--------[ EVEREST Ultimate Edition ]------------------------------------------------------------------------------------

                                                EVEREST v5.00.1650/ru
                                        2.4.258.0
                                      http://www.lavalys.com/
                                              
                                             USER-PC
                                             user
                                   Microsoft Windows 7 Ultimate 6.1.7601
                                                  2002-01-06
                                                 14:58


--------[   ]----------------------------------------------------------------------------------------

    :
                                           ACPI    x86
                                     Microsoft Windows 7 Ultimate
                                       Service Pack 1
      Internet Explorer                                 8.0.7601.17514
      DirectX                                           DirectX 10.1
                                           USER-PC
                                         user
                                              user-PC
       /                                       2002-01-06 / 14:58

     :
                                                   DualCore AMD Athlon 64 X2, 2200 MHz (11 x 200) 4200+
                                          Asus M2N-X  (3 PCI, 2 PCI-E x1, 1 PCI-E x16, 2 DDR2 DIMM, Audio, LAN)
                                    nVIDIA nForce 520, AMD Hammer
                                         2048   (DDR2-800 DDR2 SDRAM)
      DIMM1: A-Data DQVE1A16                            1  DDR2-800 DDR2 SDRAM  (5-5-5-18 @ 400 )  (4-4-4-12 @ 266 )  (3-3-3-9 @ 200 )
      DIMM2: A-Data DQVE1A16                            1  DDR2-800 DDR2 SDRAM  (5-5-5-18 @ 400 )  (4-4-4-12 @ 266 )  (3-3-3-9 @ 200 )
       BIOS                                          AMI (06/27/07)
                                      (COM1)
                                      (LPT1)

    :
                                            NVIDIA GeForce 8600 GT (Microsoft Corporation - WDDM v1.1)  (512 )
                                            NVIDIA GeForce 8600 GT (Microsoft Corporation - WDDM v1.1)  (512 )
      3D-                                    nVIDIA GeForce 8600 GT
                                                 LG L1918S  [19" LCD]  (170786967)

    :
                                         Realtek ALC883 @ nVIDIA MCP65 - High Definition Audio Controller

     :
       IDE                                       PCI IDE
       IDE                                       PCI IDE
                                      ST3250410AS ATA Device  (250 , 7200 RPM, SATA-II)
                                    PIONEER DVD-RW  DVR-219L ATA Device
       SMART                         OK

    :
      C: (NTFS)                                         20002  (9937  )
      D: (NTFS)                                         213.3  (44.3  )
                                              232.9  (54.0  )

    :
                                                PS/2
                                                    Microsoft PS/2 

    :
        IP                                127.0.0.1
        MAC                               00-1B-FC-89-6F-8C
                                            NVIDIA nForce

     :
                                                 Fax
                                                 Microsoft XPS Document Writer
       USB1                                   nVIDIA MCP65 - OHCI USB 1.1 Controller
       USB2                                   nVIDIA MCP65 - EHCI USB 2.0 Controller

    DMI:
      DMI  BIOS                                American Megatrends Inc.
      DMI  BIOS                                   0701
      DMI                           System manufacturer
      DMI                                        System Product Name
      DMI                                System Version
      DMI                         System Serial Number
      DMI  UUID                                60672F75-7743DC11-8433001B-FC896F8C
      DMI                    ASUSTeK Computer INC.
      DMI                                 M2N-X
      DMI                           Rev x.xx
      DMI                    MT7078K00601241
      DMI                             Chassis Manufacture
      DMI                                    Chassis Version
      DMI                             Chassis Serial Number
      DMI Asset-                                Asset-1234567890
      DMI                                       Desktop Case
      DMI  /                 2 / 0


--------[   ]----------------------------------------------------------------------------------------------

          
     NetBIOS                 USER-PC
      DNS               user-PC
      DNS              
      DNS              user-PC
     NetBIOS                 USER-PC
      DNS               user-PC
      DNS              
      DNS              user-PC


--------[ DMI ]---------------------------------------------------------------------------------------------------------

  [ BIOS ]

     BIOS:
                                           American Megatrends Inc.
                                                  0701
                                             06/27/2007
                                                  512 
                                   Floppy Disk, Hard Disk, CD-ROM, ATAPI ZIP, LS-120
                                             Flash BIOS, Shadow BIOS, Selectable Boot, EDD, BBS
                                 DMI, APM, ACPI, ESCD, PnP
                                   ISA, PCI, USB

  [  ]

     :
                                           System manufacturer
                                                 System Product Name
                                                  System Version
                                           System Serial Number
      SKU#                                              To Be Filled By O.E.M.
                                               To Be Filled By O.E.M.
        ID                       60672F75-7743DC11-8433001B-FC896F8C
                                           

  [   ]

      :
                                           ASUSTeK Computer INC.
                                                 M2N-X
                                                  Rev x.xx
                                           MT7078K00601241

  [  ]

     :
                                           Chassis Manufacture
                                                  Chassis Version
                                           Chassis Serial Number
                                            Asset-1234567890
                                                
                                     
                               
                                  
                                   

  [   ]

      :
                                  64-bit ECC
                                         
                              1-Way
                                1-Way
                             70ns, 60ns
                                DIMM, SDRAM
                   3.3V
                           2048 
                                           2

  [  / AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ ]

     :
                                           AMD
                                                  AMD Athlon(tm) 64 X2 Dual Core Processor 4200+
                                           To Be Filled By O.E.M.
                                            To Be Filled By O.E.M.
                                          To Be Filled By O.E.M.
                                          200 
                                     2200 
                                          2200 
                                                     Central Processor
                                       1.5 V
                                                  
                                              CPU 1

  [ - / L1-Cache ]

     :
                                                     
                                                  
                                             Varies with Memory Address
                                         4-way Set-Associative
                                       256 
                                      256 
        SRAM                           Pipeline Burst
        SRAM                                  Pipeline Burst
                                         Single-bit ECC
                                              L1-Cache

  [ - / L2-Cache ]

     :
                                                     
                                                  
                                             Varies with Memory Address
                                         4-way Set-Associative
                                       1024 
                                      1024 
        SRAM                           Pipeline Burst
        SRAM                                  Pipeline Burst
                                         Single-bit ECC
                                              L2-Cache

  [ - / L3-Cache ]

     :
                                                     
                                                  
                                       0 
                                      0 
                                              L3-Cache

  [   / DIMM0 ]

      :
                                              DIMM0
                                                     DIMM
                                                160 ns
                                      1024 
                                         1024 

  [   / DIMM1 ]

      :
                                              DIMM1
                                                     DIMM
                                                162 ns
                                      1024 
                                         1024 

  [   / DIMM0 ]

      :
      -                                       DIMM
                                                     DDR2
                                                     Synchronous
                                                  1024 
                                                800 
                                             64 
                                            72 
                                              DIMM0
                                                    BANK0
                                           Manufacturer0
                                           SerNum0
                                            AssetTagNum0
                                          PartNum0

  [   / DIMM1 ]

      :
      -                                       DIMM
                                                     DDR2
                                                     Synchronous
                                                  1024 
                                                800 
                                             64 
                                            72 
                                              DIMM1
                                                    BANK1
                                           Manufacturer1
                                           SerNum1
                                            AssetTagNum1
                                          PartNum1

  [   / PCIEX16 ]

      :
                                       PCIEX16
                                                     PCI-E x1
                                           
                                        x16
                                                   

  [   / PCIEX1_1 ]

      :
                                       PCIEX1_1
                                                     PCI-E x1
                                           
                                        x1
                                                   

  [   / PCIEX1_2 ]

      :
                                       PCIEX1_2
                                                     PCI-E x1
                                           
                                        x1
                                                   

  [   / PCI1 ]

      :
                                       PCI1
                                                     PCI
                                           
                                        32-bit
                                                   

  [   / PCI2 ]

      :
                                       PCI2
                                                     PCI
                                           
                                        32-bit
                                                   

  [   / PCI3 ]

      :
                                       PCI3
                                                     PCI
                                           
                                        32-bit
                                                   

  [   / PS2Mouse ]

      :
                                                Mouse Port
                                   PS/2 Mouse
                                    
                                      PS2Mouse
                                       PS/2

  [   / Keyboard ]

      :
                                                Keyboard Port
                                   PS/2 Keyboard
                                    
                                      
                                       PS/2

  [   / USB1 ]

      :
                                                USB
                                   USB1
                                    
                                      USB1
                                       USB

  [   / USB2 ]

      :
                                                USB
                                   USB2
                                    
                                      USB2
                                       USB

  [   / USB3 ]

      :
                                                USB
                                   USB3
                                    
                                      USB3
                                       USB

  [   / USB4 ]

      :
                                                USB
                                   USB4
                                    
                                      USB4
                                       USB

  [   / USB5 ]

      :
                                                USB
                                   USB5
                                    
                                      USB5
                                       USB

  [   / USB6 ]

      :
                                                USB
                                   USB6
                                    
                                      USB6
                                       USB

  [   / USB7 ]

      :
                                                USB
                                   USB7
                                    
                                      USB7
                                       USB

  [   / USB8 ]

      :
                                                USB
                                   USB8
                                    
                                      USB8
                                       USB

  [   / USB9 ]

      :
                                                USB
                                   USB9
                                    
                                      USB9
                                       USB

  [   / USB10 ]

      :
                                                USB
                                   USB10
                                    
                                      USB10
                                       USB

  [   / LPT 1 ]

      :
                                                Parallel Port ECP/EPP
                                   LPT Port
                                    
                                      LPT 1
                                       DB-25 pin male

  [   / COM A ]

      :
                                                Serial Port 16550A Compatible
                                   COM Port
                                    
                                      COM A
                                       DB-9 pin male

  [   / Audio Mic In ]

      :
                                                Audio Port
                                   Audio Mic In
                                    
                                      Audio Mic In
                                       Mini-jack (headphones)

  [   / Audio Line In ]

      :
                                                Audio Port
                                   Audio Line In
                                    
                                      Audio Line In
                                       Mini-jack (headphones)

  [   / Audio Line Out ]

      :
                                                Audio Port
                                   Audio Line Out
                                    
                                      Audio Line Out
                                       Mini-jack (headphones)

  [   / SPDIF ]

      :
                                   SPDIF
                                       

  [   / PRI IDE ]

      :
                                   PRI IDE
                                    On-Board IDE
                                       

  [   / FLOPPY ]

      :
                                   FLOPPY
                                    On-Board Floppy
                                       

  [   / FRONT PNL ]

      :
                                   FRONT PNL
                                    9 Pin Dual Inline (pin 10 cut)
                                       

  [   / CHASSIS REAR FAN ]

      :
                                   CHASSIS REAR FAN
                                       

  [   / CPU FAN ]

      :
                                   CPU FAN
                                       

  [   / SATA1 ]

      :
                                   SATA1
                                       

  [   / SATA2 ]

      :
                                   SATA2
                                       

  [   / SATA3 ]

      :
                                   SATA3
                                       

  [   / SATA4 ]

      :
                                   SATA4
                                       

  [   / To Be Filled By O.E.M. ]

      :
                                                To Be Filled By O.E.M.
                                                     Video
                                                  

  [  ]

    :
      OEM String                                        001BFC896F8C
      OEM String                                        To Be Filled By O.E.M.
      OEM String                                        To Be Filled By O.E.M.
      OEM String                                        To Be Filled By O.E.M.


--------[  ]------------------------------------------------------------------------------------------------------

     :
                                                   DualCore AMD Athlon 64 X2 4200+
                                             Windsor-512
                                              BH-F2
      Engineering Sample                                
        CPUID                                      AMD Athlon(tm) 64 X2 Dual Core Processor 4200+
       CPUID                                      00040FB2h

     :
                                               2210.0 MHz  (: 2200 MHz)
                                             11x
      CPU FSB                                           200.9 MHz  (: 200 MHz)
       HyperTransport                            1004.6 MHz
                                              368.3 MHz
       DRAM:FSB                              CPU/6

     :
       L1                                        64  per core  (Parity)
       L1                                      64  per core  (ECC)
       L2                                            512  per core  (On-Die, ECC, Full-Speed)

      :
      ID                                  63-0701-000001-00101111-062707-MCP65$A0744000_BIOS DATE: 06/27/07 10:49:01 VER: 08.00.12
                                          Asus M2N-X  (3 PCI, 2 PCI-E x1, 1 PCI-E x16, 2 DDR2 DIMM, Audio, LAN)

       ():
                                    nVIDIA nForce 520, AMD Hammer
                                          5-5-5-18  (CL-RCD-RP-RAS)
      Command Rate (CR)                                 2T
      DIMM1: A-Data DQVE1A16                            1  DDR2-800 DDR2 SDRAM  (5-5-5-18 @ 400 )  (4-4-4-12 @ 266 )  (3-3-3-9 @ 200 )
      DIMM2: A-Data DQVE1A16                            1  DDR2-800 DDR2 SDRAM  (5-5-5-18 @ 400 )  (4-4-4-12 @ 266 )  (3-3-3-9 @ 200 )

     BIOS:
        BIOS                               06/27/07
       BIOS                            06/20/07
      DMI  BIOS                                   0701

      :
                                            nVIDIA GeForce 8600 GT
                                       G84GT  (PCI Express 1.0 x16 10DE / 0402, Rev A2)
        (Geometric Domain)                     540   (: 540 MHz)
        (Shader Domain)                        1188   (: 1188 MHz)
                                           301   (: 300 MHz)


--------[  ]----------------------------------------------------------------------------------------------

     :
                                  
                                         
                              
                          


--------[   ]----------------------------------------------------------------------------------------------

    Centrino (Carmel)  :
      : Intel Pentium M (Banias/Dothan)                 (DualCore AMD Athlon 64 X2)
      : Intel i855GM/PM                             (nVIDIA nForce 520, AMD Hammer)
      WLAN: Intel PRO/Wireless                          
      : Centrino-                     

    Centrino (Sonoma)  :
      : Intel Pentium M (Dothan)                        (DualCore AMD Athlon 64 X2)
      : Intel i915GM/PM                             (nVIDIA nForce 520, AMD Hammer)
      WLAN: Intel PRO/Wireless                          
      : Centrino-                     

    Centrino (Napa)  :
      : Intel Core (Yonah) / Core 2 (Merom)             (DualCore AMD Athlon 64 X2)
      : Intel i945GM/PM                             (nVIDIA nForce 520, AMD Hammer)
      WLAN: Intel PRO/Wireless 3945                     
      : Centrino-                     

    Centrino (Santa Rosa)  :
      : Intel Core 2 (Merom/Penryn)                     (DualCore AMD Athlon 64 X2)
      : Intel GM965/PM965                           (nVIDIA nForce 520, AMD Hammer)
      WLAN: Intel Wireless WiFi Link 4965               
      : Centrino-                     

    Centrino (Montevina)  :
      : Intel Core 2 (Penryn)                           (DualCore AMD Athlon 64 X2)
      : Intel GM45/GM47/GS45/PM45                   (nVIDIA nForce 520, AMD Hammer)
      WLAN: Intel WiFi Link 5000 Series                 
      : Centrino-                     


--------[  ]------------------------------------------------------------------------------------------------------

     :
                                              ITE IT8712F v7+  (ISA 290h)
                                            Diode  (NV-Diode)
                               

    :
                                          30 C  (86 F)
       1 /  1                                     33 C  (91 F)
       1 /  2                                     28 C  (82 F)
      MCP                                               53 C  (127 F)
      Aux                                               29 C  (84 F)
                                                  51 C  (124 F)
      Seagate ST3250410AS                               35 C  (95 F)

    :
                                                      2500 RPM

    :
                                                  1.26 V
      +3.3 V                                            3.28 V
      +12 V                                             12.54 V
       VBAT                                      3.09 V
      Debug Info F                                      010E FFFF 0000 0000 0000
      Debug Info T                                      29 30 128
      Debug Info V                                      4F FF CD FF C4 61 FF (F7)


--------[  ]----------------------------------------------------------------------------------------------------------

     :
                                                   DualCore AMD Athlon 64 X2, 2200 MHz (11 x 200) 4200+
                                             Windsor-512
                                              BH-F2
                                        x86, x86-64, MMX, 3DNow!, SSE, SSE2, SSE3
                                         2200 
      ./.                             4x / 11x
      Engineering Sample                                
       L1                                        64  per core  (Parity)
       L1                                      64  per core  (ECC)
       L2                                            512  per core  (On-Die, ECC, Full-Speed)

    Multi CPU:
      ID                                  TEMPLATE
      CPU #1                                            AMD Athlon(tm) 64 X2 Dual Core Processor 4200+, 2210 
      CPU #2                                            AMD Athlon(tm) 64 X2 Dual Core Processor 4200+, 2210 

       :
                                              940 Pin uOPGA
                                          4.00 cm x 4.00 cm
                                       227.4 .
                                  9Mi, 90 nm, CMOS, Cu, DSL SOI
                                         230 mm2
                                   1.100 - 1.300 V
       I/O                                    1.2 V + 2.5 V

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us-en/Processors/ProductInformation/0,,30_118,00.html

     :
       1 /  1                                     0 %
       1 /  2                                     0 %


--------[ CPUID ]-------------------------------------------------------------------------------------------------------

     CPUID:
       CPUID                               AuthenticAMD
        CPUID                                      AMD Athlon(tm) 64 X2 Dual Core Processor 4200+
       CPUID                                      00040FB2h
        CPUID                          00040FB2h
       AMD                                 08D1h  (Athlon 64 X2 4200+)
                                  D5h  (Socket AM2)
      HTT / CMP                                         0 / 2

     :
      64- x86- (AMD64, Intel64)            
      AMD 3DNow!                                        
      AMD 3DNow! Professional                           
      AMD 3DNowPrefetch                                  
      AMD Enhanced 3DNow!                               
      AMD Extended MMX                                  
      AMD MisAligned SSE                                 
      AMD SSE4A                                          
      AMD SSE5                                           
      Cyrix Extended MMX                                 
      IA-64                                              
      IA MMX                                            
      IA SSE                                            
      IA SSE 2                                          
      IA SSE 3                                          
      IA Supplemental SSE 3                              
      IA SSE 4.1                                         
      IA SSE 4.2                                         
      IA AVX                                             
      IA FMA                                             
      IA AES Extensions                                  
      VIA Alternate Instruction Set                      
       CLFLUSH                                
       CMPXCHG8B                              
       CMPXCHG16B                             
       Conditional Move                       
       LZCNT                                   
       MONITOR / MWAIT                         
       MOVBE                                   
       PCLMULQDQ                               
       POPCNT                                  
       RDTSCP                                 
       SYSCALL / SYSRET                       
       SYSENTER / SYSEXIT                     
       VIA FEMMS                               

