prosim o kontrolu logu
Napsal: 17 úno 2020 23:55
info.txt logfile of random's system information tool 1.10 2020-02-17 23:52:34
======MBR======
0x33C08ED0BC007C8EC08ED8BE007CBF0006B90002FCF3A450681C06CBFBB90400BDBE07807E00007C0B0F850E0183C510E2F1CD1888560055C6461105C6461000B441BBAA55CD135D720F81FB55AA7509F7C101007403FE46106660807E1000742666680000000066FF760868000068007C680100681000B4428A56008BF4CD139F83C4109EEB14B80102BB007C8A56008A76018A4E028A6E03CD136661731CFE4E11750C807E00800F848A00B280EB845532E48A5600CD135DEB9E813EFE7D55AA756EFF7600E88D007517FAB0D1E664E88300B0DFE660E87C00B0FFE664E87500FBB800BBCD1A6623C0753B6681FB54435041753281F90201722C666807BB00006668000200006668080000006653665366556668000000006668007C0000666168000007CD1A5A32F6EA007C0000CD18A0B707EB08A0B607EB03A0B50732E40500078BF0AC3C007409BB0700B40ECD10EBF2F4EBFD2BC9E464EB002402E0F82402C3496E76616C696420706172746974696F6E207461626C65004572726F72206C6F6164696E67206F7065726174696E672073797374656D004D697373696E67206F7065726174696E672073797374656D000000637B9A10B833FB00008020210007DF130C000800000020030000DF140C07FEFFFF002803000060DB0F00FEFFFF07FEFFFF0088DE0F00C83D0D0000000000000000000000000000000055AA
======Uninstall list======
Adobe Acrobat Reader DC - Slovak-->MsiExec.exe /I{AC76BA86-7AD7-1051-7B44-AC0F074E4100}
Adobe Refresh Manager-->MsiExec.exe /I{AC76BA86-0804-1033-1959-000182435289}
Alcor Micro Smart Card Reader Driver-->C:\Program Files (x86)\InstallShield Installation Information\{F24F876B-7D71-4BD6-88E9-614D3BB84238}\setup.exe -runfromtemp -removeonly
Alcor Micro Smart Card Reader Driver-->MsiExec.exe /X{F24F876B-7D71-4BD6-88E9-614D3BB84238}
amuleC-->MsiExec.exe /I{19539992-061C-4E8B-9053-07B175303AF4}
amuleC-->MsiExec.exe /I{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
amuleC-->MsiExec.exe /I{B2EFFD4E-D098-4845-9D56-DE75BEB35913}
Avast Free Antivirus-->C:\Program Files\AVAST Software\Avast\setup\Instup.exe /control_panel
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
DAEMON Tools Lite-->C:\Program Files\DAEMON Tools Lite\uninst.exe
Google Chrome-->"C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer\setup.exe" --uninstall --system-level --verbose-logging
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
Google Update Helper-->MsiExec.exe /I{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
HiSuite-->C:\Program Files (x86)\HiSuite\uninst.exe
HP 3D DriveGuard-->MsiExec.exe /X{F8C604AC-1939-4B74-B847-CB59417F1FF2}
HP Hotkey Support-->MsiExec.exe /X{C97CC14E-4789-4FC5-BC75-79191F7CE009}
HP Software Framework-->MsiExec.exe /X{0BFFE87D-A1BD-4086-BF6F-292711E74F58}
IDT Audio-->"C:\Program Files (x86)\InstallShield Installation Information\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}\Setup.exe" -remove -removeonly
Intel(R) Control Center-->C:\Program Files (x86)\Intel\Intel Control Center\uninstaller\SetupICC.exe -uninstall -force -confirm
Intel(R) Management Engine Components-->C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\Uninstall\setup.exe -uninstall
Intel(R) Network Connections Drivers-->Prounstl.exe
Intel(R) Processor Graphics-->C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\Uninstall\setup.exe -uninstall
Intel(R) Rapid Storage Technology-->C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\Uninstall\setup.exe -uninstall
Intel(R) SDK for OpenCL - CPU Only Runtime Package-->C:\Program Files (x86)\Intel\OpenCL SDK\2.0\Uninstall\setup.exe -uninstall
Java 8 Update 111-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F32180111F0}
JMicron Flash Media Controller Driver-->"C:\Program Files (x86)\JMicron\JMCR_DIR\setup.exe" delpkg
Microsoft .NET Framework 4.5.2-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\v4.5.51209\\Setup.exe /repair /x86 /x64
Microsoft .NET Framework 4.5.2-->MsiExec.exe /X{26784146-6E05-3FF9-9335-786C7C0FB5BE}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161-->MsiExec.exe /X{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Mozilla Firefox 73.0 (x64 sk)-->"C:\Program Files\Mozilla Firefox\uninstall\helper.exe"
Mozilla Maintenance Service-->"C:\Program Files (x86)\Mozilla Maintenance Service\uninstall.exe"
