  ""
==============================

	05.04.2008 5:34:20	NSUService	0		"       0   NSUService.            .       .

     , ,       .

     : 

Bad service request
"
	05.04.2008 5:34:19	VSS	8224		 VSS  - - . 
	05.04.2008 5:26:46	VSS	8224		 VSS  - - . 
	05.04.2008 5:13:37	HHCTRL	1903		"       1903   HHCTRL.            .       .

     , ,       .

     : 

http://go.microsoft.com/fwlink?LinkID=45839
"
	05.04.2008 4:43:37	HHCTRL	1903		"       1903   HHCTRL.            .       .

     , ,       .

     : 

http://go.microsoft.com/fwlink?LinkID=45839
"
	05.04.2008 4:15:48	Microsoft-Windows-LoadPerf	1000		C    WmiApRpl (WmiApRpl)  .        ,   .
	05.04.2008 4:15:46	Microsoft-Windows-LoadPerf	1001		    WmiApRpl (WmiApRpl)  .         Last Counter  Last Help.
	05.04.2008 4:15:46	WerSvc	5007		         Windows ( DLL,      ,       ).  : 8014FFF9.
	05.04.2008 4:11:46	SecurityCenter	1		    Windows .
	05.04.2008 4:09:51	Microsoft-Windows-Search	1003	 	  Windows .

	05.04.2008 4:09:45	Microsoft-Windows-CertificateServicesClient	1		   .
	05.04.2008 4:09:44	Microsoft-Windows-CertificateServicesClient	1		   .
	05.04.2008 4:09:40	VzFw	107		Started monitoring folder.
C:\Users\pan\Pictures
	05.04.2008 4:09:40	VzFw	107		Started monitoring folder.
C:\Documentation
	05.04.2008 4:09:40	VzFw	107		Started monitoring folder.
C:\Users\Public\Videos
	05.04.2008 4:09:40	VzFw	107		Started monitoring folder.
C:\Users\pan\Videos
	05.04.2008 4:09:40	VzFw	107		Started monitoring folder.
C:\Users\pan\Music
	05.04.2008 4:09:39	VzFw	107		Started monitoring folder.
C:\Users\Public\Music
	05.04.2008 4:09:39	VzFw	1		Service started.
	05.04.2008 4:09:39	VzCdbSvc	1		Service started.
	05.04.2008 4:09:39	Microsoft-Windows-WMI	5617		Windows Management Instrumentation Service subsystems initialized successfully
	05.04.2008 4:09:38	Microsoft-Windows-WMI	5615		Windows Management Instrumentation Service started sucessfully
	05.04.2008 4:09:38	VzCdbSvc	7		Failed to load the plug-in module. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5})(Error code = 0x80042019)
	05.04.2008 4:09:37	VAIO Event Service	0		"       0   VAIO Event Service.            .       .

     , ,       .

     : 

Service started
"
	05.04.2008 4:09:37	VcmIAlzMgr	0		"       0   VcmIAlzMgr.            .       .

     , ,       .

     : 

Service started
"
	05.04.2008 4:09:35	SPIDERNT	13		SpIDer Guard started OK.
	05.04.2008 4:09:35	NSUService	0		"       0   NSUService.            .       .

     , ,       .

     : 

Service started
"
	05.04.2008 4:09:31	IviRegMgr	0		"       0   IviRegMgr.            .       .

     , ,       .

     : 

Service started
"
	05.04.2008 4:09:30	Adobe Active File Monitor 5.0	2570	(1)	Adobe Active File Monitor Service has Started.
	05.04.2008 4:09:11	Microsoft-Windows-Winlogon	6000		    -    winlogon <SessionEnv>.
	05.04.2008 4:09:11	Microsoft-Windows-Winlogon	4101		 Windows .
	05.04.2008 4:09:06	Microsoft-Windows-Security-Licensing-SLC	902		"    .
"
	05.04.2008 4:09:02	Microsoft-Windows-Security-Licensing-SLC	1005		"   Windows: hr=0x0
"
	05.04.2008 4:09:02	Microsoft-Windows-Security-Licensing-SLC	1003		"       .
 =55c92734-d682-4d71-983e-d6ec3f16059f
 =
{1,[9e042223-03bf-49ae-808f-ff37f128d40d, 8, 0xC004F014,0x0]}