     :
      Advanced Cryptography Engine (ACE)                 
      Advanced Cryptography Engine 2 (ACE2)              
         (DEP, NX, EDB)           
          (RNG)         
      PadLock Hash Engine (PHE)                          
      PadLock Montgomery Multiplier (PMM)                
         (PSN)                    

     :
      Automatic Clock Control                            
      Digital Thermometer                               
      Dynamic FSB Frequency Switching                    
      Enhanced Halt State (C1E)                          
      Enhanced SpeedStep Technology (EIST, ESS)          
      Frequency ID Control                              
      Hardware P-State Control                           
      LongRun                                            
      LongRun Table Interface                            
      PowerSaver 1.0                                     
      PowerSaver 2.0                                     
      PowerSaver 3.0                                     
      Processor Duty Cycle Control                       
      Software Thermal Control                          
                                               
      Thermal Monitor 1                                  
      Thermal Monitor 2                                  
      Thermal Monitoring                                
      Thermal Trip                                      
      Voltage ID Control                                

     CPUID:
      1 GB Page Size                                     
      36-bit Page Size Extension                        
      Address Region Registers (ARR)                     
      CPL Qualified Debug Store                          
      Debug Trace Store                                  
      Debugging Extension                               
      Direct Cache Access                                
      Dynamic Acceleration Technology (IDA)              
      Fast Save & Restore                               
      Hyper-Threading Technology (HTT)                   
      Invariant Time Stamp Counter                       
      L1 Context ID                                      
      Local APIC On Chip                                
      Machine Check Architecture (MCA)                  
      Machine Check Exception (MCE)                     
      Memory Configuration Registers (MCR)               
      Memory Type Range Registers (MTRR)                
      Model Specific Registers (MSR)                    
      Nested Paging                                      
      Page Attribute Table (PAT)                        
      Page Global Extension                             
      Page Size Extension (PSE)                         
      Pending Break Event                                
      Physical Address Extension (PAE)                  
      Safer Mode Extensions (SMX)                        
      Secure Virtual Machine Extensions (Pacifica)      
      Self-Snoop                                         
      Time Stamp Counter (TSC)                          
      Turbo Boost                                        
      Virtual Machine Extensions (Vanderpool)            
      Virtual Mode Extension                            
      x2APIC                                             
      XSAVE / XRSTOR Extended States                     

    CPUID Registers (CPU #1):
      CPUID 00000000                                    00000001-68747541-444D4163-69746E65
      CPUID 00000001                                    00040FB2-00020800-00002001-178BFBFF
      CPUID 80000000                                    80000018-68747541-444D4163-69746E65
      CPUID 80000001                                    00040FB2-000008D1-0000001F-EBD3FBFF
      CPUID 80000002                                    20444D41-6C687441-74286E6F-3620296D
      CPUID 80000003                                    32582034-61754420-6F43206C-50206572
      CPUID 80000004                                    65636F72-726F7373-30323420-00002B30
      CPUID 80000005                                    FF08FF08-FF20FF20-40020140-40020140
      CPUID 80000006                                    00000000-42004200-02008140-00000000
      CPUID 80000007                                    00000000-00000000-00000000-0000003F
      CPUID 80000008                                    00003028-00000000-00000001-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00000040-00000000-00000000
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000

    CPUID Registers (CPU #2):
      CPUID 00000000                                    00000001-68747541-444D4163-69746E65
      CPUID 00000001                                    00040FB2-01020800-00002001-178BFBFF
      CPUID 80000000                                    80000018-68747541-444D4163-69746E65
      CPUID 80000001                                    00040FB2-000008D1-0000001F-EBD3FBFF
      CPUID 80000002                                    20444D41-6C687441-74286E6F-3620296D
      CPUID 80000003                                    32582034-61754420-6F43206C-50206572
      CPUID 80000004                                    65636F72-726F7373-30323420-00002B30
      CPUID 80000005                                    FF08FF08-FF20FF20-40020140-40020140
      CPUID 80000006                                    00000000-42004200-02008140-00000000
      CPUID 80000007                                    00000000-00000000-00000000-0000003F
      CPUID 80000008                                    00003028-00000000-00000001-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00000040-00000000-00000000
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000

    MSR Registers:
      MSR 0000001B                                      0000-0000-FEE0-0900
      MSR C0010015                                      0000-0000-0200-0040
      MSR C0010042                                      310A-120C-0A0E-020E
      MSR C0010055                                      0000-0000-0000-0000


--------[   ]---------------------------------------------------------------------------------------------

      :
      ID                                  63-0701-000001-00101111-062707-MCP65$A0744000_BIOS DATE: 06/27/07 10:49:01 VER: 08.00.12
                                          Asus M2N-X

      FSB:
                                                 AMD Hammer
                                         200 
                                      200 
       HyperTransport                            1000 

      :
                                                 Dual DDR2 SDRAM
                                              128 
       DRAM:FSB                              CPU/6
                                         368  (DDR)
                                      737 
                                   11787 /

        :
                                         1 Socket AM2
                                       3 PCI, 2 PCI-E x1, 1 PCI-E x16
                                              2 DDR2 DIMM
                                    Audio, LAN
      -                                       ATX
                                   190 mm x 300 mm
                                    nForce520
                                   JumperFree, Stepless Freq Selection

      :
                                                   ASUSTeK Computer Inc.
                                     http://www.asus.com/products.aspx?l1=3
        BIOS                          http://support.asus.com/download/download.aspx?SLanguage=en-us
                                     http://driveragent.com?ref=59
       BIOS                                   http://www.esupport.com/biosagent/index.cfm?refererid=40


--------[  ]------------------------------------------------------------------------------------------------------

     :
                                                   2047 
                                                  521 
                                                1525 
                                                25 %

       :
                                                   4094 
                                                  716 
                                                3378 
                                                17 %

     :
                                                   6142 
                                                  1237 
                                                4904 
                                                20 %

     :
                                            C:\pagefile.sys
                                           2047 
      /                           113  / 113 
                                                6 %

    Physical Address Extension (PAE):
                                        
                                        
                                                


--------[ SPD ]---------------------------------------------------------------------------------------------------------

  [ DIMM1: A-Data DQVE1A16 ]

      :
                                               A-Data DQVE1A16
                                           
                                              29 / 2007
                                            1  (2 ranks, 4 banks)
                                               Unbuffered DIMM
                                               DDR2 SDRAM
                                          DDR2-800 (400 )
                                            64 bit
                                           SSTL 1.8
                                  
                                       (7.8 us), Self-Refresh

     :
      @ 400                                          5-5-5-18  (CL-RCD-RP-RAS) / 23-42-3-6-3-3  (RC-RFC-RRD-WR-WTR-RTP)
      @ 266                                          4-4-4-12  (CL-RCD-RP-RAS) / 16-28-2-4-2-2  (RC-RFC-RRD-WR-WTR-RTP)
      @ 200                                          3-3-3-9  (CL-RCD-RP-RAS) / 12-21-2-3-2-2  (RC-RFC-RRD-WR-WTR-RTP)

      :
      Analysis Probe                                    
      FET Switch External                               
      Weak Driver                                       

      :
                                                   A-DATA Technology Co., Ltd.
                                     http://www.adata.com.tw/adata_en/drammodule.php

  [ DIMM2: A-Data DQVE1A16 ]

      :
                                               A-Data DQVE1A16
                                           
                                              29 / 2007
                                            1  (2 ranks, 4 banks)
                                               Unbuffered DIMM
                                               DDR2 SDRAM
                                          DDR2-800 (400 )
                                            64 bit
                                           SSTL 1.8
                                  
                                       (7.8 us), Self-Refresh

     :
      @ 400                                          5-5-5-18  (CL-RCD-RP-RAS) / 23-42-3-6-3-3  (RC-RFC-RRD-WR-WTR-RTP)
      @ 266                                          4-4-4-12  (CL-RCD-RP-RAS) / 16-28-2-4-2-2  (RC-RFC-RRD-WR-WTR-RTP)
      @ 200                                          3-3-3-9  (CL-RCD-RP-RAS) / 12-21-2-3-2-2  (RC-RFC-RRD-WR-WTR-RTP)

      :
      Analysis Probe                                    
      FET Switch External                               
      Weak Driver                                       

      :
                                                   A-DATA Technology Co., Ltd.
                                     http://www.adata.com.tw/adata_en/drammodule.php


--------[  ]------------------------------------------------------------------------------------------------------

  [  : AMD Hammer DDR2 IMC ]

      :
                                            AMD Hammer DDR2 IMC
                                DDR2-400 SDRAM, DDR2-533 SDRAM, DDR2-667 SDRAM, DDR2-800 SDRAM
                                                  00

     :
                                                     Dual Channel  (128 )
                                           Dual Channel  (128 )

     :
      CAS Latency (CL)                                  5T
      RAS To CAS Delay (tRCD)                           5T
      RAS Precharge (tRP)                               5T
      RAS Active Time (tRAS)                            18T
      Row Cycle Time (tRC)                              24T
      Command Rate (CR)                                 2T
      RAS To RAS Delay (tRRD)                           3T
      Write Recovery Time (tWR)                         6T
      Write To Read Delay (tWTR)                        3T
      Read To Precharge Delay (tRTP)                    4T
      Four Activate Window Delay (tFAW)                 18T
      Refresh Period (tREF)                             7.8 us
      DRAM Drive Strength                               1.0x
      DRAM Data Drive Strength                          1.0x
      Clock Drive Strength                              1.5x
      CKE Drive Strength                                1.5x
      Max Async Latency                                 6 ns
      Idle Cycle Limit                                  16
      Dynamic Idle Cycle Counter                        
      Read/Write Queue Bypass                           8

     :
      ECC                                               , 
      ChipKill ECC                                      , 
      RAID                                               
      DRAM Scrub Rate                                   
      L1 Data Cache Scrub Rate                          
      L2 Cache Scrub Rate                               

     :
       DRAM #1                                    1   (DDR2-800 DDR2 SDRAM)
       DRAM #2                                    1   (DDR2-800 DDR2 SDRAM)

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us-en/Processors/DevelopWithAMD/0,,30_2252_873,00.html
                                       http://www.amd.com/us-en/Processors/TechnicalResources/0,,30_182_871_2336,00.html
       BIOS                                   http://www.esupport.com/biosagent/index.cfm?refererid=40
                                     http://driveragent.com?ref=59

  [  : nVIDIA nForce 520 (MCP65S) ]

      :
                                               nVIDIA nForce 520 (MCP65S)
                                                  A2
      nVIDIA SLI                                         
      nVIDIA Hybrid SLI                                  

    High Definition Audio:
                                               Realtek ALC883
      ID                                          10EC0883h / 10438286h
                                            00100002h
                                               Audio
                           44 kHz, 48 kHz, 96 kHz, 192 kHz, 16 , 20 , 24 

     PCI Express:
      PCI-E 1.0 x16 port #0                              @ x16  (nVIDIA GeForce 8600 GT Video Adapter)
      PCI-E 1.0 x1 port #1                              
      PCI-E 1.0 x1 port #2                              
      PCI-E 1.0 x2 port #3                              

     :
      CPU FSB                                           200.9 
      HyperTransport                                    1004.6 
      PCI Express                                       100.9 
      MAC PHY                                           125.0 
      SATA PHY                                          100.0 
       USB2                                   48.0 
      PIT / ACPI Timer                                  14.3 

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
       BIOS                                   http://www.esupport.com/biosagent/index.cfm?refererid=40
                                     http://driveragent.com?ref=59


--------[ BIOS ]--------------------------------------------------------------------------------------------------------

     BIOS:
       BIOS                                          AMI
       BIOS                                       0701
      AGESA Version                                     2.8.7.0
        BIOS                               06/27/07
       BIOS                            06/20/07

     BIOS:
                                                   American Megatrends Inc.
                                     http://www.ami.com/amibios
       BIOS                                   http://www.esupport.com/biosagent/index.cfm?refererid=40


--------[ ACPI ]--------------------------------------------------------------------------------------------------------

  [ APIC: Multiple APIC Description Table ]

      ACPI:
       ACPI                                      APIC
                                         Multiple APIC Description Table
                                             7FFC0390h
                                           112 
      OEM ID                                            062707
      OEM Table ID                                      APIC1049
      OEM Revision                                      20070627h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h
      Local APIC Address                                FEE00000h

  [ DSDT: Differentiated System Description Table ]

      ACPI:
       ACPI                                      DSDT
                                         Differentiated System Description Table
                                             7FFC0440h
                                           21615 
      OEM ID                                            A0744
      OEM Table ID                                      A0744000
      OEM Revision                                      00000000h
      Creator ID                                        INTL
      Creator Revision                                  20051117h

  [ FACP: Fixed ACPI Description Table ]

      ACPI:
       ACPI                                      FACP
                                         Fixed ACPI Description Table
                                             7FFC0200h
                                           132 
      OEM ID                                            062707
      OEM Table ID                                      FACP1049
      OEM Revision                                      20070627h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h
      SMI Command Port                                  0000082Eh
      PM Timer                                          00000508h

  [ FACS: Firmware ACPI Control Structure ]

      ACPI:
       ACPI                                      FACS
                                         Firmware ACPI Control Structure
                                             7FFCE000h
                                           64 

  [ HPET: IA-PC High Precision Event Timer Table ]

      ACPI:
       ACPI                                      HPET
                                         IA-PC High Precision Event Timer Table
                                             7FFC58B0h
                                           56 
      OEM ID                                            062707
      OEM Table ID                                      OEMHPET0
      OEM Revision                                      20070627h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h

  [ MCFG: Memory Mapped Configuration Space Base Address Description Table ]

      ACPI:
       ACPI                                      MCFG
                                         Memory Mapped Configuration Space Base Address Description Table
                                             7FFC0400h
                                           60 
      OEM ID                                            062707
      OEM Table ID                                      OEMMCFG
      OEM Revision                                      20070627h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h

  [ OEMB: OEM Specific Information Table ]

      ACPI:
       ACPI                                      OEMB
                                         OEM Specific Information Table
                                             7FFCE040h
                                           97 
      OEM ID                                            062707
      OEM Table ID                                      OEMB1049
      OEM Revision                                      20070627h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h

  [ RSD PTR: Root System Description Pointer ]

      ACPI:
       ACPI                                      RSD PTR
                                         Root System Description Pointer
                                             000FB850h
                                           36 
      OEM ID                                            ACPIAM

  [ RSDT: Root System Description Table ]

      ACPI:
       ACPI                                      RSDT
                                         Root System Description Table
                                             7FFC0000h
                                           60 
      OEM ID                                            HPQOEM
      OEM Table ID                                      SLIC-WKS
      OEM Revision                                      20070627h
      Creator ID                                        HPQ
      Creator Revision                                  00000097h

  [ SLIC: Software Licensing Description Table ]

      ACPI:
       ACPI                                      SLIC
                                         Software Licensing Description Table
                                             7FFC58E8h
                                           374 
      OEM ID                                            HPQOEM
      OEM Table ID                                      SLIC-WKS
      OEM Revision                                      00000001h
      Creator ID                                        HPQ
      Creator Revision                                  20090824h


--------[   ]----------------------------------------------------------------------------------------

      :
                                              Microsoft Windows 7 Ultimate
                                                   ()
                                               Multiprocessor Free (32-bit)
                                                6.1.7601
                                       Service Pack 1
                                       13.02.2012
                                         C:\Windows

     :
                          user
                           
      ID                                        00426-OEM-8992662-00010
                                            MHFPT-8C8M2-V9488-FGM44-2C9T3
        (WPA)                           

     :
                                           USER-PC
                                         user
                                              user-PC
                                             547  (0 ., 0 , 9 , 7 )

     :
      Common Controls                                   6.16
      Internet Explorer                                 8.0.7601.17514
      Windows Mail                                      6.1.7600.16385 (win7_rtm.090713-1255)
      Windows Media Player                              12.0.7600.16385 (win7_rtm.090713-1255)
      Windows Messenger                                 -
      MSN Messenger                                     -
      Internet Information Services (IIS)               -
      .NET Framework                                    3.5.30729.4926 built by: NetFXw7
      Novell Client                                     -
      DirectX                                           DirectX 10.1
      OpenGL                                            6.1.7600.16385 (win7_rtm.090713-1255)
      ASPI                                              -

      :
                                        
       DBCS                                       
                                        
                                     
                                             
                                         
                                         
                                      
                                      


--------[  ]----------------------------------------------------------------------------------------------------

    Dwm.exe                  C:\Windows\system32\Dwm.exe                                                   32         17600          25588 
    everest.exe              C:\Program Files\Everest\everest.exe                                          32         35252          29176 
    Explorer.EXE             C:\Windows\Explorer.EXE                                                       32         41964          32160 
    taskhost.exe             C:\Windows\system32\taskhost.exe                                              32          4644           2144 


--------[   ]------------------------------------------------------------------------------------------