Need for Speed™ Carbon-->C:\Program Files (x86)\Electronic Arts\Need for Speed Carbon\EAUninstall.exe
OpenOffice 4.1.1-->MsiExec.exe /I{456408C1-3BDE-48CC-9A5A-79B1BB4C4787}
Picasa 3-->"C:\Program Files (x86)\Google\Picasa3\Uninstall.exe"
Synaptics Pointing Device Driver-->rundll32.exe "%ProgramFiles%\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Total Commander (Remove or Repair)-->c:\totalcmd\tcuninst.exe
VLC media player-->C:\Program Files (x86)\VideoLAN\VLC\uninstall.exe
WinRAR 5.40 (64-bitová verzia)-->C:\Program Files\WinRAR\uninstall.exe
WinSnare-->MsiExec.exe /I{6B9B0FDA-3C20-4497-B62A-45102358B3C2}
YAC(Yet Another Cleaner!)-->C:\Program Files (x86)\Elex-tech\YAC\uninstall.exe
======Hosts File======
0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
0.0.0.0 media.opencandy.com
0.0.0.0 cdn.opencandy.com
0.0.0.0 tracking.opencandy.com
0.0.0.0 api.opencandy.com
0.0.0.0 api.recommendedsw.com
0.0.0.0 installer.betterinstaller.com
0.0.0.0 installer.filebulldog.com
0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
======System event log======
Computer Name: PC-PC
Event Code: 4321
Message: The name "PC-PC :0" could not be registered on the interface with IP address 192.168.1.9. The computer with the IP address 192.168.1.2 did not allow the name to be claimed by this computer.
Record Number: 1376
Source Name: NetBT
Time Written: 20151209091934.284833-000
Event Type: Error
User:
Computer Name: PC-PC
Event Code: 4321
Message: The name "PC-PC :20" could not be registered on the interface with IP address 192.168.1.9. The computer with the IP address 192.168.1.2 did not allow the name to be claimed by this computer.
Record Number: 1375
Source Name: NetBT
Time Written: 20151209091934.284833-000
Event Type: Error
User:
Computer Name: PC-PC
Event Code: 2505
Message: The server could not bind to the transport \Device\NetBT_Tcpip_{7089B032-EEC8-4628-97C0-462905BBAAF4} because another computer on the network has the same name. The server could not start.
Record Number: 1374
Source Name: Server
Time Written: 20151209091934.000000-000
Event Type: Error
User:
Computer Name: PC-PC
Event Code: 219
Message: The driver \Driver\WUDFRd failed to load for the device USB\Vid_03f0&Pid_371d&MI_03\7&361659e5&1&03.
Record Number: 1273
Source Name: Microsoft-Windows-Kernel-PnP
Time Written: 20151209085641.418420-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: PC-PC
Event Code: 27
Message: Intel(R) 82579LM Gigabit Network Connection
Network link is disconnected.
Record Number: 1271
Source Name: e1cexpress
Time Written: 20151209085640.763219-000
Event Type: Warning
User:
=====Application event log=====
Computer Name: PC-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-3213848150-4246953407-4286547329-1000:
Process 404 (\Device\HarddiskVolume2\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3213848150-4246953407-4286547329-1000
Record Number: 280
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20151207175941.746366-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: PC-PC
Event Code: 3006
Message: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Record Number: 273
Source Name: Microsoft-Windows-LoadPerf
Time Written: 20151207170206.304296-000
Event Type: Error
User: NT AUTHORITY\SYSTEM
Computer Name: PC-PC
Event Code: 3006
Message: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Record Number: 271
Source Name: Microsoft-Windows-LoadPerf
Time Written: 20151207170206.226296-000
Event Type: Error
User: NT AUTHORITY\SYSTEM
Computer Name: PC-PC
Event Code: 10
Message: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Record Number: 192
Source Name: Microsoft-Windows-WMI
Time Written: 20151207165835.000000-000
Event Type: Error
User:
Computer Name: PC-PC
Event Code: 1008
Message: Služba Windows Search sa spúšťa a pokúša sa odstrániť starý index hľadania. {Dôvod: Full Index Reset}.
Record Number: 172
Source Name: Microsoft-Windows-Search
Time Written: 20151207165741.000000-000
Event Type: Warning
User:
=====Security event log=====
Computer Name: 37L4247F27-25
Event Code: 4735
Message: A security-enabled local group was changed.