{1,[a4eec485-e375-48b4-8f51-80d13a4086b6, 8, 0xC004F014,0x0]}

{1,[b6795467-dc45-4acf-af87-e948ee3f15f4, 8, 0xC004F014,0x0]}

{1,[bffdc375-bbd5-499d-8ef1-4f37b61c895f, 0, 0x0,0x0],[0x0,0x0,0x0,0,0,0x0],[0x0,0xFFFFFFFF,0x0,0,0,0x0],[0x0,0xFFFFFFFF,0x0,0,0,0x0],[0,0,0x0]}

{1,[f3acdd3c-119a-4932-a3d7-0b6f33a1dca9, 8, 0xC004F014,0x0]}

{1,[afd5f68f-b70f-4000-a21d-28dbc8be8b07, 8, 0xC004F014,0x0]}
"
	05.04.2008 4:09:02	Microsoft-Windows-Security-Licensing-SLC	1033		"  ,       override-only.
 =(IIS-W3SVC-MaxConcurrentRequests) (Telnet-Client-EnableTelnetClient) (Telnet-Client-EnableTelnetClient_w) (Telnet-Server-EnableTelnetServer) (Telnet-Server-EnableTelnetServer_w) 
 =55c92734-d682-4d71-983e-d6ec3f16059f
 SKU=bffdc375-bbd5-499d-8ef1-4f37b61c895f"
	05.04.2008 4:08:59	Microsoft-Windows-EventSystem	4625		 EventSystem        86400 .      REG_DWORD   SuppressDuplicateDuration    : HKLM\Software\Microsoft\EventSystem\EventLog.
	05.04.2008 4:08:58	Microsoft-Windows-Security-Licensing-SLC	900		"     .
"
	05.04.2008 4:08:58	Microsoft-Windows-User Profiles Service	1531		"    .  

"
	05.04.2008 4:07:40	Microsoft-Windows-CertificateServicesClient	2		   .
	05.04.2008 4:07:26	Microsoft-Windows-Security-Licensing-SLC	901		"     .
"
	05.04.2008 4:07:25	VSS	8225		 VSS  -  ,    . 
	05.04.2008 4:07:25	SecurityCenter	2		    Windows .
	05.04.2008 4:07:22	Microsoft-Windows-User Profiles Service	1530		"  ,        .    .   ,    ,    .  

  - 
 1 user registry handles leaked from \Registry\User\S-1-5-21-510203700-3531168436-3544484334-1000_Classes:
Process 968 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-510203700-3531168436-3544484334-1000_CLASSES
"
	05.04.2008 4:07:21	Microsoft-Windows-User Profiles Service	1530		"  ,        .    .   ,    ,    .  

  - 
 1 user registry handles leaked from \Registry\User\S-1-5-21-510203700-3531168436-3544484334-1000:
Process 968 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-510203700-3531168436-3544484334-1000
"
	05.04.2008 4:07:21	Desktop Window Manager	9009		        (0x40010004)
	05.04.2008 4:06:28	System Restore	8194		"    ( = C:\Users\pan\AppData\Local\Temp\set203.tmp -deleter -l0x19 -your_launchersetup.exe -clone_of""c:\program files\installshield installation information\{f18e8a0f-be99-4305-96a5-6c0fd9d7d999}\"";  =  mobile PhoneTools)."
	05.04.2008 4:05:50	System Restore	8194		"    ( = C:\Users\pan\AppData\Local\Temp\set203.tmp -deleter -l0x19 -your_launchersetup.exe -clone_of""c:\program files\installshield installation information\{f18e8a0f-be99-4305-96a5-6c0fd9d7d999}\"";  =  mobile PhoneTools)."
	05.04.2008 4:05:38	VSS	8194		   :      IVssWriterCallback.  hr = 0x80070005.    -        . 