    1394ohci         1394 OHCI Compliant Host Controller                                     1394ohci.sys          6.1.7601.17514                        
    ACPI              Microsoft ACPI                                                  ACPI.sys              6.1.7601.17514                        
    AcpiPmi          ACPI Power Meter Driver                                                 acpipmi.sys           6.1.7601.17514                        
    adp94xx          adp94xx                                                                 adp94xx.sys           1.6.6.4                               
    adpahci          adpahci                                                                 adpahci.sys           1.6.6.1                               
    adpu320          adpu320                                                                 adpu320.sys           7.2.0.0                               
    AFD              Ancillary Function Driver for Winsock                                   afd.sys               6.1.7601.17514                        
    agp440           Intel AGP Bus Filter                                                    agp440.sys            6.1.7600.16385                        
    aic78xx          aic78xx                                                                 djsvs.sys             6.0.0.0                               
    aliide           aliide                                                                  aliide.sys            1.2.0.0                               
    amdagp           AMD AGP Bus Filter Driver                                               amdagp.sys            6.1.7600.16385                        
    amdide           amdide                                                                  amdide.sys            6.1.7600.16385                        
    AmdK8            AMD K8                                                 amdk8.sys             6.1.7600.16385                        
    AmdPPM           AMD Processor Driver                                                    amdppm.sys            6.1.7600.16385                        
    amdsata          amdsata                                                                 amdsata.sys           1.1.2.5                               
    amdsbs           amdsbs                                                                  amdsbs.sys            3.6.1540.127                          
    amdxata          amdxata                                                                 amdxata.sys           1.1.2.5                               
    AppID             AppID                                                           appid.sys             6.1.7601.17514                        
    arc              arc                                                                     arc.sys               5.2.0.10384                           
    arcsas           arcsas                                                                  arcsas.sys            5.2.0.16119                           
    AsyncMac            RAS                                       asyncmac.sys          6.1.7600.16385                        
    atapi             IDE                                                               atapi.sys             6.1.7600.16385                        
    b06bdrv          Broadcom NetXtreme II VBD                                               bxvbdx.sys            4.8.2.0                               
    b57nd60x         Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0                          b57nd60x.sys          10.100.4.0                            
    Beep             Beep                                                                                                                                
    blbdrive         blbdrive                                                                blbdrive.sys          6.1.7600.16385                        
    bowser                                                           bowser.sys            6.1.7600.16385             
    BrFiltLo         Brother USB Mass-Storage Lower Filter Driver                            BrFiltLo.sys          1.10.0.2                              
    BrFiltUp         Brother USB Mass-Storage Upper Filter Driver                            BrFiltUp.sys          1.4.0.1                               
    Brserid          Brother MFC Serial Port Interface Driver (WDM)                          Brserid.sys           1.0.1.6                               
    BrSerWdm         Brother WDM Serial driver                                               BrSerWdm.sys          1.0.0.20                              
    BrUsbMdm         Brother MFC USB Fax Only Modem                                          BrUsbMdm.sys          1.0.0.12                              
    BrUsbSer         Brother MFC USB Serial WDM Driver                                       BrUsbSer.sys          1.0.1.3                               
    BTHMODEM         Bluetooth Serial Communications Driver                                  bthmodem.sys          6.1.7600.16385                        
    cdfs             CD/DVD File System Reader                                               cdfs.sys              6.1.7600.16385             
    cdrom             CD-ROM                                                 cdrom.sys             6.1.7601.17514                        
    circlass         Consumer IR Devices                                                     circlass.sys          6.1.7600.16385                        
    CLFS               (CLFS)                                                     CLFS.sys              6.1.7600.16385                        
    CmBatt           Microsoft ACPI Control Method Battery Driver                            CmBatt.sys            6.1.7600.16385                        
    cmdide           cmdide                                                                  cmdide.sys            2.0.7.0                               
    CNG              CNG                                                                     cng.sys               6.1.7600.16385                        
    Compbatt         Compbatt                                                                compbatt.sys          6.1.7600.16385                        
    CompositeBus                                          CompositeBus.sys      6.1.7601.17514                        
    crcdisk          Crcdisk Filter Driver                                                   crcdisk.sys           6.1.7600.16385                        
    CSC                                                               csc.sys               6.1.7601.17514                        
    DfsC             DFS Namespace Client Driver                                             dfsc.sys              6.1.7601.17514             
    discache         System Attribute Cache                                                  discache.sys          6.1.7600.16385                        
    Disk                                                                         disk.sys              6.1.7600.16385                        
    dmvsc            dmvsc                                                                   dmvsc.sys             6.1.7601.17514                        
    drmkaud                                                 drmkaud.sys           6.1.7600.16385                        
    DXGKrnl          LDDM Graphics Subsystem                                                 dxgkrnl.sys           6.1.7601.17514                        
    ebdrv            Broadcom NetXtreme II 10 GigE VBD                                       evbdx.sys             4.8.13.0                              
    elxstor          elxstor                                                                 elxstor.sys           5.2.10.211                            
    ErrDev           Microsoft Hardware Error Device Driver                                  errdev.sys            6.1.7600.16385                        
    EverestDriver    Lavalys EVEREST Kernel Driver                                           kerneld.wnt                                                 
    exfat            exFAT File System Driver                                                                                                 
    fastfat          FAT12/16/32 File System Driver                                                                                           
    fdc                                                        fdc.sys               6.1.7600.16385                        
    FileInfo         File Information FS MiniFilter                                          fileinfo.sys          6.1.7600.16385             
    Filetrace        Filetrace                                                               filetrace.sys         6.1.7600.16385             
    flpydisk                                                     flpydisk.sys          6.1.7600.16385                        
    FltMgr                                                                  fltmgr.sys            6.1.7600.16385             
    FsDepends        File System Dependency Minifilter                                       FsDepends.sys         6.1.7600.16385             
    fvevol               Bitlocker                              fvevol.sys            6.1.7601.17514                        
    gagp30kx         Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms             gagp30kx.sys          6.1.7600.16385                        
    hcw85cir         Hauppauge Consumer Infrared Receiver                                    hcw85cir.sys          1.31.27127.0                          
    HdAudAddService    UAA   High Definition Audio (Microsoft),  1.1  HdAudio.sys           6.1.7601.17514                        
    HDAudBus            UAA  High Definition Audio (Microsoft)              HDAudBus.sys          6.1.7601.17514                        
    HidBatt          HID UPS Battery Driver                                                  HidBatt.sys           6.1.7600.16385                        
    HidBth           Microsoft Bluetooth HID Miniport                                        hidbth.sys            6.1.7600.16385                        
    HidIr            Microsoft Infrared HID Driver                                           hidir.sys             6.1.7600.16385                        
    HidUsb           Microsoft HID Class Driver                                              hidusb.sys            6.1.7601.17514                        
    HpSAMD           HpSAMD                                                                  HpSAMD.sys            6.12.4.32                             
    HTTP             HTTP                                                                    HTTP.sys              6.1.7601.17514                        
    hwpolicy         Hardware Policy Driver                                                  hwpolicy.sys          6.1.7601.17514                        
    i8042prt          i8042-     PS/2                          i8042prt.sys          6.1.7600.16385                        
    iaStorV          iaStorV                                                                 iaStorV.sys           8.6.2.1014                            
    iirsp            iirsp                                                                   iirsp.sys             5.4.22.0                              
    intelide         intelide                                                                intelide.sys          6.1.7600.16385                        
    intelppm         Intel Processor Driver                                                  intelppm.sys          6.1.7600.16385                        
    IpFilterDriver     IP-                                              ipfltdrv.sys          6.1.7600.16385                        
    IPMIDRV          IPMIDRV                                                                 IPMIDrv.sys           6.1.7601.17514                        
    IPNAT            IP Network Address Translator                                           ipnat.sys             6.1.7600.16385                        
    IRENUM           IR Bus Enumerator                                                       irenum.sys            6.1.7600.16385                        
    isapnp           isapnp                                                                  isapnp.sys            6.1.7600.16385                        
    iScsiPrt         iScsiPort Driver                                                        msiscsi.sys           6.1.7601.17514                        
    kbdclass                                                          kbdclass.sys          6.1.7600.16385                        
    kbdhid           Keyboard HID Driver                                                     kbdhid.sys            6.1.7601.17514                        
    KSecDD           KSecDD                                                                  ksecdd.sys            6.1.7601.17514                        
    KSecPkg          KSecPkg                                                                 ksecpkg.sys           6.1.7600.16385                        
    lltdio           Link-Layer Topology Discovery Mapper I/O Driver                         lltdio.sys            6.1.7600.16385                        
    LSI_FC           LSI_FC                                                                  lsi_fc.sys            1.28.3.52                             
    LSI_SAS          LSI_SAS                                                                 lsi_sas.sys           1.28.3.52                             
    LSI_SAS2         LSI_SAS2                                                                lsi_sas2.sys          2.0.2.71                              
    LSI_SCSI         LSI_SCSI                                                                lsi_scsi.sys          1.28.3.67                             
    luafv                                            luafv.sys             6.1.7600.16385             
    megasas          megasas                                                                 megasas.sys           4.5.1.32                              
    MegaSR           MegaSR                                                                  MegaSR.sys            13.5.409.2009                         
    Modem            Modem                                                                   modem.sys             6.1.7600.16385                        
    monitor          Microsoft Monitor Class Function Driver Service                         monitor.sys           6.1.7600.16385                        
    mouclass                                                                mouclass.sys          6.1.7600.16385                        
    mouhid           Mouse HID Driver                                                        mouhid.sys            6.1.7600.16385                        
    mountmgr                                                        mountmgr.sys          6.1.7601.17514                        
    mpio             mpio                                                                    mpio.sys              6.1.7601.17514                        
    mpsdrv              Windows                                 mpsdrv.sys            6.1.7600.16385                        
    MRxDAV              WebDav                                 mrxdav.sys            6.1.7601.17514             
    mrxsmb              - SMB                              mrxsmb.sys            6.1.7601.17514             
    mrxsmb10         - SMB 1.x                                            mrxsmb10.sys          6.1.7601.17514             
    mrxsmb20         - SMB 2.0                                            mrxsmb20.sys          6.1.7601.17514             
    msahci           msahci                                                                  msahci.sys            6.1.7601.17514                        
    msdsm            msdsm                                                                   msdsm.sys             6.1.7601.17514                        
    Msfs             Msfs                                                                                                                     
    mshidkmdf        Pass-through HID to KMDF Filter Driver                                  mshidkmdf.sys         6.1.7600.16385                        
    msisadrv         msisadrv                                                                msisadrv.sys          6.1.7600.16385                        
    MSKSSRV             Microsoft                                   MSKSSRV.sys           6.1.7600.16385                        
    MSPCLOCK            Microsoft                               MSPCLOCK.sys          6.1.7600.16385                        
    MSPQM                Microsoft                     MSPQM.sys             6.1.7600.16385                        
    MsRPC            MsRPC                                                                                                                               
    mssmbios         Microsoft System Management BIOS                                 mssmbios.sys          6.1.7600.16385                        
    MSTEE              Tee/Sink-to-Sink Microsoft                      MSTEE.sys             6.1.7600.16385                        
    MTConfig         Microsoft Input Configuration Driver                                    MTConfig.sys          6.1.7600.16385                        
    Mup              Mup                                                                     mup.sys               6.1.7600.16385             
    NativeWifiP      NativeWiFi Filter                                                       nwifi.sys             6.1.7600.16385                        
    NDIS               NDIS                                                  ndis.sys              6.1.7601.17514                        
    NdisCap          NDIS Capture LightWeight Filter                                         ndiscap.sys           6.1.7600.16385                        
    NdisTapi         NDIS- TAPI                                      ndistapi.sys          6.1.7600.16385                        
    Ndisuio          NDIS Usermode I/O Protocol                                              ndisuio.sys           6.1.7601.17514                        
    NdisWan          NDIS- WAN                                       ndiswan.sys           6.1.7601.17514                        
    NDProxy          NDIS Proxy                                                                                                                          
    NetBIOS          NetBIOS Interface                                                       netbios.sys           6.1.7600.16385             
    NetBT            NetBT                                                                   netbt.sys             6.1.7601.17514                        
    nfrd960          nfrd960                                                                 nfrd960.sys           7.10.0.0                              
    Npfs             Npfs                                                                                                                     
    nsiproxy         NSI proxy service driver.                                               nsiproxy.sys          6.1.7600.16385                        
    Ntfs             Ntfs                                                                                                                     
    Null             Null                                                                                                                                
    nv_agp           NVIDIA nForce AGP Bus Filter                                            nv_agp.sys            6.1.7600.16385                        
    NVENETFD            NVIDIA nForce                              nvm62x32.sys          1.0.1.210                             
    nvlddmkm         nvlddmkm                                                                nvlddmkm.sys          8.15.11.8593                          
    nvraid           nvraid                                                                  nvraid.sys            10.6.0.18                             
    nvstor           nvstor                                                                  nvstor.sys            10.6.0.18                             
    ohci1394         1394 OHCI Compliant Host Controller (Legacy)                            ohci1394.sys          6.1.7600.16385                        
    Parport                                                         parport.sys           6.1.7600.16385                        
    partmgr                                                                 partmgr.sys           6.1.7601.17514                        
    Parvdm           Parvdm                                                                  parvdm.sys            6.1.7600.16385                        
    pci               PCI                                                         pci.sys               6.1.7601.17514                        
    pciide           pciide                                                                  pciide.sys            6.1.7600.16385                        
    pcmcia           pcmcia                                                                  pcmcia.sys            6.1.7600.16385                        
    pcw              Performance Counters for Windows Driver                                 pcw.sys               6.1.7600.16385                        
    PEAUTH           PEAUTH                                                                  peauth.sys            6.1.7600.16385                        
    PptpMiniport     - WAN (PPTP)                                                    raspptp.sys           6.1.7600.16385                        
    Processor        Processor Driver                                                        processr.sys          6.1.7600.16385                        
    Psched             QoS                                                 pacer.sys             6.1.7600.16385                        
    ql2300           ql2300                                                                  ql2300.sys            9.1.8.6                               
    ql40xx           ql40xx                                                                  ql40xx.sys            2.1.3.20                              
    QWAVEdrv          QWAVE                                                           qwavedrv.sys          6.1.7600.16385                        
    RasAcd           Remote Access Auto Connection Driver                                    rasacd.sys            6.1.7600.16385                        
    RasAgileVpn      WAN Miniport (IKEv2)                                                    AgileVpn.sys          6.1.7600.16385                        
    Rasl2tp          - WAN (L2TP)                                                    rasl2tp.sys           6.1.7600.16385                        
    RasPppoe          PPPOE                                          raspppoe.sys          6.1.7600.16385                        
    RasSstp          - WAN (SSTP)                                                    rassstp.sys           6.1.7600.16385                        
    rdbss                                               rdbss.sys             6.1.7601.17514             
    rdpbus           Remote Desktop Device Redirector Bus Driver                             rdpbus.sys            6.1.7600.16385                        
    RDPCDD           RDPCDD                                                                  RDPCDD.sys            6.1.7601.17514                        
    RDPDR            Terminal Server Device Redirector Driver                                rdpdr.sys             6.1.7601.17514                        
    RDPENCDD         RDP Encoder Mirror Driver                                               rdpencdd.sys          6.1.7600.16385                        
    RDPREFMP         Reflector Display Driver used to gain access to graphics data           rdprefmp.sys          6.1.7600.16385                        
    RdpVideoMiniport  Remote Desktop Video Miniport Driver                                    rdpvideominiport.sys  6.1.7601.17514                        
    RDPWD            RDP Winstation Driver                                                                                                               
    rdyboost         ReadyBoost                                                              rdyboost.sys          6.1.7601.17514                        
    rspndr           Link-Layer Topology Discovery Responder                                 rspndr.sys            6.1.7600.16385                        
    RTL8167           Realtek 8167 NT                                                 Rt86win7.sys          7.2.1125.2008                         
    s3cap            s3cap                                                                   vms3cap.sys           6.1.7601.17514                        
    sbp2port         sbp2port                                                                sbp2port.sys          6.1.7601.17514                        
    scfilter           -  PnP                                  scfilter.sys          6.1.7601.17514                        
    secdrv           Security Driver                                                                                                                     
    Serenum            Serenum                                                 serenum.sys           6.1.7600.16385                        
    Serial                                                      serial.sys            6.1.7600.16385                        
    sermouse         Serial Mouse Driver                                                     sermouse.sys          6.1.7600.16385                        
    sffdisk          SFF Storage Class Driver                                                sffdisk.sys           6.1.7600.16385                        
    sffp_mmc         SFF Storage Protocol Driver for MMC                                     sffp_mmc.sys          6.1.7600.16385                        
    sffp_sd          SFF Storage Protocol Driver for SDBus                                   sffp_sd.sys           6.1.7601.17514                        
    sfloppy          High-Capacity Floppy Disk Drive                                         sfloppy.sys           6.1.7600.16385                        
    sisagp           SIS AGP Bus Filter                                                      sisagp.sys            6.1.7600.16385                        
    SiSRaid2         SiSRaid2                                                                SiSRaid2.sys          5.1.1039.2600                         
    SiSRaid4         SiSRaid4                                                                sisraid4.sys          5.1.1039.3600                         
    Smb                TCP/IP  TCP/IPv6 ( SMB)                        smb.sys               6.1.7600.16385                        
    spldr            Security Processor Loader Driver                                                                                                    
    srv                Server SMB 1.xxx                                        srv.sys               6.1.7601.17514             
    srv2               Server SMB 2.xxx                                        srv2.sys              6.1.7601.17514             
    srvnet           srvnet                                                                  srvnet.sys            6.1.7601.17514             
    stexstor         stexstor                                                                stexstor.sys          5.0.1.1                               
    storflt                                   vmstorfl.sys          6.1.7601.17514                        
    storvsc          storvsc                                                                 storvsc.sys           6.1.7601.17514                        
    swenum                                                             swenum.sys            6.1.7600.16385                        
    Synth3dVsc       Synth3dVsc                                                              synth3dvsc.sys        6.1.7601.17514                        
    Tcpip              TCP/IP                                                tcpip.sys             6.1.7601.17514                        
    TCPIP6           Microsoft IPv6 Protocol Driver                                          tcpip.sys             6.1.7601.17514                        
    tcpipreg         TCP/IP Registry Compatibility                                           tcpipreg.sys          6.1.7601.17514                        
    TDPIPE           TDPIPE                                                                  tdpipe.sys            6.1.7601.17514                        
    TDTCP            TDTCP                                                                   tdtcp.sys             6.1.7601.17514                        
    tdx                NetIO Legacy TDI                                      tdx.sys               6.1.7601.17514                        
    TermDD                                                         termdd.sys            6.1.7601.17514                        
    terminpt         Microsoft Remote Desktop Input Driver                                   terminpt.sys          6.1.7601.17514                        
    tssecsrv         Remote Desktop Services Security Filter Driver                          tssecsrv.sys          6.1.7601.17514                        
    TsUsbFlt         TsUsbFlt                                                                tsusbflt.sys          6.1.7601.17514                        
    TsUsbGD          Remote Desktop Generic USB Device                                       TsUsbGD.sys           6.1.7601.17514                        
    tsusbhub         tsusbhub                                                                tsusbhub.sys          6.1.7601.17514                        
    tunnel                Microsoft                        tunnel.sys            6.1.7601.17514                        
    uagp35           Microsoft AGPv3.5 Filter                                                uagp35.sys            6.1.7600.16385                        
    udfs             udfs                                                                    udfs.sys              6.1.7601.17514             
    uliagpkx         Uli AGP Bus Filter                                                      uliagpkx.sys          6.1.7600.16385                        
    umbus            UMBus                                               umbus.sys             6.1.7601.17514                        
    UmPass           Microsoft UMPass Driver                                                 umpass.sys            6.1.7600.16385                        
    usbccgp          Microsoft USB Generic Parent Driver                                     usbccgp.sys           6.1.7601.17514                        
    usbcir           eHome Infrared Receiver (USBCIR)                                        usbcir.sys            6.1.7600.16385                        
    usbehci            Microsoft USB 2.0  -       usbehci.sys           6.1.7601.17514                        
    usbhub             USB- ()                      usbhub.sys            6.1.7601.17514                        
    usbohci            Microsoft USB  -              usbohci.sys           6.1.7600.16385                        
    usbprint         Microsoft USB PRINTER Class                                             usbprint.sys          6.1.7600.16385                        
    USBSTOR              USB                                  USBSTOR.SYS           6.1.7601.17514                        
    usbuhci          Microsoft USB Universal Host Controller Miniport Driver                 usbuhci.sys           6.1.7600.16385                        
    vdrvroot             ()                   vdrvroot.sys          6.1.7600.16385                        
    vga              vga                                                                     vgapnp.sys            6.1.7600.16385                        
    VgaSave          VgaSave                                                                 vga.sys               6.1.7600.16385                        
    VGPU             VGPU                                                                    rdvgkmd.sys                                                 
    vhdmp            vhdmp                                                                   vhdmp.sys             6.1.7601.17514                        
    viaagp           VIA AGP Bus Filter                                                      viaagp.sys            6.1.7600.16385                        
    ViaC7            VIA C7 Processor Driver                                                 viac7.sys             6.1.7600.16385                        
    viaide           viaide                                                                  viaide.sys            6.0.6000.170                          
    vmbus            vmbus                                                                   vmbus.sys             6.1.7601.17514                        
    VMBusHID         VMBusHID                                                                VMBusHID.sys          6.1.7601.17514                        
    volmgr                                                             volmgr.sys            6.1.7601.17514                        
    volmgrx                                                        volmgrx.sys           6.1.7600.16385                        
    volsnap                                                         volsnap.sys           6.1.7601.17514                        
    vsmraid          vsmraid                                                                 vsmraid.sys           6.0.6000.6210                         
    vwifibus           Virtual WiFi                                               vwifibus.sys          6.1.7600.16385                        
    WacomPen         Wacom Serial Pen HID Driver                                             wacompen.sys          6.1.7600.16385                        
    WANARP              IP ARP                                       wanarp.sys            6.1.7601.17514                        
    Wanarpv6            IPv6 ARP                                     wanarp.sys            6.1.7601.17514                        
    Wd               Wd                                                                      wd.sys                6.1.7600.16385                        
    Wdf01000         Kernel Mode Driver Frameworks service                                   Wdf01000.sys          1.9.7600.16385                        
    WfpLwf           WFP Lightweight Filter                                                  wfplwf.sys            6.1.7600.16385                        
    WIMMount         WIMMount                                                                wimmount.sys          6.1.7600.16385             
    WmiAcpi          Microsoft Windows Management Interface for ACPI                         wmiacpi.sys           6.1.7600.16385                        
    ws2ifsl           WinSock IFS                                                     ws2ifsl.sys           6.1.7600.16385                        
    WudfPf           User Mode Driver Frameworks Platform Driver                             WudfPf.sys            6.1.7601.17514                        
    WUDFRd           WUDFRd                                                                  WUDFRd.sys            6.1.7601.17514                        