Subject:
Security ID: S-1-5-18
Account Name: 37L4247F27-25$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Group:
Security ID: S-1-5-32-551
Group Name: Backup Operators
Group Domain: Builtin
Changed Attributes:
SAM Account Name: -
SID History: -
Additional Information:
Privileges: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20151207165230.787644-000
Event Type: Audit Success
User:
Computer Name: 37L4247F27-25
Event Code: 4731
Message: A security-enabled local group was created.
Subject:
Security ID: S-1-5-18
Account Name: 37L4247F27-25$
Account Domain: WORKGROUP
Logon ID: 0x3e7
New Group:
Security ID: S-1-5-32-551
Group Name: Backup Operators
Group Domain: Builtin
Attributes:
SAM Account Name: Backup Operators
SID History: -
Additional Information:
Privileges: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20151207165230.787644-000
Event Type: Audit Success
User:
Computer Name: 37L4247F27-25
Event Code: 4902
Message: The Per-user audit policy table was created.
Number of Elements: 0
Policy ID: 0x3213f
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20151207165230.413243-000
Event Type: Audit Success
User:
Computer Name: 37L4247F27-25
Event Code: 4624
Message: An account was successfully logged on.
Subject:
Security ID: S-1-0-0
Account Name: -
Account Domain: -
Logon ID: 0x0
Logon Type: 0
New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}
Process Information:
Process ID: 0x4
Process Name:
Network Information:
Workstation Name: -
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: -
Authentication Package: -
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
This event is generated when a logon session is created. It is generated on the computer that was accessed.
The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20151207165228.322840-000
Event Type: Audit Success
User:
Computer Name: 37L4247F27-25
Event Code: 4608
Message: Windows is starting up.
This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20151207165228.166839-000
Event Type: Audit Success
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=C:\ProgramData\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=4
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=Intel64 Family 6 Model 42 Stepping 7, GenuineIntel
"PROCESSOR_REVISION"=2a07
"windows_tracing_logfile"=C:\BVTBin\Tests\installpackage\csilogfile.log
"windows_tracing_flags"=3
"BREAKPAD_DUMP_LOCATION"=C:\Program Files (x86)\Coldold\Reports\Dump
-----------------EOF-----------------
======MBR======
0x33C08ED0BC007C8EC08ED8BE007CBF0006B90002FCF3A450681C06CBFBB90400BDBE07807E00007C0B0F850E0183C510E2F1CD1888560055C6461105C6461000B441BBAA55CD135D720F81FB55AA7509F7C101007403FE46106660807E1000742666680000000066FF760868000068007C680100681000B4428A56008BF4CD139F83C4109EEB14B80102BB007C8A56008A76018A4E028A6E03CD136661731CFE4E11750C807E00800F848A00B280EB845532E48A5600CD135DEB9E813EFE7D55AA756EFF7600E88D007517FAB0D1E664E88300B0DFE660E87C00B0FFE664E87500FBB800BBCD1A6623C0753B6681FB54435041753281F90201722C666807BB00006668000200006668080000006653665366556668000000006668007C0000666168000007CD1A5A32F6EA007C0000CD18A0B707EB08A0B607EB03A0B50732E40500078BF0AC3C007409BB0700B40ECD10EBF2F4EBFD2BC9E464EB002402E0F82402C3496E76616C696420706172746974696F6E207461626C65004572726F72206C6F6164696E67206F7065726174696E672073797374656D004D697373696E67206F7065726174696E672073797374656D000000637B9A10B833FB00008020210007DF130C000800000020030000DF140C07FEFFFF002803000060DB0F00FEFFFF07FEFFFF0088DE0F00C83D0D0000000000000000000000000000000055AA
======Uninstall list======
Adobe Acrobat Reader DC - Slovak-->MsiExec.exe /I{AC76BA86-7AD7-1051-7B44-AC0F074E4100}
Adobe Refresh Manager-->MsiExec.exe /I{AC76BA86-0804-1033-1959-000182435289}
Alcor Micro Smart Card Reader Driver-->C:\Program Files (x86)\InstallShield Installation Information\{F24F876B-7D71-4BD6-88E9-614D3BB84238}\setup.exe -runfromtemp -removeonly
Alcor Micro Smart Card Reader Driver-->MsiExec.exe /X{F24F876B-7D71-4BD6-88E9-614D3BB84238}
amuleC-->MsiExec.exe /I{19539992-061C-4E8B-9053-07B175303AF4}