:
      

:
      : {e8132975-6f93-4464-a53e-1050253ae220}
     : System Writer
      : {4e2007b1-ba21-4717-a127-a1a49efe194e}
	05.04.2008 4:05:19	System Restore	8194		"    ( = C:\Users\pan\AppData\Local\Temp\set203.tmp -deleter -l0x19 -your_launchersetup.exe -clone_of""c:\program files\installshield installation information\{f18e8a0f-be99-4305-96a5-6c0fd9d7d999}\"";  =  mobile PhoneTools)."
	05.04.2008 4:05:12	VSS	8194		   :      IVssWriterCallback.  hr = 0x80070005.    -        . 
=========================



:
      

:
      : {e8132975-6f93-4464-a53e-1050253ae220}
     : System Writer
      : {4e2007b1-ba21-4717-a127-a1a49efe194e}
	05.04.2008 3:55:54	VSS	8224		 VSS  - - . 
	05.04.2008 3:52:38	Microsoft-Windows-RestartManager	10001		  1,  04.04.2008 23:52:23.
	05.04.2008 3:52:38	MsiInstaller	1034		 Windows   . : Vista Manager. : 1.1.2. : 1033.    : 0.
	05.04.2008 3:52:38	MsiInstaller	11724		Product: Vista Manager -- Removal completed successfully.
	05.04.2008 3:52:38	System Restore	8194		    ( = C:\Windows\system32\msiexec.exe /V;  = ).
	05.04.2008 3:52:23	Microsoft-Windows-RestartManager	10000		  1 - 04.04.2008 23:52:23.
	05.04.2008 3:52:20	System Restore	8194		    ( = C:\Windows\system32\msiexec.exe /V;  = Removed Vista Manager).
	05.04.2008 3:52:04	Microsoft-Windows-RestartManager	10001		  1,  04.04.2008 23:51:59.
	05.04.2008 3:52:04	MsiInstaller	1034		 Windows   . : RSS Builder. : 2.1.8. : 1033.    : 0.
	05.04.2008 3:52:04	MsiInstaller	11724		Product: RSS Builder -- Removal completed successfully.
	05.04.2008 3:52:04	System Restore	8194		    ( = C:\Windows\system32\msiexec.exe /V;  = ).
	05.04.2008 3:51:59	Microsoft-Windows-RestartManager	10000		  1 - 04.04.2008 23:51:59.
	05.04.2008 3:51:46	System Restore	8194		    ( = C:\Windows\system32\msiexec.exe /V;  = Removed RSS Builder).
	05.04.2008 3:47:55	VSS	8224		 VSS  - - . 
	05.04.2008 3:43:38	HHCTRL	1903		"       1903   HHCTRL.            .       .

     , ,       .

     : 

http://go.microsoft.com/fwlink?LinkID=45839
"
	05.04.2008 3:40:08	VSS	8224		 VSS  - - . 
	05.04.2008 3:35:58	System Restore	8209		     : (  Windows).  : .
	05.04.2008 3:33:48	VSS	8224		 VSS  - - . 
	05.04.2008 3:30:46	Microsoft-Windows-CertificateServicesClient	1		   .
	05.04.2008 3:30:46	Microsoft-Windows-Winlogon	4101		 Windows .
	05.04.2008 3:24:19	Microsoft-Windows-LoadPerf	1000		C    WmiApRpl (WmiApRpl)  .        ,   .
	05.04.2008 3:24:18	Microsoft-Windows-LoadPerf	1001		    WmiApRpl (WmiApRpl)  .         Last Counter  Last Help.
	05.04.2008 3:19:26	SecurityCenter	1		    Windows .
	05.04.2008 3:17:12	Microsoft-Windows-CertificateServicesClient	1		   .
	05.04.2008 3:17:11	Microsoft-Windows-Search	1003	 	  Windows .

