-041B-1000-0000000FF1CE}" "{42BF90E0-1B49-4A35-A4F3-83ED52250403}" "1051" "0"
Update for Microsoft Visio 2013 (KB2817306) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{F16E7B82-23FE-4054-AB73-EAE53965251C}" "1051" "0"
Update for Microsoft Visio Viewer 2013 (KB2768338) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-0011-0000-1000-0000000FF1CE}" "{D1F1940B-94DF-4DCB-BF82-9530D7FBB1BF}" "1051" "0"
Update for Microsoft Word 2013 (KB2837647) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001A-041B-1000-0000000FF1CE}" "{532F2B3B-E996-4BEC-AB32-BD45D3F6B93E}" "1051" "0"
Update for Microsoft Word 2013 (KB2837647) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-001B-041B-1000-0000000FF1CE}" "{532F2B3B-E996-4BEC-AB32-BD45D3F6B93E}" "1051" "0"
Update for Microsoft Word 2013 (KB2837647) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE15\Oarpmany.exe" /removereleaseinpatch "{90150000-012B-041B-1000-0000000FF1CE}" "{532F2B3B-E996-4BEC-AB32-BD45D3F6B93E}" "1051" "0"
VLC media player 2.1.1-->C:\Program Files (x86)\VideoLAN\VLC\uninstall.exe
VMware Workstation-->"C:\ProgramData\VMware\VMware Workstation\Uninstaller\\uninstall.exe" -x -S "C:\ProgramData\VMware\VMware Workstation\Uninstaller\"
VMware Workstation-->MsiExec.exe /I{0D94F75A-0EA6-4951-B3AF-B145FA9E05C6}
War Thunder-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/236390
Windows 7 USB/DVD Download Tool-->MsiExec.exe /X{CCF298AF-9CE1-4B26-B251-486E98A34789}
Windows Driver Package - Lenovo (ACPIVPC) System (06/15/2012 8.1.0.1)-->C:\PROGRA~1\DIFX\8C6574~1\DPInst.exe /u C:\Windows\System32\DriverStore\FileRepository\vpc.inf_amd64_37c65821ee7b9e70\vpc.inf
Windows Driver Package - Lenovo (WUDFRd) LenovoVhid (06/19/2012 10.13.29.733)-->C:\PROGRA~1\DIFX\8C6574~1\DPInst.exe /u C:\Windows\System32\DriverStore\FileRepository\wudfvhidmini.inf_amd64_4f86ecaa9af0d5de\wudfvhidmini.inf
Windows Live Communications Platform-->MsiExec.exe /I{03D562B5-C4E2-4846-A920-33178788BE00}
Windows Live Essentials-->C:\Program Files (x86)\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{FA29B84F-8306-4A62-A340-F2C41305E7AF}
Windows Live Installer-->MsiExec.exe /I{5A0EE0F0-E909-4F3B-B437-AAD9252427CB}
Windows Live Photo Common-->MsiExec.exe /X{C6B0EE9E-2128-4448-B7AE-5E2B46E0F0E7}
Windows Live PIMT Platform-->MsiExec.exe /I{E3445598-4424-4EE2-B71C-C23325F7FB71}
Windows Live SOXE Definitions-->MsiExec.exe /I{0FF9CC94-EF23-401E-BDBD-37403D1A2B38}
Windows Live SOXE-->MsiExec.exe /I{6B6923B9-8719-425B-916C-CD2908F31AAF}
Windows Live UX Platform Language Pack-->MsiExec.exe /I{28950295-A98C-4081-AC82-045E9879945E}
Windows Live UX Platform-->MsiExec.exe /I{F0E58739-2B4C-498F-9B0D-FF0F2FD52B61}
Windows Mobile Device Updater Component-->MsiExec.exe /X{F2CB8C3C-9C9E-4FAB-9067-655601C5F748}
WinRAR 4.20 (64-bit)-->C:\Program Files\WinRAR\uninstall.exe
World of Tanks-->"D:\Games\WoT\unins000.exe"
Worms Revolution-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/200170
Zune Language Pack (CSY)-->MsiExec.exe /X{A8F2E50B-86E2-4D96-9BD2-9758BCC6F9B3}
Zune Language Pack (DAN)-->MsiExec.exe /X{8B112338-2B08-4851-AF84-E7CAD74CEB32}
Zune Language Pack (DEU)-->MsiExec.exe /X{BE236D9A-52EC-4A17-82DA-84B5EAD31E3E}
Zune Language Pack (ELL)-->MsiExec.exe /X{3589A659-F732-4E65-A89A-5438C332E59D}
Zune Language Pack (ESP)-->MsiExec.exe /X{6B33492E-FBBC-4EC3-8738-09E16E395A10}
Zune Language Pack (FIN)-->MsiExec.exe /X{B4870774-5F3A-46D9-9DFE-06FB5599E26B}
Zune Language Pack (FRA)-->MsiExec.exe /X{C68D33B1-0204-4EBE-BC45-A6E432B1D13A}
Zune Language Pack (HUN)-->MsiExec.exe /X{C6BE19C6-B102-4038-B2A6-1C313872DBB4}
Zune Language Pack (CHS)-->MsiExec.exe /X{2A9DFFD8-4E09-4B91-B957-454805B0D7C4}
Zune Language Pack (CHT)-->MsiExec.exe /X{A5A53EA8-A11E-49F0-BDF5-AE536426A31A}
Zune Language Pack (IND)-->MsiExec.exe /X{92ECE3F9-591E-4C12-8A62-B9FCE38BF646}
Zune Language Pack (ITA)-->MsiExec.exe /X{C5D37FFA-7483-410B-982B-91E93FD3B7DA}
Zune Language Pack (JPN)-->MsiExec.exe /X{D8A781C9-3892-4E2E-9320-480CF896CFBB}
Zune Language Pack (KOR)-->MsiExec.exe /X{51C839E1-2BE4-4E77-A1BA-CCEA5DAFA741}
Zune Language Pack (MSL)-->MsiExec.exe /X{76BA306B-2AA0-47C0-AB6B-F313AB56C136}
Zune Language Pack (NLD)-->MsiExec.exe /X{6740BCB0-5863-47F4-80F4-44F394DE4FE2}