amuleC-->MsiExec.exe /I{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
amuleC-->MsiExec.exe /I{B2EFFD4E-D098-4845-9D56-DE75BEB35913}
Avast Free Antivirus-->C:\Program Files\AVAST Software\Avast\setup\Instup.exe /control_panel
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
DAEMON Tools Lite-->C:\Program Files\DAEMON Tools Lite\uninst.exe
Google Chrome-->"C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer\setup.exe" --uninstall --system-level --verbose-logging
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
Google Update Helper-->MsiExec.exe /I{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
HiSuite-->C:\Program Files (x86)\HiSuite\uninst.exe
HP 3D DriveGuard-->MsiExec.exe /X{F8C604AC-1939-4B74-B847-CB59417F1FF2}
HP Hotkey Support-->MsiExec.exe /X{C97CC14E-4789-4FC5-BC75-79191F7CE009}
HP Software Framework-->MsiExec.exe /X{0BFFE87D-A1BD-4086-BF6F-292711E74F58}
IDT Audio-->"C:\Program Files (x86)\InstallShield Installation Information\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}\Setup.exe" -remove -removeonly
Intel(R) Control Center-->C:\Program Files (x86)\Intel\Intel Control Center\uninstaller\SetupICC.exe -uninstall -force -confirm
Intel(R) Management Engine Components-->C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\Uninstall\setup.exe -uninstall
Intel(R) Network Connections Drivers-->Prounstl.exe
Intel(R) Processor Graphics-->C:\Program Files (x86)\Intel\Intel(R) Processor Graphics\Uninstall\setup.exe -uninstall
Intel(R) Rapid Storage Technology-->C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\Uninstall\setup.exe -uninstall
Intel(R) SDK for OpenCL - CPU Only Runtime Package-->C:\Program Files (x86)\Intel\OpenCL SDK\2.0\Uninstall\setup.exe -uninstall
Java 8 Update 111-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F32180111F0}
JMicron Flash Media Controller Driver-->"C:\Program Files (x86)\JMicron\JMCR_DIR\setup.exe" delpkg
Microsoft .NET Framework 4.5.2-->C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SetupCache\v4.5.51209\\Setup.exe /repair /x86 /x64
Microsoft .NET Framework 4.5.2-->MsiExec.exe /X{26784146-6E05-3FF9-9335-786C7C0FB5BE}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161-->MsiExec.exe /X{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Mozilla Firefox 73.0 (x64 sk)-->"C:\Program Files\Mozilla Firefox\uninstall\helper.exe"
Mozilla Maintenance Service-->"C:\Program Files (x86)\Mozilla Maintenance Service\uninstall.exe"
Need for Speed™ Carbon-->C:\Program Files (x86)\Electronic Arts\Need for Speed Carbon\EAUninstall.exe
OpenOffice 4.1.1-->MsiExec.exe /I{456408C1-3BDE-48CC-9A5A-79B1BB4C4787}
Picasa 3-->"C:\Program Files (x86)\Google\Picasa3\Uninstall.exe"
Synaptics Pointing Device Driver-->rundll32.exe "%ProgramFiles%\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
Total Commander (Remove or Repair)-->c:\totalcmd\tcuninst.exe
VLC media player-->C:\Program Files (x86)\VideoLAN\VLC\uninstall.exe
WinRAR 5.40 (64-bitová verzia)-->C:\Program Files\WinRAR\uninstall.exe
WinSnare-->MsiExec.exe /I{6B9B0FDA-3C20-4497-B62A-45102358B3C2}
YAC(Yet Another Cleaner!)-->C:\Program Files (x86)\Elex-tech\YAC\uninstall.exe
======Hosts File======
0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
0.0.0.0 media.opencandy.com
0.0.0.0 cdn.opencandy.com
0.0.0.0 tracking.opencandy.com
0.0.0.0 api.opencandy.com
0.0.0.0 api.recommendedsw.com
0.0.0.0 installer.betterinstaller.com
0.0.0.0 installer.filebulldog.com
0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
======System event log======
Computer Name: PC-PC
Event Code: 4321
Message: The name "PC-PC :0" could not be registered on the interface with IP address 192.168.1.9. The computer with the IP address 192.168.1.2 did not allow the name to be claimed by this computer.
Record Number: 1376
Source Name: NetBT
Time Written: 20151209091934.284833-000
Event Type: Error
User:
Computer Name: PC-PC
Event Code: 4321
Message: The name "PC-PC :20" could not be registered on the interface with IP address 192.168.1.9. The computer with the IP address 192.168.1.2 did not allow the name to be claimed by this computer.