	05.04.2008 3:17:06	VzFw	107		Started monitoring folder.
C:\Users\pan\Music
	05.04.2008 3:17:06	VzFw	107		Started monitoring folder.
C:\Users\pan\Pictures
	05.04.2008 3:17:06	VzFw	107		Started monitoring folder.
C:\Users\Public\Music
	05.04.2008 3:17:06	VzFw	107		Started monitoring folder.
C:\Users\pan\Videos
	05.04.2008 3:17:06	VzFw	107		Started monitoring folder.
C:\Users\Public\Videos
	05.04.2008 3:17:06	VzFw	107		Started monitoring folder.
C:\Documentation
	05.04.2008 3:17:06	VzFw	1		Service started.
	05.04.2008 3:17:06	VzCdbSvc	1		Service started.
	05.04.2008 3:17:05	VzCdbSvc	7		Failed to load the plug-in module. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5})(Error code = 0x80042019)
	05.04.2008 3:17:04	Microsoft-Windows-WMI	5617		Windows Management Instrumentation Service subsystems initialized successfully
	05.04.2008 3:17:04	VAIO Event Service	0		"       0   VAIO Event Service.            .       .

     , ,       .

     : 

Service started
"
	05.04.2008 3:17:04	Microsoft-Windows-WMI	5615		Windows Management Instrumentation Service started sucessfully
	05.04.2008 3:17:04	VcmIAlzMgr	0		"       0   VcmIAlzMgr.            .       .

     , ,       .

     : 

Service started
"
	05.04.2008 3:17:03	NSUService	0		"       0   NSUService.            .       .

     , ,       .

     : 

Service started
"
	05.04.2008 3:17:03	SPIDERNT	13		SpIDer Guard started OK.
	05.04.2008 3:17:00	IviRegMgr	0		"       0   IviRegMgr.            .       .

     , ,       .

     : 

Service started
"
	05.04.2008 3:16:59	Adobe Active File Monitor 5.0	2570	(1)	Adobe Active File Monitor Service has Started.
	05.04.2008 3:16:12	Microsoft-Windows-Security-Licensing-SLC	902		"    .
"
	05.04.2008 3:16:11	Microsoft-Windows-Security-Licensing-SLC	1005		"   Windows: hr=0x0
"
	05.04.2008 3:16:11	Microsoft-Windows-Security-Licensing-SLC	1003		"       .
 =55c92734-d682-4d71-983e-d6ec3f16059f
 =
{1,[9e042223-03bf-49ae-808f-ff37f128d40d, 8, 0xC004F014,0x0]}

{1,[a4eec485-e375-48b4-8f51-80d13a4086b6, 8, 0xC004F014,0x0]}

{1,[b6795467-dc45-4acf-af87-e948ee3f15f4, 8, 0xC004F014,0x0]}

{1,[bffdc375-bbd5-499d-8ef1-4f37b61c895f, 0, 0x0,0x0],[0x0,0x0,0x0,0,0,0x0],[0x0,0xFFFFFFFF,0x0,0,0,0x0],[0x0,0xFFFFFFFF,0x0,0,0,0x0],[0,0,0x0]}

{1,[f3acdd3c-119a-4932-a3d7-0b6f33a1dca9, 8, 0xC004F014,0x0]}

{1,[afd5f68f-b70f-4000-a21d-28dbc8be8b07, 8, 0xC004F014,0x0]}
"
	05.04.2008 3:16:11	Microsoft-Windows-Security-Licensing-SLC	1033		"  ,       override-only.
 =(IIS-W3SVC-MaxConcurrentRequests) (Telnet-Client-EnableTelnetClient) (Telnet-Client-EnableTelnetClient_w) (Telnet-Server-EnableTelnetServer) (Telnet-Server-EnableTelnetServer_w) 
 =55c92734-d682-4d71-983e-d6ec3f16059f
 SKU=bffdc375-bbd5-499d-8ef1-4f37b61c895f"
	05.04.2008 3:16:09	Microsoft-Windows-EventSystem	4625		 EventSystem        86400 .      REG_DWORD   SuppressDuplicateDuration    : HKLM\Software\Microsoft\EventSystem\EventLog.
	05.04.2008 3:16:09	Microsoft-Windows-Security-Licensing-SLC	900		"     .
"
	05.04.2008 3:16:09	Microsoft-Windows-User Profiles Service	1531		"    .  