--------[  ]------------------------------------------------------------------------------------------------------

    AeLookupSvc                                                              svchost.exe           6.1.7600.16385                       localSystem
    ALG                                                                             alg.exe               6.1.7600.16385                 NT AUTHORITY\LocalService
    AppIDSvc                                                                            svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    Appinfo                                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    AppMgmt                                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    AudioEndpointBuilder                   Windows Audio                        svchost.exe           6.1.7600.16385                       LocalSystem
    Audiosrv                           Windows Audio                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    AxInstSV                            ActiveX (AxInstSV)                                           svchost.exe           6.1.7600.16385                       LocalSystem
    BDESVC                                BitLocker                                      svchost.exe           6.1.7600.16385                       localSystem
    BFE                                                                                 svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    BITS                                   (BITS)                         svchost.exe           6.1.7600.16385                       LocalSystem
    Browser                                                                                  svchost.exe           6.1.7600.16385                       LocalSystem
    bthserv                              Bluetooth                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    CertPropSvc                                                                      svchost.exe           6.1.7600.16385                       LocalSystem
    clr_optimization_v2.0.50727_32     Microsoft .NET Framework NGEN v2.0.50727_X86                            mscorsvw.exe          2.0.50727.4927                 LocalSystem
    COMSysApp                            COM+                                               dllhost.exe           6.1.7600.16385                 LocalSystem
    CryptSvc                                                                                 svchost.exe           6.1.7600.16385                       NT Authority\NetworkService
    CscService                                                                                  svchost.exe           6.1.7600.16385                       LocalSystem
    DcomLaunch                            DCOM-                                   svchost.exe           6.1.7600.16385                       LocalSystem
    defragsvc                                                                               svchost.exe           6.1.7600.16385                 localSystem
    Dhcp                               DHCP-                                                             svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    Dnscache                           DNS-                                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    dot3svc                                                                              svchost.exe           6.1.7600.16385                       localSystem
    DPS                                                                               svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    EapHost                                (EAP)                         svchost.exe           6.1.7600.16385                       localSystem
    EFS                                   (EFS)                                      lsass.exe             6.1.7600.16385                       LocalSystem
    ehRecvr                              Windows Media Center                                    ehRecvr.exe           6.1.7601.17514                 NT AUTHORITY\networkService
    ehSched                              Windows Media Center                                ehsched.exe           6.1.7600.16385                 NT AUTHORITY\networkService
    eventlog                             Windows                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    EventSystem                          COM+                                                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Fax                                                                                                    fxssvc.exe            6.1.7601.17514                 NT AUTHORITY\NetworkService
    fdPHost                                                                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    FDResPub                                                               svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    FontCache                             Windows                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    FontCache3.0.0.0                     Windows Presentation Foundation 3.0.0.0                     PresentationFontCache.exe  3.0.6920.4902                  NT Authority\LocalService
    gpsvc                                                                               svchost.exe           6.1.7600.16385                       LocalSystem
    hidserv                              HID-                                                svchost.exe           6.1.7600.16385                       LocalSystem
    hkmsvc                                                      svchost.exe           6.1.7600.16385                       localSystem
    HomeGroupListener                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    HomeGroupProvider                                                                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    idsvc                              Windows CardSpace                                                       infocard.exe          3.0.4506.5420                        LocalSystem
    IKEEXT                               IPsec        IP     svchost.exe           6.1.7600.16385                       LocalSystem
    IPBusEnum                           IP- PnP-X                                              svchost.exe           6.1.7600.16385                       LocalSystem
    iphlpsvc                             IP                                               svchost.exe           6.1.7600.16385                       LocalSystem
    KeyIso                               CNG                                                     lsass.exe             6.1.7600.16385                       LocalSystem
    KtmRm                              KtmRm                            svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    LanmanServer                                                                                         svchost.exe           6.1.7600.16385                       LocalSystem
    LanmanWorkstation                                                                            svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    lltdsvc                                                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    lmhosts                              NetBIOS  TCP/IP                                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Mcx2Svc                              Media Center                                      svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    MMCSS                                                                         svchost.exe           6.1.7600.16385                       LocalSystem
    MpsSvc                              Windows                                                      svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    MSDTC                                                                   msdtc.exe             2001.12.8530.16385                NT AUTHORITY\NetworkService
    MSiSCSI                               iSCSI                                      svchost.exe           6.1.7600.16385                       LocalSystem
    msiserver                           Windows                                                      msiexec.exe           5.0.7601.17514                 LocalSystem
    napagent                                                                         svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    Netlogon                                                                                lsass.exe             6.1.7600.16385                       LocalSystem
    Netman                                                                                   svchost.exe           6.1.7600.16385                       LocalSystem
    netprofm                                                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    NetTcpPortSharing                       Net.Tcp                                  SMSvcHost.exe         3.0.4506.5420                        NT AUTHORITY\LocalService
    NlaSvc                                                                     svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    nsi                                                                          svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    p2pimsvc                                                            svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    p2psvc                                                                         svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PcaSvc                                                               svchost.exe           6.1.7600.16385                       LocalSystem
    PeerDistSvc                        BranchCache                                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    pla                                                                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PlugPlay                           Plug-and-Play                                                           svchost.exe           6.1.7600.16385                       LocalSystem
    PNRPAutoReg                            PNRP                                 svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PNRPsvc                             PNRP                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PolicyAgent                          IPsec                                                    svchost.exe           6.1.7600.16385                       NT Authority\NetworkService
    Power                                                                                               svchost.exe           6.1.7600.16385                       LocalSystem
    ProfSvc                                                                         svchost.exe           6.1.7600.16385                       LocalSystem
    ProtectedStorage                                                                        lsass.exe             6.1.7600.16385                       LocalSystem
    QWAVE                              Quality Windows Audio Video Experience                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    RasAuto                                                 svchost.exe           6.1.7600.16385                       localSystem
    RasMan                                                                svchost.exe           6.1.7600.16385                       localSystem
    RemoteAccess                                                                  svchost.exe           6.1.7600.16385                       localSystem
    RemoteRegistry                                                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    RpcEptMapper                          RPC                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    RpcLocator                             (RPC)                                locator.exe           6.1.7600.16385                 NT AUTHORITY\NetworkService
    RpcSs                                 (RPC)                                          svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    SamSs                                                                   lsass.exe             6.1.7600.16385                       LocalSystem
    SCardSvr                           -                                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Schedule                                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    SCPolicySvc                          -                                            svchost.exe           6.1.7600.16385                       LocalSystem
    SDRSVC                              Windows                                                       svchost.exe           6.1.7600.16385                 localSystem
    seclogon                                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    SENS                                                                    svchost.exe           6.1.7600.16385                       LocalSystem
    SensrSvc                                                                       svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    SessionEnv                                                           svchost.exe           6.1.7600.16385                       localSystem
    SharedAccess                             (ICS)                            svchost.exe           6.1.7600.16385                       LocalSystem
    ShellHWDetection                                                            svchost.exe           6.1.7600.16385                       LocalSystem
    SNMPTRAP                            SNMP                                                            snmptrap.exe          6.1.7600.16385                 NT AUTHORITY\LocalService
    Spooler                                                                                     spoolsv.exe           6.1.7601.17514                 LocalSystem
    sppsvc                                                                        sppsvc.exe            6.1.7601.17514                 NT AUTHORITY\NetworkService
    sppuinotify                          SPP                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    SSDPSRV                             SSDP                                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    SstpSvc                             SSTP                                                             svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    StiSvc                                Windows (WIA)                               svchost.exe           6.1.7600.16385                 NT Authority\LocalService
    swprv                                  (Microsoft)                  svchost.exe           6.1.7600.16385                 LocalSystem
    SysMain                            Superfetch                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    TabletInputService                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    TapiSrv                                                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    TBS                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    TermService                                                                    svchost.exe           6.1.7600.16385                       NT Authority\NetworkService
    Themes                                                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    THREADORDER                                                                       svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    TrkWks                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    TrustedInstaller                     Windows                                              TrustedInstaller.exe  6.1.7601.17514                 localSystem
    UI0Detect                                                                     UI0Detect.exe         6.1.7600.16385                 LocalSystem
    UmRdpService                                svchost.exe           6.1.7600.16385                       localSystem
    upnphost                             PNP-                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    UxSms                                                           svchost.exe           6.1.7600.16385                       localSystem
    VaultSvc                                                                             lsass.exe             6.1.7600.16385                       LocalSystem
    vds                                                                                         vds.exe               6.1.7601.17514                 LocalSystem
    VSS                                                                                  vssvc.exe             6.1.7601.17514                 LocalSystem
    W32Time                              Windows                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    wbengine                                                                wbengine.exe          6.1.7601.17514                 localSystem
    WbioSrvc                             Windows                                           svchost.exe           6.1.7600.16385                       LocalSystem
    wcncsvc                              Windows -                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WcsPlugInService                     Windows (WCS)                                          svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WdiServiceHost                                                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WdiSystemHost                                                                        svchost.exe           6.1.7600.16385                       LocalSystem
    WebClient                          -                                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Wecsvc                               Windows                                                 svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    wercplsupport                          "     "  svchost.exe           6.1.7600.16385                       localSystem
    WerSvc                                Windows                                       svchost.exe           6.1.7600.16385                       localSystem
    WinDefend                           Windows                                                        svchost.exe           6.1.7600.16385                       LocalSystem
    WinHttpAutoProxySvc                   - WinHTTP                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Winmgmt                              Windows                                       svchost.exe           6.1.7600.16385                       localSystem
    WinRM                                 Windows (WS-Management)                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    Wlansvc                              WLAN                                               svchost.exe           6.1.7600.16385                       LocalSystem
    wmiApSrv                           WMI Performance Adapter                                                 WmiApSrv.exe          6.1.7600.16385                 localSystem
    WMPNetworkSvc                           Windows Media               wmpnetwk.exe          12.0.7601.17514                NT AUTHORITY\NetworkService
    WPCSvc                             Parental Controls                                                       svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    WPDBusEnum                                                           svchost.exe           6.1.7600.16385                       LocalSystem
    wscsvc                                                                         svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WSearch                            Windows Search                                                          SearchIndexer.exe     7.0.7600.16385                 LocalSystem
    wuauserv                             Windows                                                svchost.exe           6.1.7600.16385                       LocalSystem
    wudfsvc                            Windows Driver Foundation - User-mode Driver Framework                  svchost.exe           6.1.7600.16385                       LocalSystem
    WwanSvc                             WWAN                                                      svchost.exe           6.1.7600.16385                       NT Authority\LocalService


--------[  AX ]----------------------------------------------------------------------------------------------------

    bdaplgin.ax                6.1.7600.16385              Microsoft BDA Device Control Plug-in for MPEG2 based networks.
    g711codc.ax                6.1.7601.17514              Intel G711 CODEC
    iac25_32.ax                2.0.5.53                      Indeo audio
    ir41_32.ax                 4.51.16.3                   Intel Indeo Video 4.5
    ivfsrc.ax                  5.10.2.51                    Intel Indeo video IVF  5.10
    ksproxy.ax                 6.1.7601.17514              WDM Streaming ActiveMovie Proxy
    kstvtune.ax                6.1.7601.17514               - WDM
    kswdmcap.ax                6.1.7601.17514                WDM
    ksxbar.ax                  6.1.7601.17514              WDM Streaming Crossbar
    mpeg2data.ax               6.6.7601.17514              Microsoft MPEG-2 Section and Table Acquisition Module
    mpg2splt.ax                6.6.7601.17514              DirectShow MPEG-2 Splitter.
    msdvbnp.ax                 6.6.7601.17514              Microsoft Network Provider for MPEG2 based networks.
    msnp.ax                    6.6.7601.17514              Microsoft Network Provider for MPEG2 based networks.
    psisrndr.ax                6.6.7601.17514              Microsoft Transport Information Filter for MPEG2 based networks.
    vbicodec.ax                6.6.7601.17514              Microsoft VBI Codec
    vbisurf.ax                 6.1.7601.17514              VBI Surface Allocator Filter
    vidcap.ax                  6.1.7600.16385              Video Capture Interface Server
    wstpager.ax                6.6.7601.17514              Microsoft Teletext Server