Record Number: 1375
Source Name: NetBT
Time Written: 20151209091934.284833-000
Event Type: Error
User:
Computer Name: PC-PC
Event Code: 2505
Message: The server could not bind to the transport \Device\NetBT_Tcpip_{7089B032-EEC8-4628-97C0-462905BBAAF4} because another computer on the network has the same name. The server could not start.
Record Number: 1374
Source Name: Server
Time Written: 20151209091934.000000-000
Event Type: Error
User:
Computer Name: PC-PC
Event Code: 219
Message: The driver \Driver\WUDFRd failed to load for the device USB\Vid_03f0&Pid_371d&MI_03\7&361659e5&1&03.
Record Number: 1273
Source Name: Microsoft-Windows-Kernel-PnP
Time Written: 20151209085641.418420-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: PC-PC
Event Code: 27
Message: Intel(R) 82579LM Gigabit Network Connection
Network link is disconnected.
Record Number: 1271
Source Name: e1cexpress
Time Written: 20151209085640.763219-000
Event Type: Warning
User:
=====Application event log=====
Computer Name: PC-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-3213848150-4246953407-4286547329-1000:
Process 404 (\Device\HarddiskVolume2\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-3213848150-4246953407-4286547329-1000
Record Number: 280
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20151207175941.746366-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: PC-PC
Event Code: 3006
Message: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Record Number: 273
Source Name: Microsoft-Windows-LoadPerf
Time Written: 20151207170206.304296-000
Event Type: Error
User: NT AUTHORITY\SYSTEM
Computer Name: PC-PC
Event Code: 3006
Message: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.
Record Number: 271
Source Name: Microsoft-Windows-LoadPerf
Time Written: 20151207170206.226296-000
Event Type: Error
User: NT AUTHORITY\SYSTEM
Computer Name: PC-PC
Event Code: 10
Message: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Record Number: 192
Source Name: Microsoft-Windows-WMI
Time Written: 20151207165835.000000-000
Event Type: Error
User:
Computer Name: PC-PC
Event Code: 1008
Message: Služba Windows Search sa spúšťa a pokúša sa odstrániť starý index hľadania. {Dôvod: Full Index Reset}.
Record Number: 172
Source Name: Microsoft-Windows-Search
Time Written: 20151207165741.000000-000
Event Type: Warning
User:
=====Security event log=====
Computer Name: 37L4247F27-25
Event Code: 4735
Message: A security-enabled local group was changed.
Subject:
Security ID: S-1-5-18
Account Name: 37L4247F27-25$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Group:
Security ID: S-1-5-32-551
Group Name: Backup Operators
Group Domain: Builtin
Changed Attributes:
SAM Account Name: -
SID History: -
Additional Information:
Privileges: -
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20151207165230.787644-000
Event Type: Audit Success
User:
Computer Name: 37L4247F27-25
Event Code: 4731
Message: A security-enabled local group was created.
Subject:
Security ID: S-1-5-18
Account Name: 37L4247F27-25$
Account Domain: WORKGROUP
Logon ID: 0x3e7
New Group:
Security ID: S-1-5-32-551
Group Name: Backup Operators
Group Domain: Builtin
Attributes:
SAM Account Name: Backup Operators
SID History: -
Additional Information:
Privileges: -
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20151207165230.787644-000
Event Type: Audit Success
User:
Computer Name: 37L4247F27-25
Event Code: 4902
Message: The Per-user audit policy table was created.
Number of Elements: 0
Policy ID: 0x3213f
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20151207165230.413243-000
Event Type: Audit Success
User:
Computer Name: 37L4247F27-25
Event Code: 4624
Message: An account was successfully logged on.
Subject:
Security ID: S-1-0-0
Account Name: -
Account Domain: -
Logon ID: 0x0
Logon Type: 0
New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}
Process Information:
Process ID: 0x4
Process Name:
Network Information:
Workstation Name: -
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: -
Authentication Package: -
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
This event is generated when a logon session is created. It is generated on the computer that was accessed.
The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).
The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.
The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20151207165228.322840-000
Event Type: Audit Success
User:
Computer Name: 37L4247F27-25
Event Code: 4608
Message: Windows is starting up.
This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20151207165228.166839-000
Event Type: Audit Success
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=C:\ProgramData\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PSModulePath"=%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\
"NUMBER_OF_PROCESSORS"=4
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=Intel64 Family 6 Model 42 Stepping 7, GenuineIntel
"PROCESSOR_REVISION"=2a07
"windows_tracing_logfile"=C:\BVTBin\Tests\installpackage\csilogfile.log
"windows_tracing_flags"=3
"BREAKPAD_DUMP_LOCATION"=C:\Program Files (x86)\Coldold\Reports\Dump
-----------------EOF-----------------