Zune Language Pack (NOR)-->MsiExec.exe /X{5DEFD397-4012-46C3-B6DA-E8013E660772}
Zune Language Pack (PLK)-->MsiExec.exe /X{8960A0A1-BB5A-479E-92CF-65AB9D684B43}
Zune Language Pack (PTB)-->MsiExec.exe /X{07EEE598-5F21-4B57-B40B-46592625B3D9}
Zune Language Pack (PTG)-->MsiExec.exe /X{5C93E291-A1CC-4E51-85C6-E194209FCDB4}
Zune Language Pack (RUS)-->MsiExec.exe /X{57C51D56-B287-4C11-9192-EC3C46EF76A4}
Zune Language Pack (SVE)-->MsiExec.exe /X{6EB931CD-A7DA-4A44-B74A-89C8EB50086F}
Zune-->C:\Program Files\Zune\ZuneSetup.exe /x
Zune-->MsiExec.exe /X{9B75648B-6C30-4A0D-9DE6-0D09D20AF5A5}
======System event log======
Computer Name: Lacko
Event Code: 28
Message: Lokálny adaptér nepodporuje funkciu nedostatku energie rozhrania Bluetooth.
Record Number: 154
Source Name: BTHUSB
Time Written: 20130816200148.664446-000
Event Type: Warning
User:
Computer Name: windows-e3tqq9a
Event Code: 28
Message: Lokálny adaptér nepodporuje funkciu nedostatku energie rozhrania Bluetooth.
Record Number: 86
Source Name: BTHUSB
Time Written: 20130816200022.241145-000
Event Type: Warning
User:
Computer Name: windows-e3tqq9a
Event Code: 7023
Message: Služba Služba zoznamu sietí bola ukončená s nasledujúcou chybou:
Zariadenie nie je pripravené.
Record Number: 39
Source Name: Service Control Manager
Time Written: 20130816200005.798609-000
Event Type: Error
User:
Computer Name: windows-e3tqq9a
Event Code: 7023
Message: Služba IP Helper bola ukončená s nasledujúcou chybou:
Služba sa nedá spustiť, pretože je vypnutá, alebo nemá priradené žiadne zapnuté zariadenia.
Record Number: 37
Source Name: Service Control Manager
Time Written: 20130816200004.238595-000
Event Type: Error
User:
Computer Name: windows-e3tqq9a
Event Code: 46
Message: Crash dump initialization failed!
Record Number: 14
Source Name: volmgr
Time Written: 20130816195910.449304-000
Event Type: Error
User:
=====Application event log=====
Computer Name: Lacko
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. No user action is required.
DETAIL -
62 user registry handles leaked from \Registry\User\S-1-5-21-3352856905-2808976808-1590191317-1001:
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\MY
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\CA
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\CA
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\CA
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\CA
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\TrustedPeople
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\TrustedPeople
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\TrustedPeople
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\Root
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\Root
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\Root
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\Root
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\Disallowed
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\Disallowed
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\Disallowed
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\Disallowed
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 556 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\trust
Process 876 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\trust
Process 1604 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\trust
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\trust
Record Number: 326
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20130816202752.922781-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: Lacko
Event Code: 3006
Message: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Record Number: 75
Source Name: Microsoft-Windows-LoadPerf
Time Written: 20130816200749.571324-000
Event Type: Error
User: NT AUTHORITY\SYSTEM
Computer Name: Lacko
Event Code: 3006
Message: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Record Number: 73
Source Name: Microsoft-Windows-LoadPerf
Time Written: 20130816200749.493320-000
Event Type: Error
User: NT AUTHORITY\SYSTEM
Computer Name: Lacko
Event Code: 1008
Message: Služba Windows Search sa spúšťa a pokúša sa odstrániť starý index hľadania. {Dôvod: Full Index Reset}.