--------[  DLL ]---------------------------------------------------------------------------------------------------

    aaclient.dll               6.1.7601.17514                  
    accessibilitycpl.dll       6.1.7601.17514                 
    acctres.dll                6.1.7600.16385                     (Microsoft)
    acledit.dll                6.1.7600.16385                 ACL
    aclui.dll                  6.1.7600.16385                
    acppage.dll                6.1.7601.17514                  ""
    acproxy.dll                6.1.7600.16385               DLL  AUTOCHK
    actioncenter.dll           6.1.7601.17514               
    actioncentercpl.dll        6.1.7601.17514                 
    actionqueue.dll            6.1.7601.17514              Unattend Action Queue Generator / Executor
    activeds.dll               6.1.7601.17514               DLL   AD
    actxprxy.dll               6.1.7601.17514              ActiveX Interface Marshaling Library
    admparse.dll               8.0.7600.16385              IEAK Global Policy Template Parser
    admtmpl.dll                6.1.7601.17514               " "
    adprovider.dll             6.1.7600.16385               DLL adprovider
    adsldp.dll                 6.1.7601.17514              ADs LDAP Provider DLL
    adsldpc.dll                6.1.7600.16385               DLL  LDAP AD
    adsmsext.dll               6.1.7600.16385              ADs LDAP Provider DLL
    adsnt.dll                  6.1.7600.16385               DLL    Windows NT
    adtschema.dll              6.1.7600.16385                 
    advapi32.dll               6.1.7601.17514                API Windows 32
    advpack.dll                8.0.7600.16385              ADVPACK
    aecache.dll                6.1.7600.16385              AECache Sysprep Plugin
    aeevts.dll                 6.1.7600.16385                  
    aeinv.dll                  6.1.7601.17514              Application Experience Program Inventory Component
    aelupsvc.dll               6.1.7600.16385                 
    aepdu.dll                  6.1.7601.17514                   
    aepic.dll                  6.1.7600.16385              Application Experience Program Cache
    alttab.dll                 6.1.7600.16385              Windows Shell Alt Tab
    amstream.dll               6.6.7601.17514              DirectShow Runtime.
    amxread.dll                6.1.7600.16385              API Tracing Manifest Read Library
    apds.dll                   6.1.7600.16385                  Microsoft
    apilogen.dll               6.1.7600.16385                 API
    api-ms-win-core-console-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-datetime-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-debug-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-delayload-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-errorhandling-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-fibers-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-file-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-handle-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-heap-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-interlocked-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-io-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-libraryloader-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-localization-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-localregistry-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-memory-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-misc-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-namedpipe-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-processenvironment-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-processthreads-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-profile-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-rtlsupport-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-string-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-synch-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-sysinfo-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-threadpool-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-util-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-core-xstate-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-security-base-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-security-lsalookup-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-security-sddl-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-core-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-management-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-management-l2-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-winsvc-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    apircl.dll                 6.1.7600.16385              Microsoft InfoTech IR Local DLL
    apisetschema.dll           6.1.7600.16385              ApiSet Schema DLL
    apphelp.dll                6.1.7601.17514                 
    apphlpdm.dll               6.1.7600.16385                 
    appidapi.dll               6.1.7600.16385               API-  
    appidpolicyengineapi.dll   6.1.7600.16385              AppId Policy Engine API Module
    appidsvc.dll               6.1.7600.16385                
    appinfo.dll                6.1.7601.17514                 
    appmgmts.dll               6.1.7600.16385                
    appmgr.dll                 6.1.7601.17514                 
    apss.dll                   6.1.7600.16385              Microsoft InfoTech Storage System Library
    asferror.dll               12.0.7600.16385               ASF
    asycfilt.dll               6.1.7601.17514              
    atl.dll                    3.5.2284.0                  ATL Module for Windows XP (Unicode)
    atmfd.dll                  5.1.2.230                   Windows NT OpenType/Type 1 Font Driver
    atmlib.dll                 5.1.2.230                   Windows NT OpenType/Type 1 API Library.
    audiodev.dll               6.1.7601.17514                   
    audioeng.dll               6.1.7600.16385              Audio Engine
    audiokse.dll               6.1.7600.16385              Audio Ks Endpoint
    audioses.dll               6.1.7601.17514                
    audiosrv.dll               6.1.7601.17514               Windows Audio
    auditcse.dll               6.1.7600.16385              CSE   Windows
    auditnativesnapin.dll      6.1.7600.16385                    
    auditpolicygpinterop.dll   6.1.7600.16385                 
    auditpolmsg.dll            6.1.7600.16385                MMC  
    authfwcfg.dll              6.1.7600.16385               Windows      
    authfwgp.dll               6.1.7600.16385               Windows c      
    authfwsnapin.dll           6.1.7601.17514              Microsoft.WindowsFirewall.SnapIn
    authfwwizfwk.dll           6.1.7600.16385              Wizard Framework
    authui.dll                 6.1.7601.17514                
    authz.dll                  6.1.7600.16385              Authorization Framework
    autoplay.dll               6.1.7601.17514               ( )
    auxiliarydisplayapi.dll    6.1.7600.16385              Microsoft Windows SideShow API
    auxiliarydisplayclassinstaller.dll  6.1.7600.16385                 Microsoft Windows SideShow -  
    auxiliarydisplaycpl.dll    6.1.7601.17514                Microsoft Windows SideShow
    auxiliarydisplaydriverlib.dll  6.1.7600.16385              Microsoft Windows SideShow class extension component
    auxiliarydisplayservices.dll  6.1.7601.17514               Microsoft Windows SideShow
    avicap.dll                 1.15.0.1                    AVI Capture DLL
    avicap32.dll               6.1.7600.16385                 AVI
    avifil32.dll               6.1.7601.17514                 AVI
    avifile.dll                4.90.0.3000                 Microsoft AVI File support library
    avrt.dll                   6.1.7600.16385              Multimedia Realtime Runtime
    axinstsv.dll               6.1.7601.17514                ActiveX
    azroles.dll                6.1.7601.17514              azroles Module
    azroleui.dll               6.1.7601.17514               
    azsqlext.dll               6.1.7601.17514              AzMan Sql Audit Extended Stored Procedures Dll
    basecsp.dll                6.1.7601.17514                 - (Microsoft)
    basesrv.dll                6.1.7601.17514              Windows NT BASE API Server DLL
    batmeter.dll               6.1.7601.17514              Battery Meter Helper DLL
    batt.dll                   6.1.7600.16385                
    bcdprov.dll                6.1.7600.16385              Boot Configuration Data WMI Provider
    bcdsrv.dll                 6.1.7601.17514              Boot Configuration Data COM Server
    bcrypt.dll                 6.1.7600.16385              Windows Cryptographic Primitives Library
    bcryptprimitives.dll       6.1.7600.16385              Windows Cryptographic Primitives Library
    bdehdcfglib.dll            6.1.7600.16385                  Windows BitLocker
    bderepair.dll              6.1.7600.16385              BitLocker Drive Encryption: Drive Repair Tool
    bdesvc.dll                 6.1.7600.16385               BDE
    bdeui.dll                  6.1.7600.16385              Windows BitLocker Drive Encryption User Interface
    bfe.dll                    6.1.7601.17514                
    bidispl.dll                6.1.7600.16385              Bidispl DLL
    biocpl.dll                 6.1.7601.17514                - 
    biocredprov.dll            6.1.7600.16385                 WinBio
    bitsigd.dll                7.5.7600.16385              Background Intelligent Transfer Service IGD Support
    bitsperf.dll               7.5.7601.17514              Perfmon Counter Access
    bitsprx2.dll               7.5.7600.16385              Background Intelligent Transfer Service Proxy
    bitsprx3.dll               7.5.7600.16385              Background Intelligent Transfer Service 2.0 Proxy
    bitsprx4.dll               7.5.7600.16385              Background Intelligent Transfer Service 2.5 Proxy
    bitsprx5.dll               7.5.7600.16385              Background Intelligent Transfer Service 3.0 Proxy
    bitsprx6.dll               7.5.7600.16385              Background Intelligent Transfer Service 4.0 Proxy
    blackbox.dll               11.0.7601.17514             BlackBox DLL
    blb_ps.dll                 6.1.7600.16385              Microsoft Block Level Backup proxy/stub
    blbevents.dll              6.1.7601.17514               Blb
    blbres.dll                 6.1.7600.16385                     
    bootres.dll                6.1.7601.17514                
    bootstr.dll                6.1.7600.16385              Boot String Resource Library
    bootvid.dll                6.1.7600.16385              VGA Boot Driver
    brcoinst.dll               1.0.0.20                    Brother Multi Function CoInstaller
    brdgcfg.dll                6.1.7600.16385              NWLink IPX Notify Object
    bridgeres.dll              6.1.7600.16385               
    browcli.dll                6.1.7601.17514              Browser Service Client DLL
    browser.dll                6.1.7601.17514               DLL   
    browseui.dll               6.1.7601.17514              Shell Browser UI Library
    bthci.dll                  6.1.7600.16385                Bluetooth
    bthmtpcontexthandler.dll   6.1.7600.16385                 Bluetooth MTP
    bthpanapi.dll              6.1.7600.16385              bthpanapi
    bthpancontexthandler.dll   1.0.0.1                       Bthpan
    bthserv.dll                6.1.7600.16385                Bluetooth
    btpanui.dll                6.1.7600.16385                Bluetooth   
    bwcontexthandler.dll       1.0.0.1                      ContextH
    bwunpairelevated.dll       6.1.7600.16385              BWUnpairElevated Proxy Dll
    c_g18030.dll               6.1.7600.16385              GB18030 DBCS-Unicode Conversion DLL
    c_is2022.dll               6.1.7600.16385              ISO-2022 Code Page Translation DLL
    c_iscii.dll                6.1.7601.17514              ISCII Code Page Translation DLL
    cabinet.dll                6.1.7601.17514              Microsoft Cabinet File API
    cabview.dll                6.1.7601.17514                 CAB-
    capiprovider.dll           6.1.7600.16385               DLL capiprovider
    capisp.dll                 6.1.7600.16385              Sysprep cleanup dll for CAPI
    cardgames.dll              1.0.0.1                     CardGames Resources
    catsrv.dll                 2001.12.8530.16385          COM+ Configuration Catalog Server
    catsrvps.dll               2001.12.8530.16385          COM+ Configuration Catalog Server Proxy/Stub
    catsrvut.dll               2001.12.8530.16385          COM+ Configuration Catalog Server Utilities
    cca.dll                    6.6.7601.17514              CCA DirectShow Filter.
    cdd.dll                    6.1.7601.17514              Canonical Display Driver
    cdosys.dll                 6.6.7601.17514              Microsoft CDO for Windows Library
    certcli.dll                6.1.7601.17514                 Microsoft Active Directory
    certcredprovider.dll       6.1.7600.16385                 
    certenc.dll                6.1.7600.16385              Active Directory Certificate Services Encoding
    certenroll.dll             6.1.7601.17514                  Active Directory Microsoft
    certenrollui.dll           6.1.7600.16385                  X509
    certmgr.dll                6.1.7601.17514                
    certpoleng.dll             6.1.7601.17514                
    certprop.dll               6.1.7601.17514                 -
    cewmdm.dll                 12.0.7600.16385               Windows CE WMDM
    cfgbkend.dll               6.1.7600.16385              Configuration Backend Interface
    cfgmgr32.dll               6.1.7601.17514              Configuration Manager DLL
    chkwudrv.dll               6.1.7600.16385                    Windows
    chsbrkr.dll                6.1.7600.16385              Simplified Chinese Word Breaker
    chtbrkr.dll                6.1.7600.16385              Chinese Traditional Word Breaker
    chxreadingstringime.dll    6.1.7600.16385              CHxReadingStringIME
    ci.dll                     6.1.7601.17514              Code Integrity Module
    cic.dll                    6.1.7600.16385                CIC - MMC   
    circoinst.dll              6.1.7600.16385              USB Consumer IR Driver coinstaller for eHome
    clb.dll                    6.1.7600.16385                
    clbcatq.dll                2001.12.8530.16385          COM+ Configuration Catalog
    clfsw32.dll                6.1.7600.16385              Common Log Marshalling Win32 DLL
    cliconfg.dll               6.1.7600.16385              SQL Client Configuration Utility DLL
    clusapi.dll                6.1.7601.17514               API 
    cmcfg32.dll                7.2.7600.16385                  Microsoft
    cmdial32.dll               7.2.7600.16385               
    cmicryptinstall.dll        6.1.7600.16385              Installers for cryptographic elements of CMI objects
    cmifw.dll                  6.1.7600.16385              Windows Firewall rule configuration plug-in
    cmipnpinstall.dll          6.1.7600.16385              PNP plugin installer for CMI
    cmlua.dll                  7.2.7600.16385                API   
    cmnclim.dll                6.1.7600.16385                
    cmpbk32.dll                7.2.7600.16385              Microsoft Connection Manager Phonebook
    cmstplua.dll               7.2.7600.16385                API      
    cmutil.dll                 7.2.7600.16385                  (Microsoft)
    cngaudit.dll               6.1.7600.16385              Windows Cryptographic Next Generation audit library
    cngprovider.dll            6.1.7600.16385               DLL cngprovider
    cnvfat.dll                 6.1.7600.16385              FAT File System Conversion Utility DLL
    cofiredm.dll               6.1.7600.16385                  
    colbact.dll                2001.12.8530.16385          COM+
    colorcnv.dll               6.1.7600.16385              Windows Media Color Conversion
    colorui.dll                6.1.7600.16385                 
    comcat.dll                 6.1.7600.16385              Microsoft Component Category Manager Library
    comctl32.dll               5.82.7601.17514                  
    comdlg32.dll               6.1.7601.17514                 
    commdlg.dll                3.10.0.103                  Common Dialogs libraries
    compobj.dll                2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    compstui.dll               6.1.7600.16385                   
    comrepl.dll                2001.12.8530.16385          COM+
    comres.dll                 2001.12.8530.16385           COM+
    comsnap.dll                2001.12.8530.16385          COM+ Explorer MMC Snapin
    comsvcs.dll                2001.12.8530.16385          COM+ Services
    comuid.dll                 2001.12.8530.16385          COM+ Explorer UI
    connect.dll                6.1.7600.16385               
    console.dll                6.1.7600.16385                 
    corpol.dll                 8.0.7600.16385              Microsoft COM Runtime Execution Engine
    correngine.dll             6.1.7600.16385              Correlation Engine
    cpfilters.dll              6.6.7601.17514               PTFilter & Encypter/Decrypter Tagger Filters.
    credssp.dll                6.1.7601.17514              Credential Delegation Security Package
    credui.dll                 6.1.7601.17514                 
    crppresentation.dll        6.1.7600.16385              Conference Room Projector : Presentation
    crtdll.dll                 4.0.1183.1                  Microsoft C Runtime Library
    crypt32.dll                6.1.7601.17514              API32 
    cryptbase.dll              6.1.7600.16385              Base cryptographic API DLL
    cryptdlg.dll               6.1.7600.16385                
    cryptdll.dll               6.1.7600.16385              Cryptography Manager
    cryptext.dll               6.1.7600.16385                
    cryptnet.dll               6.1.7600.16385              Crypto Network Related API
    cryptsp.dll                6.1.7600.16385              Cryptographic Service Provider API
    cryptsvc.dll               6.1.7601.17514               
    cryptui.dll                6.1.7601.17514                
    cryptxml.dll               6.1.7600.16385              API- XML DigSig
    cscapi.dll                 6.1.7601.17514              Offline Files Win32 API
    cscdll.dll                 6.1.7601.17514              Offline Files Temporary Shim
    cscmig.dll                 6.1.7601.17514                   (Microsoft)
    cscobj.dll                 6.1.7601.17514               COM-   CSC API
    cscsvc.dll                 6.1.7601.17514              DLL  CSC
    cscui.dll                  6.1.7601.17514                  
    csrsrv.dll                 6.1.7600.16385                -
    ctl3d32.dll                2.31.0.0                    Ctl3D 3D Windows Controls
    ctl3dv2.dll                2.99.0.0                    Ctl3D 3D Windows NT(WOW) Controls
    d2d1.dll                   6.1.7601.17514              Microsoft D2D Library
    d3d10.dll                  6.1.7600.16385              Direct3D 10 Runtime
    d3d10_1.dll                6.1.7600.16385              Direct3D 10.1 Runtime
    d3d10_1core.dll            6.1.7601.17514              Direct3D 10.1 Runtime
    d3d10core.dll              6.1.7600.16385              Direct3D 10 Runtime
    d3d10level9.dll            6.1.7601.17514              Direct3D 10 to Direct3D9 Translation Runtime
    d3d10warp.dll              6.1.7601.17514              Direct3D 10 Rasterizer
    d3d11.dll                  6.1.7601.17514              Direct3D 11 Runtime
    d3d8.dll                   6.1.7600.16385              Microsoft Direct3D
    d3d8thk.dll                6.1.7600.16385              Microsoft Direct3D OS Thunk Layer
    d3d9.dll                   6.1.7601.17514              Direct3D 9 Runtime
    d3dcompiler_33.dll         9.18.904.15                 Microsoft Direct3D
    d3dcompiler_34.dll         9.19.949.46                 Microsoft Direct3D
    d3dcompiler_35.dll         9.19.949.1104               Microsoft Direct3D
    d3dcompiler_36.dll         9.19.949.2111               Microsoft Direct3D
    d3dcompiler_37.dll         9.22.949.2248               Microsoft Direct3D
    d3dcompiler_38.dll         9.23.949.2378               Microsoft Direct3D
    d3dcompiler_39.dll         9.24.949.2307               Microsoft Direct3D
    d3dcompiler_40.dll         9.24.950.2656               Direct3D HLSL Compiler
    d3dcompiler_41.dll         9.26.952.2844               Direct3D HLSL Compiler
    d3dcompiler_42.dll         9.27.952.3022               Direct3D HLSL Compiler