"
	05.04.2008 3:03:07	Microsoft-Windows-CertificateServicesClient	2		   .
	05.04.2008 3:03:05	SecurityCenter	2		    Windows .
	05.04.2008 3:03:04	Microsoft-Windows-User Profiles Service	1532		"   .  

"
	05.04.2008 3:03:04	Microsoft-Windows-Security-Licensing-SLC	901		"     .
"
	05.04.2008 3:03:04	VSS	8225		 VSS  -  ,    . 
	05.04.2008 3:03:04	Microsoft-Windows-User Profiles Service	1530		"  ,        .    .   ,    ,    .  

  - 
 1 user registry handles leaked from \Registry\User\S-1-5-21-510203700-3531168436-3544484334-1000_Classes:
Process 992 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-510203700-3531168436-3544484334-1000_CLASSES
"
	05.04.2008 3:03:02	Microsoft-Windows-Winsrv	10002		       : MSASCui.exe.
	05.04.2008 3:03:03	Microsoft-Windows-User Profiles Service	1530		"  ,        .    .   ,    ,    .  

  - 
 1 user registry handles leaked from \Registry\User\S-1-5-21-510203700-3531168436-3544484334-1000:
Process 992 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-510203700-3531168436-3544484334-1000
"
	05.04.2008 3:03:03	Desktop Window Manager	9009		        (0x40010004)
	05.04.2008 3:02:53	System Restore	8198		   : (  Windows).
	05.04.2008 3:02:53	System Restore	8196		   ( =   Windows;  = [C:\]).
	05.04.2008 2:56:57	Microsoft-Windows-LoadPerf	1000		C    WmiApRpl (WmiApRpl)  .        ,   .
	05.04.2008 2:56:55	Microsoft-Windows-LoadPerf	1001		    WmiApRpl (WmiApRpl)  .         Last Counter  Last Help.
	05.04.2008 2:56:31	System Restore	8209		     : (  ).  : .
	05.04.2008 2:54:18	SecurityCenter	1		    Windows .
	05.04.2008 2:53:54	VSS	8224		 VSS  - - . 
	05.04.2008 2:50:52	Microsoft-Windows-CertificateServicesClient	1		   .
	05.04.2008 2:50:52	Microsoft-Windows-CertificateServicesClient	1		   .
	05.04.2008 2:50:52	Microsoft-Windows-Search	1003	 	  Windows .

	05.04.2008 2:50:47	VzFw	107		Started monitoring folder.
C:\Users\pan\Videos
	05.04.2008 2:50:47	VzFw	107		Started monitoring folder.
C:\Documentation
	05.04.2008 2:50:47	VzFw	107		Started monitoring folder.
C:\Users\Public\Videos
	05.04.2008 2:50:47	VzFw	107		Started monitoring folder.
C:\Users\pan\Pictures
	05.04.2008 2:50:47	VzFw	107		Started monitoring folder.
C:\Users\pan\Music
	05.04.2008 2:50:47	VzFw	107		Started monitoring folder.
C:\Users\Public\Music
	05.04.2008 2:50:47	VzFw	1		Service started.
	05.04.2008 2:50:47	VzCdbSvc	1		Service started.
	05.04.2008 2:50:46	VzCdbSvc	7		Failed to load the plug-in module. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5})(Error code = 0x80042019)
	05.04.2008 2:50:46	Microsoft-Windows-WMI	5617		Windows Management Instrumentation Service subsystems initialized successfully
	05.04.2008 2:50:46	VAIO Event Service	0		"       0   VAIO Event Service.            .       .

     , ,       .

     : 

Service started
"
	05.04.2008 2:50:45	VcmIAlzMgr	0		"       0   VcmIAlzMgr.            .       .

     , ,       .

     : 

Service started
"
	05.04.2008 2:50:45	Microsoft-Windows-WMI	5615		Windows Management Instrumentation Service started sucessfully
	05.04.2008 2:50:44	NSUService	0		"       0   NSUService.            .       .

     , ,       .

     : 
========================================================================================================