Record Number: 42
Source Name: Microsoft-Windows-Search
Time Written: 20130816200407.000000-000
Event Type: Warning
User:
Computer Name: Lacko
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. No user action is required.
DETAIL -
14 user registry handles leaked from \Registry\User\S-1-5-21-3352856905-2808976808-1590191317-1001:
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\CA
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\TrustedPeople
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\Root
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\Disallowed
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Policies\Microsoft\SystemCertificates
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 896 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3352856905-2808976808-1590191317-1001\Software\Microsoft\SystemCertificates\trust
Record Number: 40
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20130816200402.573443-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
=====Security event log=====
Computer Name: Lacko
Event Code: 4907
Message: Auditing settings on object were changed.
Subject:
Security ID: S-1-5-18
Account Name: LACKO$
Account Domain: WORKGROUP
Logon ID: 0x3E7
Object:
Object Server: Security
Object Type: File
Object Name: C:\Windows\System32\mfasfsrcsnk.dll
Handle ID: 0x34
Process Information:
Process ID: 0x740
Process Name: C:\Windows\System32\poqexec.exe
Auditing Settings:
Original Security Descriptor: S:AI
New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 5246
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20130821073526.853524-000
Event Type: Audit Success
User:
Computer Name: Lacko
Event Code: 4907
Message: Auditing settings on object were changed.
Subject:
Security ID: S-1-5-18
Account Name: LACKO$
Account Domain: WORKGROUP
Logon ID: 0x3E7
Object:
Object Server: Security
Object Type: File
Object Name: C:\Windows\System32\vdsutil.dll
Handle ID: 0x34
Process Information:
Process ID: 0x740
Process Name: C:\Windows\System32\poqexec.exe
Auditing Settings:
Original Security Descriptor: S:AI
New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 5245
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20130821073526.837900-000
Event Type: Audit Success
User:
Computer Name: Lacko
Event Code: 4907
Message: Auditing settings on object were changed.
Subject:
Security ID: S-1-5-18
Account Name: LACKO$
Account Domain: WORKGROUP
Logon ID: 0x3E7
Object:
Object Server: Security
Object Type: File
Object Name: C:\Windows\System32\samsrv.dll
Handle ID: 0x34
Process Information:
Process ID: 0x740
Process Name: C:\Windows\System32\poqexec.exe
Auditing Settings:
Original Security Descriptor: S:AI
New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 5244
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20130821073526.806690-000
Event Type: Audit Success
User:
Computer Name: Lacko
Event Code: 4907
Message: Auditing settings on object were changed.
Subject:
Security ID: S-1-5-18
Account Name: LACKO$
Account Domain: WORKGROUP
Logon ID: 0x3E7
Object:
Object Server: Security
Object Type: File
Object Name: C:\Windows\System32\audiosrv.dll
Handle ID: 0x34
Process Information:
Process ID: 0x740
Process Name: C:\Windows\System32\poqexec.exe
Auditing Settings:
Original Security Descriptor: S:AI
New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 5243
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20130821073526.775524-000
Event Type: Audit Success
User:
Computer Name: Lacko
Event Code: 4907
Message: Auditing settings on object were changed.
Subject:
Security ID: S-1-5-18
Account Name: LACKO$
Account Domain: WORKGROUP
Logon ID: 0x3E7
Object:
Object Server: Security
Object Type: File
Object Name: C:\Windows\System32\MbaeParserTask.exe
Handle ID: 0x34
Process Information:
Process ID: 0x740
Process Name: C:\Windows\System32\poqexec.exe
Auditing Settings:
Original Security Descriptor: S:AI
New Security Descriptor: S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)
Record Number: 5242
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20130821073526.728723-000
Event Type: Audit Success
User:
======Environment variables======
"FP_NO_HOST_CHECK"=NO
"USERNAME"=SYSTEM
"ComSpec"=%SystemRoot%\system32\cmd.exe
"TMP"=%SystemRoot%\TEMP
"OS"=Windows_NT
"windir"=%SystemRoot%
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=3
"PROCESSOR_LEVEL"=16
"PROCESSOR_IDENTIFIER"=AMD64 Family 16 Model 5 Stepping 3, AuthenticAMD
"PROCESSOR_REVISION"=0503
"Path"=C:\Program Files (x86)\AMD APP\bin\x86_64;C:\Program Files (x86)\AMD APP\bin\x86;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files (x86)\Common Files\Adobe\AGL;C:\Program Files\MATLAB\R2010a\runtime\win64;C:\Program Files\MATLAB\R2010a\bin;C:\Program Files (x86)\Windows Live\Shared
"AMDAPPSDKROOT"=C:\Program Files (x86)\AMD APP\
-----------------EOF-----------------