    d3dcompiler_43.dll         9.29.952.3111               Direct3D HLSL Compiler
    d3dcsx_42.dll              9.27.952.3022               Direct3D 10.1 Extensions
    d3dcsx_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dim.dll                  6.1.7600.16385              Microsoft Direct3D
    d3dim700.dll               6.1.7600.16385              Microsoft Direct3D
    d3dramp.dll                6.1.7600.16385              Microsoft Direct3D
    d3dx10.dll                 9.16.843.0                  Microsoft Direct3D
    d3dx10_33.dll              9.18.904.21                 Microsoft Direct3D
    d3dx10_34.dll              9.19.949.46                 Microsoft Direct3D
    d3dx10_35.dll              9.19.949.1104               Microsoft Direct3D
    d3dx10_36.dll              9.19.949.2009               Microsoft Direct3D
    d3dx10_37.dll              9.19.949.2187               Microsoft Direct3D
    d3dx10_38.dll              9.23.949.2378               Microsoft Direct3D
    d3dx10_39.dll              9.24.949.2307               Microsoft Direct3D
    d3dx10_40.dll              9.24.950.2656               Direct3D 10.1 Extensions
    d3dx10_41.dll              9.26.952.2844               Direct3D 10.1 Extensions
    d3dx10_42.dll              9.27.952.3001               Direct3D 10.1 Extensions
    d3dx10_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dx11_42.dll              9.27.952.3022               Direct3D 10.1 Extensions
    d3dx11_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dx9_24.dll               9.5.132.0                   Microsoft DirectX for Windows
    d3dx9_25.dll               9.6.168.0                   Microsoft DirectX for Windows
    d3dx9_26.dll               9.7.239.0                   Microsoft DirectX for Windows
    d3dx9_27.dll               9.8.299.0                   Microsoft DirectX for Windows
    d3dx9_28.dll               9.10.455.0                  Microsoft DirectX for Windows
    d3dx9_29.dll               9.11.519.0                  Microsoft DirectX for Windows
    d3dx9_30.dll               9.12.589.0                  Microsoft DirectX for Windows
    d3dx9_31.dll               9.15.779.0                  Microsoft DirectX for Windows
    d3dx9_32.dll               9.16.843.0                  Microsoft DirectX for Windows
    d3dx9_33.dll               9.18.904.15                 Microsoft DirectX for Windows
    d3dx9_34.dll               9.19.949.46                 Microsoft DirectX for Windows
    d3dx9_35.dll               9.19.949.1104               Microsoft DirectX for Windows
    d3dx9_36.dll               9.19.949.2111               Microsoft DirectX for Windows
    d3dx9_37.dll               9.22.949.2248               Microsoft DirectX for Windows
    d3dx9_38.dll               9.23.949.2378               Microsoft DirectX for Windows
    d3dx9_39.dll               9.24.949.2307               Microsoft DirectX for Windows
    d3dx9_40.dll               9.24.950.2656               Direct3D 9 Extensions
    d3dx9_41.dll               9.26.952.2844               Direct3D 9 Extensions
    d3dx9_42.dll               9.27.952.3001               Direct3D 9 Extensions
    d3dx9_43.dll               9.29.952.3111               Direct3D 9 Extensions
    d3dxof.dll                 6.1.7600.16385              DirectX Files DLL
    dataclen.dll               6.1.7600.16385                 Windows
    davclnt.dll                6.1.7601.17514              Web DAV Client DLL
    davhlpr.dll                6.1.7600.16385              DAV Helper DLL
    dbgeng.dll                 6.1.7601.17514              Windows Symbolic Debugger Engine
    dbghelp.dll                6.1.7601.17514              Windows Image Helper
    dbnetlib.dll               6.1.7600.16385              Winsock Oriented Net DLL for SQL Clients
    dbnmpntw.dll               6.1.7600.16385              Named Pipes Net DLL for SQL Clients
    dciman32.dll               6.1.7600.16385              DCI Manager
    ddaclsys.dll               6.1.7600.16385              SysPrep module for Reseting Data Drive ACL 
    ddeml.dll                  3.50.0.103                  DDE Management library
    ddoiproxy.dll              6.1.7600.16385              DDOI Interface Proxy
    ddores.dll                 6.1.7600.16385                  
    ddraw.dll                  6.1.7600.16385              Microsoft DirectDraw
    ddrawex.dll                6.1.7600.16385              Direct Draw Ex
    defaultlocationcpl.dll     6.1.7601.17514               :   
    defragproxy.dll            6.1.7600.16385              Microsoft Disk Defragmenter Proxy Library
    defragsvc.dll              6.1.7600.16385              \ 
    deskadp.dll                6.1.7600.16385                 
    deskmon.dll                6.1.7600.16385                
    deskperf.dll               6.1.7600.16385                
    devenum.dll                6.6.7600.16385               .
    devicecenter.dll           6.1.7601.17514                
    devicedisplaystatusmanager.dll  6.1.7600.16385              Device Display Status Manager
    devicemetadataparsers.dll  6.1.7600.16385              Common Device Metadata parsers
    devicepairing.dll          6.1.7600.16385               ,   
    devicepairingfolder.dll    6.1.7601.17514                 
    devicepairinghandler.dll   6.1.7600.16385              Device Pairing Handler Dll
    devicepairingproxy.dll     6.1.7600.16385              Device Pairing Proxy Dll
    deviceuxres.dll            6.1.7600.16385              Windows Device User Experience Resource File
    devmgr.dll                 6.1.7600.16385                 
    devobj.dll                 6.1.7600.16385              Device Information Set DLL
    devrtl.dll                 6.1.7600.16385              Device Management Run Time Library
    dfdts.dll                  6.1.7600.16385                  (Windows)
    dfscli.dll                 6.1.7600.16385              Windows NT Distributed File System Client DLL
    dfshim.dll                 4.0.40305.0                 ClickOnce Application Deployment Support Library
    dfsshlex.dll               6.1.7600.16385                   DFS
    dhcpcmonitor.dll           6.1.7600.16385               (DLL)   DHCP
    dhcpcore.dll               6.1.7601.17514               DHCP-
    dhcpcore6.dll              6.1.7600.16385               DHCPv6
    dhcpcsvc.dll               6.1.7600.16385               DHCP-
    dhcpcsvc6.dll              6.1.7600.16385               DHCPv6
    dhcpqec.dll                6.1.7600.16385                   Microsoft DHCP
    dhcpsapi.dll               6.1.7600.16385               API  DHCP-c
    diagcpl.dll                6.1.7601.17514                -  
    diagperf.dll               6.1.7601.17514                 (Microsoft)
    difxapi.dll                2.1.0.0                     Driver Install Frameworks for API library module
    dimsjob.dll                6.1.7600.16385               DLL  DIMS
    dimsroam.dll               6.1.7600.16385               DLL  DIMS  
    dinput.dll                 6.1.7600.16385              Microsoft DirectInput
    dinput8.dll                6.1.7600.16385              Microsoft DirectInput
    directdb.dll               6.1.7600.16385              Microsoft Direct Database API
    diskcopy.dll               6.1.7600.16385              Windows DiskCopy
    dispci.dll                 6.1.7600.16385                 (Microsoft)
    dispex.dll                 5.8.7600.16385              Microsoft  DispEx
    display.dll                6.1.7601.17514                
    dmband.dll                 6.1.7600.16385              Microsoft DirectMusic Band
    dmcompos.dll               6.1.7600.16385              Microsoft DirectMusic Composer
    dmdlgs.dll                 6.1.7600.16385              Disk Management Snap-in Dialogs
    dmdskmgr.dll               6.1.7600.16385              Disk Management Snap-in Support Library
    dmdskres.dll               6.1.7600.16385                 
    dmdskres2.dll              6.1.7600.16385                 
    dmime.dll                  6.1.7600.16385              Microsoft DirectMusic Interactive Engine
    dmintf.dll                 6.1.7600.16385              Disk Management DCOM Interface Stub
    dmloader.dll               6.1.7600.16385              Microsoft DirectMusic Loader
    dmocx.dll                  6.1.7600.16385              TreeView OCX
    dmrc.dll                   6.1.7600.16385              Windows MRC
    dmscript.dll               6.1.7600.16385              Microsoft DirectMusic Scripting
    dmstyle.dll                6.1.7600.16385              Microsoft DirectMusic Style Engline
    dmsynth.dll                6.1.7600.16385              Microsoft DirectMusic Software Synthesizer
    dmusic.dll                 6.1.7600.16385                Microsoft DirectMusic
    dmutil.dll                 6.1.7600.16385                 
    dmvdsitf.dll               6.1.7600.16385              Disk Management Snap-in Support Library
    dmvscres.dll               6.1.7601.17514               DLL     
    dnsapi.dll                 6.1.7601.17514                API DNS-
    dnscmmc.dll                6.1.7601.17514               DLL  DNS  MMC
    dnsext.dll                 6.1.7600.16385              DNS extension DLL
    dnshc.dll                  6.1.7600.16385                DNS
    dnsrslvr.dll               6.1.7601.17514                 DNS
    docprop.dll                6.1.7600.16385                OLE
    documentperformanceevents.dll  6.1.7600.16385                   
    dot3api.dll                6.1.7601.17514              802.3 Autoconfiguration API
    dot3cfg.dll                6.1.7601.17514               Netsh  802.3
    dot3dlg.dll                6.1.7600.16385                UI  802.3
    dot3gpclnt.dll             6.1.7600.16385                   802.3
    dot3gpui.dll               6.1.7600.16385               "   802.3"
    dot3hc.dll                 6.1.7600.16385                 Dot3
    dot3msm.dll                6.1.7601.17514                   802.3
    dot3svc.dll                6.1.7601.17514               
    dot3ui.dll                 6.1.7601.17514                802.3
    dpapiprovider.dll          6.1.7600.16385               DLL dpapiprovider
    dplayx.dll                 6.1.7600.16385              Microsoft DirectPlay
    dpmodemx.dll               6.1.7600.16385                      DirectPlay
    dpnaddr.dll                6.1.7601.17514              Microsoft DirectPlay8 Address
    dpnathlp.dll               6.1.7600.16385              Microsoft DirectPlay NAT Helper UPnP
    dpnet.dll                  6.1.7600.16385              Microsoft DirectPlay
    dpnhpast.dll               6.1.7600.16385              Microsoft DirectPlay NAT Helper PAST
    dpnhupnp.dll               6.1.7600.16385              Microsoft DirectPlay NAT Helper UPNP
    dpnlobby.dll               6.1.7600.16385              Microsoft DirectPlay8 Lobby
    dps.dll                    6.1.7601.17514                 WDI
    dpwsockx.dll               6.1.7600.16385                  TCP/IP  IPX  DirectPlay
    dpx.dll                    6.1.7601.17514              Microsoft(R) Delta Package Expander
    drmmgrtn.dll               11.0.7601.17514             DRM Migration DLL
    drmv2clt.dll               11.0.7600.16385             DRMv2 Client DLL
    drprov.dll                 6.1.7600.16385                   ,        ()
    drt.dll                    6.1.7600.16385                
    drtprov.dll                6.1.7600.16385              Distributed Routing Table Providers
    drttransport.dll           6.1.7600.16385              Distributed Routing Table Transport Provider
    drvstore.dll               6.1.7601.17514              Driver Store API
    ds16gt.dll                 3.510.3711.0                Microsoft ODBC Driver Setup Generic Thunk
    ds32gt.dll                 6.1.7600.16385              ODBC Driver Setup Generic Thunk
    dsauth.dll                 6.1.7601.17514              DS Authorization for Services
    dsdmo.dll                  6.1.7600.16385              DirectSound Effects
    dshowrdpfilter.dll         1.0.0.0                           ()
    dskquota.dll               6.1.7600.16385               DLL    Windows
    dskquoui.dll               6.1.7601.17514               DLL   
    dsound.dll                 6.1.7600.16385              DirectSound
    dsprop.dll                 6.1.7600.16385                Active Directory
    dsquery.dll                6.1.7600.16385                 
    dsrole.dll                 6.1.7600.16385              DS Role Client DLL
    dssec.dll                  6.1.7600.16385                 
    dssenh.dll                 6.1.7600.16385              Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider
    dsuiext.dll                6.1.7601.17514                 
    dswave.dll                 6.1.7600.16385              Microsoft DirectMusic Wave
    dtsh.dll                   6.1.7600.16385               API     
    dui70.dll                  6.1.7600.16385               DirectUI Windows
    duser.dll                  6.1.7600.16385              Windows DirectUser Engine
    dwmapi.dll                 6.1.7600.16385               API     ()
    dwmcore.dll                6.1.7601.17514                Microsoft DWM
    dwmredir.dll               6.1.7601.17514                    Microsoft
    dwrite.dll                 6.1.7601.17514               Microsoft DirectX Typography
    dxdiagn.dll                6.1.7601.17514                Microsoft DirectX
    dxgi.dll                   6.1.7601.17514              DirectX Graphics Infrastructure
    dxmasf.dll                 12.0.7601.17514             Microsoft Windows Media Component Removal File.
    dxp.dll                    6.1.7601.17514                 Device Stage
    dxpps.dll                  6.1.7600.16385              Device Experience Platform Proxy\Stub DLL
    dxptaskringtone.dll        6.1.7601.17514                 Microsoft
    dxptasksync.dll            6.1.7601.17514               Microsoft Windows DXP
    dxtmsft.dll                8.0.7600.16385              DirectX Media -- Image DirectX Transforms
    dxtrans.dll                8.0.7600.16385              DirectX Media -- DirectX Transform Core
    dxva2.dll                  6.1.7600.16385              DirectX Video Acceleration 2.0 DLL
    eapp3hst.dll               6.1.7601.17514              Microsoft ThirdPartyEapDispatcher
    eappcfg.dll                6.1.7600.16385                EAP
    eappgnui.dll               6.1.7601.17514                 EAP
    eapphost.dll               6.1.7601.17514                 EAPHost 
    eappprxy.dll               6.1.7600.16385              Microsoft EAPHost Peer Client DLL
    eapqec.dll                 6.1.7600.16385                   Microsoft EAP
    eapsvc.dll                 6.1.7600.16385               Microsoft EAPHost
    efsadu.dll                 6.1.7600.16385                
    efscore.dll                6.1.7601.17514              EFS Core Library
    efslsaext.dll              6.1.7600.16385              LSA extension for EFS
    efssvc.dll                 6.1.7600.16385               EFS
    efsutil.dll                6.1.7600.16385              EFS Utility Library
    ehstorapi.dll              6.1.7601.17514              Windows Enhanced Storage API
    ehstorpwdmgr.dll           6.1.7600.16385                Windows Enhanced Storage
    ehstorshell.dll            6.1.7600.16385               DLL   Windows Enhanced Storage
    els.dll                    6.1.7600.16385                
    elscore.dll                6.1.7600.16385               DLL   Els
    elslad.dll                 6.1.7600.16385              ELS Language Detection
    elstrans.dll               6.1.7601.17514              ELS Transliteration Service
    encapi.dll                 6.1.7600.16385              Encoder API
    encdec.dll                 6.6.7601.17514                XDS     .
    encdump.dll                5.0.1.1                     Media Foundation Crash Dump Encryption DLL 
    energy.dll                 6.1.7600.16385                
    eqossnap.dll               6.1.7600.16385                EQoS
    es.dll                     2001.12.8530.16385          COM+
    esent.dll                  6.1.7601.17514                  ESE  Microsoft(R) Windows(R)
    esentprf.dll               6.1.7600.16385              Extensible Storage Engine Performance Monitoring Library for Microsoft(R) Windows(R)
    eventcls.dll               6.1.7600.16385              Microsoft Volume Shadow Copy Service event class
    evr.dll                    6.1.7601.17514                DLL   
    explorerframe.dll          6.1.7601.17514              ExplorerFrame
    expsrv.dll                 6.0.72.9589                 Visual Basic for Applications Runtime - Expression Service
    f3ahvoas.dll               6.1.7600.16385              JP Japanese Keyboard Layout for Fujitsu FMV oyayubi-shift keyboard
    faultrep.dll               6.1.7601.17514                     Windows
    fdbth.dll                  6.1.7600.16385              Function Discovery Bluetooth Provider Dll
    fdbthproxy.dll             6.1.7600.16385              Bluetooth Provider Proxy Dll
    fde.dll                    6.1.7601.17514                 
    fdeploy.dll                6.1.7601.17514                  
    fdphost.dll                6.1.7600.16385                  
    fdpnp.dll                  6.1.7600.16385              Pnp Provider Dll
    fdprint.dll                6.1.7600.16385               DLL    
    fdproxy.dll                6.1.7600.16385              Function Discovery Proxy Dll
    fdrespub.dll               6.1.7600.16385                  
    fdssdp.dll                 6.1.7600.16385              Function Discovery SSDP Provider Dll
    fdwcn.dll                  6.1.7600.16385              Windows Connect Now - Config Function Discovery Provider DLL
    fdwnet.dll                 6.1.7600.16385              Function Discovery WNet Provider Dll
    fdwsd.dll                  6.1.7600.16385              Function Discovery WS Discovery Provider Dll
    feclient.dll               6.1.7600.16385              Windows NT File Encryption Client Interfaces
    ff_vfw.dll                                             
    filemgmt.dll               6.1.7600.16385                 
    findnetprinters.dll        6.1.7600.16385              Find Network Printers COM Component
    firewallapi.dll            6.1.7600.16385              API  Windows
    firewallcontrolpanel.dll   6.1.7601.17514                -  Windows
    fltlib.dll                 6.1.7600.16385               
    fmifs.dll                  6.1.7600.16385              FM IFS Utility DLL
    fms.dll                    1.1.6000.16384                
    fntcache.dll               6.1.7601.17514                 Windows
    fontext.dll                6.1.7601.17514                Windows
    fontsub.dll                6.1.7601.17514              Font Subsetting DLL
    fphc.dll                   6.1.7601.17514               Filtering Platform Helper
    framebuf.dll               6.1.7600.16385              Framebuffer Display Driver
    framedyn.dll               6.1.7601.17514              WMI SDK Provider Framework
    framedynos.dll             6.1.7601.17514              WMI SDK Provider Framework
    fthsvc.dll                 6.1.7600.16385                  Microsoft Windows
    fundisc.dll                6.1.7600.16385              DLL  
    fveapi.dll                 6.1.7601.17514              Windows BitLocker Drive Encryption API
    fveapibase.dll             6.1.7600.16385              Windows BitLocker Drive Encryption Base API
    fvecerts.dll               6.1.7600.16385              BitLocker Certificates Library
    fvecpl.dll                 6.1.7601.17514                  BitLocker
    fverecover.dll             6.1.7600.16385                   Windows BitLocker
    fveui.dll                  6.1.7600.16385                 BitLocker
    fvewiz.dll                 6.1.7600.16385                 BitLocker
    fwcfg.dll                  6.1.7600.16385                  Windows
    fwpuclnt.dll               6.1.7601.17514              API   FWP/IPsec
    fwremotesvr.dll            6.1.7600.16385              Windows Firewall Remote APIs Server
    fxsapi.dll                 6.1.7600.16385              Microsoft  Fax API Support DLL
    fxscom.dll                 6.1.7600.16385              Microsoft Fax Server COM Client Interface
    fxscomex.dll               6.1.7600.16385              Microsoft Fax Server Extended COM Client Interface
    fxscompose.dll             6.1.7600.16385              Compose Form
    fxscomposeres.dll          6.1.7600.16385               
    fxsevent.dll               6.1.7600.16385               DLL    Microsoft Fax
    fxsext32.dll               6.1.7600.16385              Microsoft  Fax Exchange Command Extension
    fxsmon.dll                 6.1.7601.17514              Microsoft  Fax Print Monitor
    fxsresm.dll                6.1.7600.16385               DLL   (Microsoft)
    fxsroute.dll               6.1.7600.16385              Microsoft  Fax Routing DLL
    fxsst.dll                  6.1.7600.16385              Fax Service
    fxst30.dll                 6.1.7600.16385              Microsoft  Fax T30 Protocol Service Provider
    fxstiff.dll                6.1.7601.17514              Microsoft  Fax TIFF library
    fxsutility.dll             6.1.7600.16385               (DLL)  
    fxsxp32.dll                6.1.7600.16385              Microsoft  Fax Transport Provider
    gacinstall.dll             6.1.7600.16385              Installers for CLR and other managed code
    gameux.dll                 6.1.7601.17514               
    gameuxlegacygdfs.dll       1.0.0.1                     Legacy GDF resource DLL
    gcdef.dll                  6.1.7600.16385                   
    gdi32.dll                  6.1.7601.17514              GDI Client DLL
    getuname.dll               6.1.7600.16385                   UCE
    glmf32.dll                 6.1.7600.16385              OpenGL Metafiling DLL
    glu32.dll                  6.1.7600.16385                OpenGL
    gpapi.dll                  6.1.7600.16385                API  
    gpedit.dll                 6.1.7600.16385              GPEdit
    gpprefcl.dll               6.1.7601.17514                 
    gpprnext.dll               6.1.7600.16385                 
    gpscript.dll               6.1.7600.16385                
    gpsvc.dll                  6.1.7601.17514                
    gptext.dll                 6.1.7600.16385              GPTExt
    groupinghc.dll             6.1.7600.16385                
    hal.dll                    6.1.7601.17514              Hardware Abstraction Layer DLL
    halacpi.dll                6.1.7601.17514              Hardware Abstraction Layer DLL
    halmacpi.dll               6.1.7601.17514              Hardware Abstraction Layer DLL
    hbaapi.dll                 6.1.7601.17514              HBA API data interface dll for HBA_API_Rev_2-18_2002MAR1.doc
    hcproviders.dll            6.1.7600.16385                
    helppaneproxy.dll          6.1.7600.16385              Microsoft Help Proxy
    hgcpl.dll                  6.1.7601.17514                 
    hgprint.dll                6.1.7601.17514              HomeGroup Printing Support
    hhsetup.dll                6.1.7600.16385              Microsoft HTML Help
    hid.dll                    6.1.7600.16385                HID
    hidserv.dll                6.1.7600.16385               HID
    hlink.dll                  6.1.7600.16385               Microsoft Office 2000
    hnetcfg.dll                6.1.7600.16385                 
    hnetmon.dll                6.1.7600.16385              DLL   
    hotplug.dll                6.1.7600.16385                 
    hotstartuseragent.dll      6.1.7601.17514                Windows HotStart (Microsoft)
    httpapi.dll                6.1.7601.17514              HTTP Protocol Stack API
    htui.dll                   6.1.7600.16385                  
    ias.dll                    6.1.7600.16385                 (NPS)
    iasacct.dll                6.1.7601.17514                NPS
    iasads.dll                 6.1.7600.16385                Active Directory NPS
    iasdatastore.dll           6.1.7600.16385              NPS Datastore server
    iashlpr.dll                6.1.7600.16385                NPS
    iasmigplugin.dll           6.1.7600.16385              NPS Migration DLL
    iasnap.dll                 6.1.7600.16385              NPS NAP Provider
    iaspolcy.dll               6.1.7600.16385              NPS Pipeline
    iasrad.dll                 6.1.7601.17514                RADIUS NPS
    iasrecst.dll               6.1.7601.17514              NPS XML Datastore Access
    iassam.dll                 6.1.7600.16385              NPS NT SAM Provider
    iassdo.dll                 6.1.7600.16385               SDO NPS
    iassvcs.dll                6.1.7600.16385                NPS
    icaapi.dll                 6.1.7601.17514              DLL Interface to TermDD Device Driver
    icardie.dll                8.0.7600.16385              Microsoft Information Card IE Helper
    icardres.dll               3.0.4506.4926               Windows CardSpace
    iccoinstall.dll            6.1.7601.17514              Hyper-V Integration Components Coinstaller
    iccvid.dll                 1.10.0.13                    Cinepak
    icfupgd.dll                6.1.7600.16385              Windows Firewal ICF Settings Upgrade
    icm32.dll                  6.1.7600.16385              Microsoft Color Management Module (CMM)
    icmp.dll                   6.1.7600.16385              ICMP DLL
    icmui.dll                  6.1.7600.16385                  
    iconcodecservice.dll       6.1.7600.16385              Converts a PNG part of the icon to a legacy bmp icon
    icsigd.dll                 6.1.7600.16385                 
    idlisten.dll               6.1.7600.16385               
    idndl.dll                  6.1.7600.16385              Downlevel DLL
    idstore.dll                6.1.7600.16385              Identity Store
    ieakeng.dll                8.0.7600.16385                  Internet Explorer
    ieaksie.dll                8.0.7600.16385                 Internet Explorer   
    ieakui.dll                 8.0.7600.16385                UI DLL Microsoft IEAK
    ieapfltr.dll               8.0.6001.18669              Microsoft SmartScreen Filter
    iedkcs32.dll               18.0.7601.17514               IEAK
    ieframe.dll                8.0.7601.17514              -
    iepeers.dll                8.0.7601.17514              Peer- Internet Explorer
    iernonce.dll               8.0.7600.16385                RunOnce   
    iertutil.dll               8.0.7601.17514              Run time utility for Internet Explorer
    iesetup.dll                8.0.7600.16385                IOD
    iesysprep.dll              8.0.7601.17514              IE Sysprep Provider
    ieui.dll                   8.0.7600.16385                 Internet Explorer
    ifmon.dll                  6.1.7600.16385                IF
    ifsutil.dll                6.1.7601.17514              IFS Utility DLL
    ifsutilx.dll               6.1.7600.16385              IFS Utility Extension DLL
    igddiag.dll                6.1.7600.16385                IGD
    ikeext.dll                 6.1.7601.17514                IKE
    imagehlp.dll               6.1.7601.17514              Windows NT Image Helper
    imageres.dll               6.1.7600.16385              Windows Image Resource
    imagesp1.dll               6.1.7600.16385              Windows SP1 Image Resource
    imapi.dll                  6.1.7600.16385               Image Mastering API
    imapi2.dll                 6.1.7601.17514              IMAPI  2
    imapi2fs.dll               6.1.7601.17514              Image Mastering File System Imaging API v2
    imgutil.dll                8.0.7601.17514              IE plugin image decoder support DLL
    imjp10k.dll                10.1.7600.16385             Microsoft IME
    imm32.dll                  6.1.7601.17514              Multi-User Windows IMM32 API Client DLL
    inetcomm.dll               6.1.7601.17514              Microsoft Internet Messaging API Resources
    inetmib1.dll               6.1.7601.17514              Microsoft MIB-II subagent
    inetpp.dll                 6.1.7601.17514               DLL Internet Print Provider
    inetppui.dll               6.1.7600.16385               DLL    
    inetres.dll                6.1.7600.16385               API  
    infocardapi.dll            3.0.4506.4926               Microsoft InfoCards
    inked.dll                  6.1.7600.16385              Microsoft Tablet PC InkEdit Control
    input.dll                  6.1.7601.17514               DLL  
    inseng.dll                 8.0.7601.17514               
    iologmsg.dll               6.1.7600.16385                /
    ipbusenum.dll              6.1.7600.16385              PnP-X IP Bus Enumerator DLL
    ipbusenumproxy.dll         6.1.7600.16385              Associated Device Presence Proxy Dll
    iphlpapi.dll               6.1.7601.17514              IP Helper API
    iphlpsvc.dll               6.1.7601.17514                   IPv6   IPv4.
    ipnathlp.dll               6.1.7600.16385                 Microsoft NAT
    iprop.dll                  6.1.7600.16385              OLE PropertySet Implementation
    iprtprio.dll               6.1.7600.16385              IP Routing Protocol Priority DLL
    iprtrmgr.dll               6.1.7601.17514               IP-
    ipsecsnp.dll               6.1.7600.16385                 IP-
    ipsecsvc.dll               6.1.7601.17514              Windows IPsec SPD Server DLL
    ipsmsnap.dll               6.1.7601.17514                IP-
    ir32_32.dll                3.24.15.3                   32-  Intel Indeo(R) Video R3.2
    ir41_qc.dll                4.30.62.2                   Intel Indeo Video Interactive Quick Compressor
    ir41_qcx.dll               4.30.62.2                   Intel Indeo Video Interactive Quick Compressor
    ir50_32.dll                5.2562.15.55                Intel Indeo video 5.10
    ir50_qc.dll                5.0.63.48                   Intel Indeo video 5.10 Quick Compressor
    ir50_qcx.dll               5.0.63.48                   Intel Indeo video 5.10 Quick Compressor
    irclass.dll                6.1.7600.16385                 
    irmon.dll                  6.1.7600.16385                
    iscsicpl.dll               5.2.3790.1830                   iSCSI
    iscsidsc.dll               6.1.7600.16385              API-  iSCSI
    iscsied.dll                6.1.7600.16385              iSCSI Extension DLL
    iscsiexe.dll               6.1.7600.16385                iSCSI
    iscsilog.dll               6.1.7600.16385               DLL   iSCSI
    iscsium.dll                6.1.7601.17514              iSCSI Discovery api
    iscsiwmi.dll               6.1.7600.16385              MS iSCSI Initiator WMI Provider
    itircl.dll                 6.1.7601.17514              Microsoft InfoTech IR Local DLL
    itss.dll                   6.1.7600.16385              Microsoft InfoTech Storage System Library
    itvdata.dll                6.6.7601.17514              iTV Data Filters.
    iyuv_32.dll                6.1.7601.17514              Intel Indeo(R) Video YUV 
    jnwmon.dll                 0.3.7600.16385                  Windows
    jscript.dll                5.8.7601.17514              Microsoft (R) JScript
    jsproxy.dll                8.0.7600.16385              JScript Proxy Auto-Configuration
    kbd101.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for 101
    kbd101a.dll                6.1.7600.16385              KO Hangeul Keyboard Layout for 101 (Type A)
    kbd101b.dll                6.1.7600.16385              KO Hangeul Keyboard Layout for 101(Type B)
    kbd101c.dll                6.1.7600.16385              KO Hangeul Keyboard Layout for 101(Type C)
    kbd103.dll                 6.1.7600.16385              KO Hangeul Keyboard Layout for 103
    kbd106.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for 106
    kbd106n.dll                6.1.7600.16385              JP Japanese Keyboard Layout for 106
    kbda1.dll                  6.1.7600.16385              Arabic_English_101 Keyboard Layout
    kbda2.dll                  6.1.7600.16385              Arabic_2 Keyboard Layout
    kbda3.dll                  6.1.7600.16385              Arabic_French_102 Keyboard Layout
    kbdal.dll                  6.1.7600.16385              Albania Keyboard Layout
    kbdarme.dll                6.1.7600.16385              Eastern Armenian Keyboard Layout
    kbdarmw.dll                6.1.7600.16385              Western Armenian Keyboard Layout
    kbdax2.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for AX2
    kbdaze.dll                 6.1.7600.16385              Azerbaijan_Cyrillic Keyboard Layout
    kbdazel.dll                6.1.7600.16385              Azeri-Latin Keyboard Layout
    kbdbash.dll                6.1.7601.17514              Bashkir Keyboard Layout
    kbdbe.dll                  6.1.7600.16385              Belgian Keyboard Layout
    kbdbene.dll                6.1.7600.16385              Belgian Dutch Keyboard Layout
    kbdbgph.dll                6.1.7600.16385              Bulgarian Phonetic Keyboard Layout
    kbdbgph1.dll               6.1.7600.16385              Bulgarian (Phonetic Traditional) Keyboard Layout
    kbdbhc.dll                 6.1.7600.16385              Bosnian (Cyrillic) Keyboard Layout
    kbdblr.dll                 6.1.7601.17514              Belarusian Keyboard Layout
    kbdbr.dll                  6.1.7600.16385              Brazilian Keyboard Layout
    kbdbu.dll                  6.1.7600.16385              Bulgarian (Typewriter) Keyboard Layout
    kbdbulg.dll                6.1.7601.17514              Bulgarian Keyboard Layout
    kbdca.dll                  6.1.7600.16385              Canadian Multilingual Keyboard Layout
    kbdcan.dll                 6.1.7600.16385              Canadian Multilingual Standard Keyboard Layout
    kbdcr.dll                  6.1.7600.16385              Croatian/Slovenian Keyboard Layout
    kbdcz.dll                  6.1.7600.16385              Czech Keyboard Layout
    kbdcz1.dll                 6.1.7601.17514              Czech_101 Keyboard Layout
    kbdcz2.dll                 6.1.7600.16385              Czech_Programmer's Keyboard Layout
    kbdda.dll                  6.1.7600.16385              Danish Keyboard Layout
    kbddiv1.dll                6.1.7600.16385              Divehi Phonetic Keyboard Layout
    kbddiv2.dll                6.1.7600.16385              Divehi Typewriter Keyboard Layout
    kbddv.dll                  6.1.7600.16385              Dvorak US English Keyboard Layout
    kbdes.dll                  6.1.7600.16385              Spanish Alernate Keyboard Layout
    kbdest.dll                 6.1.7600.16385              Estonia Keyboard Layout
    kbdfa.dll                  6.1.7600.16385              Persian Keyboard Layout
    kbdfc.dll                  6.1.7600.16385              Canadian French Keyboard Layout
    kbdfi.dll                  6.1.7600.16385              Finnish Keyboard Layout
    kbdfi1.dll                 6.1.7600.16385              Finnish-Swedish with Sami Keyboard Layout
    kbdfo.dll                  6.1.7600.16385              F?roese Keyboard Layout
    kbdfr.dll                  6.1.7600.16385              French Keyboard Layout
    kbdgae.dll                 6.1.7600.16385              Gaelic Keyboard Layout
    kbdgeo.dll                 6.1.7601.17514              Georgian Keyboard Layout
    kbdgeoer.dll               6.1.7600.16385              Georgian (Ergonomic) Keyboard Layout
    kbdgeoqw.dll               6.1.7600.16385              Georgian (QWERTY) Keyboard Layout
    kbdgkl.dll                 6.1.7601.17514              Greek_Latin Keyboard Layout
    kbdgr.dll                  6.1.7600.16385              German Keyboard Layout
    kbdgr1.dll                 6.1.7601.17514              German_IBM Keyboard Layout
    kbdgrlnd.dll               6.1.7600.16385              Greenlandic Keyboard Layout
    kbdhau.dll                 6.1.7600.16385              Hausa Keyboard Layout
    kbdhe.dll                  6.1.7600.16385              Greek Keyboard Layout
    kbdhe220.dll               6.1.7600.16385              Greek IBM 220 Keyboard Layout
    kbdhe319.dll               6.1.7600.16385              Greek IBM 319 Keyboard Layout
    kbdheb.dll                 6.1.7600.16385              KBDHEB Keyboard Layout
    kbdhela2.dll               6.1.7600.16385              Greek IBM 220 Latin Keyboard Layout
    kbdhela3.dll               6.1.7600.16385              Greek IBM 319 Latin Keyboard Layout
    kbdhept.dll                6.1.7600.16385              Greek_Polytonic Keyboard Layout
    kbdhu.dll                  6.1.7600.16385              Hungarian Keyboard Layout
    kbdhu1.dll                 6.1.7600.16385              Hungarian 101-key Keyboard Layout
    kbdibm02.dll               6.1.7600.16385              JP Japanese Keyboard Layout for IBM 5576-002/003
    kbdibo.dll                 6.1.7600.16385              Igbo Keyboard Layout
    kbdic.dll                  6.1.7600.16385              Icelandic Keyboard Layout
    kbdinasa.dll               6.1.7600.16385              Assamese (Inscript) Keyboard Layout
    kbdinbe1.dll               6.1.7600.16385              Bengali - Inscript (Legacy) Keyboard Layout
    kbdinbe2.dll               6.1.7600.16385              Bengali (Inscript) Keyboard Layout
    kbdinben.dll               6.1.7601.17514              Bengali Keyboard Layout
    kbdindev.dll               6.1.7600.16385              Devanagari Keyboard Layout
    kbdinguj.dll               6.1.7600.16385              Gujarati Keyboard Layout
    kbdinhin.dll               6.1.7601.17514              Hindi Keyboard Layout
    kbdinkan.dll               6.1.7601.17514              Kannada Keyboard Layout
    kbdinmal.dll               6.1.7600.16385              Malayalam Keyboard Layout Keyboard Layout
    kbdinmar.dll               6.1.7601.17514              Marathi Keyboard Layout
    kbdinori.dll               6.1.7601.17514              Oriya Keyboard Layout
    kbdinpun.dll               6.1.7600.16385              Punjabi/Gurmukhi Keyboard Layout
    kbdintam.dll               6.1.7601.17514              Tamil Keyboard Layout
    kbdintel.dll               6.1.7601.17514              Telugu Keyboard Layout
    kbdinuk2.dll               6.1.7600.16385              Inuktitut Naqittaut Keyboard Layout
    kbdir.dll                  6.1.7600.16385              Irish Keyboard Layout
    kbdit.dll                  6.1.7600.16385              Italian Keyboard Layout
    kbdit142.dll               6.1.7600.16385              Italian 142 Keyboard Layout
    kbdiulat.dll               6.1.7600.16385              Inuktitut Latin Keyboard Layout
    kbdjpn.dll                 6.1.7600.16385              JP Japanese Keyboard Layout Stub driver
    kbdkaz.dll                 6.1.7600.16385              Kazak_Cyrillic Keyboard Layout
    kbdkhmr.dll                6.1.7600.16385              Cambodian Standard Keyboard Layout
    kbdkor.dll                 6.1.7600.16385              KO Hangeul Keyboard Layout Stub driver
    kbdkyr.dll                 6.1.7600.16385              Kyrgyz Keyboard Layout
    kbdla.dll                  6.1.7600.16385              Latin-American Spanish Keyboard Layout
    kbdlao.dll                 6.1.7600.16385              Lao Standard Keyboard Layout
    kbdlk41a.dll               6.1.7601.17514              DEC LK411-AJ Keyboard Layout
    kbdlt.dll                  6.1.7600.16385              Lithuania Keyboard Layout
    kbdlt1.dll                 6.1.7601.17514              Lithuanian Keyboard Layout
    kbdlt2.dll                 6.1.7600.16385              Lithuanian Standard Keyboard Layout
    kbdlv.dll                  6.1.7600.16385              Latvia Keyboard Layout
    kbdlv1.dll                 6.1.7600.16385              Latvia-QWERTY Keyboard Layout
    kbdmac.dll                 6.1.7600.16385              Macedonian (FYROM) Keyboard Layout
    kbdmacst.dll               6.1.7600.16385              Macedonian (FYROM) - Standard Keyboard Layout
    kbdmaori.dll               6.1.7601.17514              Maori Keyboard Layout
    kbdmlt47.dll               6.1.7600.16385              Maltese 47-key Keyboard Layout
    kbdmlt48.dll               6.1.7600.16385              Maltese 48-key Keyboard Layout
    kbdmon.dll                 6.1.7601.17514              Mongolian Keyboard Layout
    kbdmonmo.dll               6.1.7600.16385              Mongolian (Mongolian Script) Keyboard Layout
    kbdne.dll                  6.1.7600.16385              Dutch Keyboard Layout
    kbdnec.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for (NEC PC-9800)
    kbdnec95.dll               6.1.7600.16385              JP Japanese Keyboard Layout for (NEC PC-9800 Windows 95)
    kbdnecat.dll               6.1.7600.16385              JP Japanese Keyboard Layout for (NEC PC-9800 on PC98-NX)
    kbdnecnt.dll               6.1.7600.16385              JP Japanese NEC PC-9800 Keyboard Layout
    kbdnepr.dll                6.1.7601.17514              Nepali Keyboard Layout
    kbdno.dll                  6.1.7600.16385              Norwegian Keyboard Layout
    kbdno1.dll                 6.1.7600.16385              Norwegian with Sami Keyboard Layout
    kbdnso.dll                 6.1.7600.16385              Sesotho sa Leboa Keyboard Layout
    kbdpash.dll                6.1.7600.16385              Pashto (Afghanistan) Keyboard Layout
    kbdpl.dll                  6.1.7600.16385              Polish Keyboard Layout
    kbdpl1.dll                 6.1.7600.16385              Polish Programmer's Keyboard Layout
    kbdpo.dll                  6.1.7601.17514              Portuguese Keyboard Layout
    kbdro.dll                  6.1.7600.16385              Romanian (Legacy) Keyboard Layout
    kbdropr.dll                6.1.7600.16385              Romanian (Programmers) Keyboard Layout
    kbdrost.dll                6.1.7600.16385              Romanian (Standard) Keyboard Layout
    kbdru.dll                  6.1.7600.16385              Russian Keyboard Layout
    kbdru1.dll                 6.1.7600.16385              Russia(Typewriter) Keyboard Layout
    kbdsf.dll                  6.1.7601.17514              Swiss French Keyboard Layout
    kbdsg.dll                  6.1.7601.17514              Swiss German Keyboard Layout
    kbdsl.dll                  6.1.7600.16385              Slovak Keyboard Layout
    kbdsl1.dll                 6.1.7600.16385              Slovak(QWERTY) Keyboard Layout
    kbdsmsfi.dll               6.1.7600.16385              Sami Extended Finland-Sweden Keyboard Layout
    kbdsmsno.dll               6.1.7600.16385              Sami Extended Norway Keyboard Layout
    kbdsn1.dll                 6.1.7600.16385              Sinhala Keyboard Layout
    kbdsorex.dll               6.1.7600.16385              Sorbian Extended Keyboard Layout
    kbdsors1.dll               6.1.7600.16385              Sorbian Standard Keyboard Layout
    kbdsorst.dll               6.1.7600.16385              Sorbian Standard (Legacy) Keyboard Layout
    kbdsp.dll                  6.1.7600.16385              Spanish Keyboard Layout
    kbdsw.dll                  6.1.7600.16385              Swedish Keyboard Layout
    kbdsw09.dll                6.1.7600.16385              Sinhala - Wij 9 Keyboard Layout
    kbdsyr1.dll                6.1.7600.16385              Syriac Standard Keyboard Layout
    kbdsyr2.dll                6.1.7600.16385              Syriac Phoenetic Keyboard Layout
    kbdtajik.dll               6.1.7601.17514              Tajik Keyboard Layout
    kbdtat.dll                 6.1.7600.16385              Tatar_Cyrillic Keyboard Layout
    kbdth0.dll                 6.1.7600.16385              Thai Kedmanee Keyboard Layout
    kbdth1.dll                 6.1.7600.16385              Thai Pattachote Keyboard Layout
    kbdth2.dll                 6.1.7600.16385              Thai Kedmanee (non-ShiftLock) Keyboard Layout
    kbdth3.dll                 6.1.7600.16385              Thai Pattachote (non-ShiftLock) Keyboard Layout
    kbdtiprc.dll               6.1.7600.16385              Tibetan (PRC) Keyboard Layout
    kbdtuf.dll                 6.1.7601.17514              Turkish F Keyboard Layout
    kbdtuq.dll                 6.1.7601.17514              Turkish Q Keyboard Layout
    kbdturme.dll               6.1.7601.17514              Turkmen Keyboard Layout
    kbdughr.dll                6.1.7600.16385              Uyghur (Legacy) Keyboard Layout
    kbdughr1.dll               6.1.7601.17514              Uyghur Keyboard Layout
    kbduk.dll                  6.1.7600.16385              United Kingdom Keyboard Layout
    kbdukx.dll                 6.1.7600.16385              United Kingdom Extended Keyboard Layout
    kbdur.dll                  6.1.7600.16385              Ukrainian Keyboard Layout
    kbdur1.dll                 6.1.7600.16385              Ukrainian (Enhanced) Keyboard Layout
    kbdurdu.dll                6.1.7600.16385              Urdu Keyboard Layout
    kbdus.dll                  6.1.7601.17514              United States Keyboard Layout
    kbdusa.dll                 6.1.7600.16385              US IBM Arabic 238_L Keyboard Layout
    kbdusl.dll                 6.1.7600.16385              Dvorak Left-Hand US English Keyboard Layout
    kbdusr.dll                 6.1.7600.16385              Dvorak Right-Hand US English Keyboard Layout
    kbdusx.dll                 6.1.7600.16385              US Multinational Keyboard Layout
    kbduzb.dll                 6.1.7600.16385              Uzbek_Cyrillic Keyboard Layout
    kbdvntc.dll                6.1.7600.16385              Vietnamese Keyboard Layout
    kbdwol.dll                 6.1.7600.16385              Wolof Keyboard Layout
    kbdyak.dll                 6.1.7600.16385              Yakut - Russia Keyboard Layout
    kbdyba.dll                 6.1.7600.16385              Yoruba Keyboard Layout
    kbdycc.dll                 6.1.7600.16385              Serbian (Cyrillic) Keyboard Layout
    kbdycl.dll                 6.1.7600.16385              Serbian (Latin) Keyboard Layout
    kd1394.dll                 6.1.7600.16385              1394 Kernel Debugger
    kdcom.dll                  6.1.7600.16385              Serial Kernel Debugger
    kdusb.dll                  6.1.7600.16385              USB 2.0 Kernel Debugger
    kerberos.dll               6.1.7601.17514                Kerberos
    kernel32.dll               6.1.7601.17514                Windows NT BASE API
    kernelbase.dll             6.1.7601.17514                Windows NT BASE API
    kernelceip.dll             6.1.7600.16385                CEIP 
    keyiso.dll                 6.1.7600.16385                 CNG
    keymgr.dll                 6.1.7600.16385                  
    kmsvc.dll                  6.1.7601.17514                
    korwbrkr.dll               6.1.7600.16385              korwbrkr
    ksuser.dll                 6.1.7600.16385              User CSA Library
    ktmw32.dll                 6.1.7600.16385              Windows KTM Win32 Client DLL
    l2gpstore.dll              6.1.7600.16385              Policy Storage dll
    l2nacp.dll                 6.1.7600.16385                 Onex Windows
    l2sechc.dll                6.1.7600.16385                    2
    langcleanupsysprepaction.dll  6.1.7600.16385              Language cleanup Sysprep action
    laprxy.dll                 12.0.7600.16385             Windows Media Logagent Proxy
    licmgr10.dll               8.0.7601.17514               (DLL)    Microsoft
    linkinfo.dll               6.1.7600.16385              Windows Volume Tracking
    listsvc.dll                6.1.7601.17514                Windows
    lltdapi.dll                6.1.7600.16385              Link-Layer Topology Mapper API
    lltdres.dll                6.1.7600.16385                 
    lltdsvc.dll                6.1.7600.16385              Link-Layer Topology Mapper Service
    lmhsvc.dll                 6.1.7600.16385               DLL   TCPIP NetBios
    loadperf.dll               6.1.7600.16385                  
    localsec.dll               6.1.7601.17514               MMC "   "
    localspl.dll               6.1.7601.17514                 
    localui.dll                6.1.7600.16385                
    locationapi.dll            6.1.7600.16385              Microsoft Windows Location API
    loghours.dll               6.1.7600.16385               
    logoncli.dll               6.1.7601.17514              Net Logon Client DLL
    lpk.dll                    6.1.7600.16385              Language Pack
    lpksetupproxyserv.dll      6.1.7600.16385              COM proxy server for lpksetup.exe
    lsasrv.dll                 6.1.7601.17514               DLL  LSA
    lscshostpolicy.dll         6.1.7601.17514              Microsoft Remote Desktop Virtual Graphics Session Licensing Host Policy
    lsmproxy.dll               6.1.7601.17514              LSM interfaces proxy Dll
    luainstall.dll             6.1.7601.17514              Lua manifest install
    lz32.dll                   6.1.7600.16385              LZ Expand/Compress API DLL
    lzexpand.dll               3.10.0.103                  Windows file expansion library
    magnification.dll          6.1.7600.16385               API  ()
    mapi32.dll                 1.0.2536.0                   MAPI 1.0  Windows NT
    mapistub.dll               1.0.2536.0                   MAPI 1.0  Windows NT
    mcewmdrmndbootstrap.dll    1.3.2302.0                  Windows Media Center WMDRM-ND Receiver Bridge Bootstrap DLL
    mciavi32.dll               6.1.7601.17514               MCI Video  Windows
    mcicda.dll                 6.1.7600.16385               MCI   cdaudio
    mciqtz32.dll               6.6.7601.17514               MCI DirectShow
    mciseq.dll                 6.1.7600.16385               MCI   MIDI
    mciwave.dll                6.1.7600.16385               MCI   
    mcmde.dll                  12.0.7601.17514             MCMDE DLL
    mcsrchph.dll               1.0.0.1                     Windows Media Center Search Protocol Handler
    mctres.dll                 6.1.7600.16385                MCT
    mcupdate_authenticamd.dll  6.1.7600.16385              AMD Microcode Update Library
    mcupdate_genuineintel.dll  6.1.7601.17514              Intel Microcode Update Library
    mcx2svc.dll                6.1.7601.17514              Media Center Extender Service
    mcxdriv.dll                6.1.7600.16385                Media Center
    mdminst.dll                6.1.7600.16385               
    mediametadatahandler.dll   6.1.7601.17514              Media Metadata Handler
    memdiag.dll                6.1.7600.16385                 
    mf.dll                     12.0.7601.17514               
    mf3216.dll                 6.1.7600.16385              32-bit to 16-bit Metafile Conversion DLL
    mfaacenc.dll               6.1.7600.16385              Media Foundation AAC Encoder
    mfc40.dll                  4.1.0.6151                    MFCDLL -  
    mfc40u.dll                 4.1.0.6151                    MFCDLL -  
    mfc42.dll                  6.6.8063.0                    MFCDLL -  
    mfc42u.dll                 6.6.8063.0                    MFCDLL -  
    mfcsubs.dll                2001.12.8530.16385          COM+
    mfds.dll                   12.0.7601.17514             Media Foundation Direct Show wrapper DLL
    mfdvdec.dll                6.1.7600.16385              Media Foundation DV Decoder
    mferror.dll                12.0.7600.16385                
    mfh264enc.dll              6.1.7600.16385              Media Foundation H264 Encoder
    mfmjpegdec.dll             6.1.7600.16385              Media Foundation MJPEG Decoder
    mfplat.dll                 12.0.7600.16385             Media Foundation Platform DLL
    mfplay.dll                 12.0.7601.17514             Media Foundation Playback API DLL
    mfps.dll                   12.0.7600.16385             Media Foundation Proxy DLL
    mfreadwrite.dll            12.0.7601.17514             Media Foundation ReadWrite DLL
    mfvdsp.dll                 6.1.7600.16385              Windows Media Foundation Video DSP Components
    mfwmaaec.dll               6.1.7600.16385              Windows Media Audio AEC for Media Foundation
    mgmtapi.dll                6.1.7600.16385              Microsoft SNMP Manager API (uses WinSNMP)
    microsoft-windows-hal-events.dll  6.1.7600.16385              Microsoft-Windows-HAL-Events Resources
    microsoft-windows-kernel-power-events.dll  6.1.7600.16385              Microsoft-Windows-Kernel-Power-Events Resources
    microsoft-windows-kernel-processor-power-events.dll  6.1.7600.16385              Microsoft-Windows-Kernel-Processor-Power-Events Resources
    midimap.dll                6.1.7600.16385              Microsoft MIDI Mapper
    migisol.dll                6.1.7601.17514              Migration System Isolation Layer
    miguiresource.dll          6.1.7600.16385               MIG wini32
    mimefilt.dll               2008.0.7601.17514            MIME
    mlang.dll                  6.1.7600.16385               DLL  
    mmcbase.dll                6.1.7600.16385                DLL MMC
    mmci.dll                   6.1.7600.16385                
    mmcico.dll                 6.1.7600.16385              Media class co-installer
    mmcndmgr.dll               6.1.7601.17514                 MMC
    mmcshext.dll               6.1.7600.16385              MMC Shell Extension DLL
    mmcss.dll                  6.1.7600.16385                 
    mmdevapi.dll               6.1.7601.17514              MMDevice API
    mmres.dll                  6.1.7600.16385               
    mmsystem.dll               3.10.0.103                  System APIs for Multimedia
    modemui.dll                6.1.7600.16385                Windows
    montr_ci.dll               6.1.7600.16385                 (Microsoft)
    moricons.dll               6.1.7600.16385              Windows NT Setup Icon Resources Library
    mp3dmod.dll                6.1.7600.16385              Microsoft MP3 Decoder DMO
    mp43decd.dll               6.1.7600.16385              Windows Media MPEG-4 Video Decoder
    mp4sdecd.dll               6.1.7600.16385              Windows Media MPEG-4 S Video Decoder
    mpg4decd.dll               6.1.7600.16385              Windows Media MPEG-4 Video Decoder
    mpr.dll                    6.1.7600.16385                   
    mprapi.dll                 6.1.7601.17514              Windows NT MP Router Administration DLL
    mprddm.dll                 6.1.7601.17514                  
    mprdim.dll                 6.1.7600.16385                
    mprmsg.dll                 6.1.7600.16385               (DLL)    
    mpssvc.dll                 6.1.7601.17514                (Microsoft)
    msaatext.dll               2.0.10413.0                 Active Accessibility text support
    msac3enc.dll               6.1.7601.17514              Microsoft AC-3 Encoder
    msacm.dll                  3.50.0.9                    Microsoft Audio Compression Manager
    msacm32.dll                6.1.7600.16385                 Microsoft
    msadce.dll                 6.1.7601.17514              OLE DB Cursor Engine
    msadcer.dll                6.1.7600.16385              OLE DB Cursor Engine Resources
    msadcf.dll                 6.1.7601.17514              Remote Data Services Data Factory
    msadcfr.dll                6.1.7600.16385              Remote Data Services Data Factory Resources
    msadco.dll                 6.1.7601.17514              Remote Data Services Data Control
    msadcor.dll                6.1.7600.16385              Remote Data Services Data Control Resources
    msadcs.dll                 6.1.7601.17514              Remote Data Services ISAPI Library
    msadds.dll                 6.1.7600.16385              OLE DB Data Shape Provider
    msaddsr.dll                6.1.7600.16385               OLE DB Data Shape Provider Resources
    msader15.dll               6.1.7600.16385              ActiveX Data Objects Resources
    msado15.dll                6.1.7601.17514              ActiveX Data Objects
    msadomd.dll                6.1.7601.17514              ActiveX Data Objects (Multi-Dimensional)
    msador15.dll               6.1.7601.17514              Microsoft ActiveX Data Objects Recordset
    msadox.dll                 6.1.7601.17514              ActiveX Data Objects Extensions
    msadrh15.dll               6.1.7600.16385              ActiveX Data Objects Rowset Helper
    msafd.dll                  6.1.7600.16385              Microsoft Windows Sockets 2.0 Service Provider
    msasn1.dll                 6.1.7601.17514              ASN.1 Runtime APIs
    msaudite.dll               6.1.7600.16385                 
    mscandui.dll               6.1.7600.16385                MSCANDUI
    mscat32.dll                6.1.7600.16385              MSCAT32 Forwarder DLL
    msclmd.dll                 6.1.7601.17514              Microsoft Class Mini-driver
    mscms.dll                  6.1.7601.17514              DLL-    
    mscoree.dll                4.0.40305.0                 Microsoft .NET Runtime Execution Engine
    mscorier.dll               2.0.50727.5420               IE    Microsoft .NET
    mscories.dll               2.0.50727.5420              Microsoft .NET IE SECURITY REGISTRATION
    mscpx32r.dll               6.1.7600.16385              ODBC Code Page Translator Resources
    mscpxl32.dll               6.1.7600.16385                 ODBC
    msctf.dll                  6.1.7600.16385                MSCTF
    msctfmonitor.dll           6.1.7600.16385              MsCtfMonitor DLL
    msctfp.dll                 6.1.7600.16385              MSCTFP Server DLL
    msctfui.dll                6.1.7600.16385                MSCTFUI
    msdadc.dll                 6.1.7600.16385              OLE DB Data Conversion Stub
    msdadiag.dll               6.1.7600.16385              Built-In Diagnostics
    msdaenum.dll               6.1.7600.16385              OLE DB Root Enumerator Stub
    msdaer.dll                 6.1.7600.16385              OLE DB Error Collection Stub
    msdaora.dll                6.1.7600.16385              OLE DB Provider for Oracle
    msdaorar.dll               6.1.7600.16385              OLE DB Provider for Oracle Resources
    msdaosp.dll                6.1.7601.17514              OLE DB Simple Provider
    msdaprsr.dll               6.1.7600.16385                OLE DB Persistence Services
    msdaprst.dll               6.1.7600.16385              OLE DB Persistence Services
    msdaps.dll                 6.1.7600.16385              OLE DB Interface Proxies/Stubs
    msdarem.dll                6.1.7601.17514              OLE DB Remote Provider
    msdaremr.dll               6.1.7600.16385              OLE DB Remote Provider Resources
    msdart.dll                 6.1.7600.16385              OLE DB Runtime Routines
    msdasc.dll                 6.1.7600.16385              OLE DB Service Components Stub
    msdasql.dll                6.1.7601.17514              OLE DB Provider for ODBC Drivers
    msdasqlr.dll               6.1.7600.16385              OLE DB Provider for ODBC Drivers Resources
    msdatl3.dll                6.1.7600.16385              OLE DB Implementation Support Routines
    msdatt.dll                 6.1.7600.16385              OLE DB Temporary Table Services
    msdaurl.dll                6.1.7600.16385              OLE DB RootBinder Stub
    msdelta.dll                6.1.7600.16385              Microsoft Patch Engine
    msdfmap.dll                6.1.7601.17514              Data Factory Handler
    msdmo.dll                  6.6.7601.17514              DMO Runtime
    msdri.dll                  6.1.7601.17514              Microsoft Digital Receiver Interface Class Driver
    msdrm.dll                  6.1.7601.17514                 Windows
    msdtckrm.dll               2001.12.8530.16385          Microsoft Distributed Transaction Coordinator OLE Transactions KTM Resource Manager DLL
    msdtclog.dll               2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Log Manager DLL
    msdtcprx.dll               2001.12.8530.16385          Microsoft Distributed Transaction Coordinator OLE Transactions Interface Proxy DLL
    msdtctm.dll                2001.12.8531.17514          Microsoft Distributed Transaction Coordinator Transaction Manager DLL
    msdtcuiu.dll               2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Administrative DLL
    msdtcvsp1res.dll           2001.12.8530.16385               Vista SP1
    msexch40.dll               4.0.9756.0                  Microsoft Jet Exchange Isam
    msexcl40.dll               4.0.9756.0                  Microsoft Jet Excel Isam
    msfeeds.dll                8.0.7601.17514              Microsoft Feeds Manager
    msfeedsbs.dll              8.0.7601.17514                 ()
    msftedit.dll               5.41.21.2510                Rich Text Edit Control, v4.1
    mshtml.dll                 8.0.7601.17514                HTML Microsoft
    mshtmled.dll               8.0.7601.17514              Microsoft HTML Editing Component
    mshtmler.dll               8.0.7600.16385                  HTML (Microsoft)
    msi.dll                    5.0.7601.17514              Windows Installer
    msicofire.dll              6.1.7600.16385                  MSI-
    msidcrl30.dll              6.1.7600.16385              IDCRL Dynamic Link Library
    msident.dll                6.1.7600.16385                (Microsoft)
    msidle.dll                 6.1.7600.16385              User Idle Monitor
    msidntld.dll               6.1.7600.16385                (Microsoft)
    msieftp.dll                6.1.7601.17514                Microsoft Internet Explorer  FTP
    msihnd.dll                 5.0.7601.17514              Windows installer
    msiltcfg.dll               5.0.7600.16385              Windows Installer Configuration API Stub
    msimg32.dll                6.1.7600.16385              GDIEXT Client DLL
    msimsg.dll                 5.0.7600.16385                 Windows
    msimtf.dll                 6.1.7600.16385              Active IMM Server DLL
    msisip.dll                 5.0.7600.16385              MSI Signature SIP Provider
    msjet40.dll                4.0.9756.0                  Microsoft Jet Engine Library
    msjetoledb40.dll           4.0.9756.0                  
    msjint40.dll               4.0.9756.0                       Microsoft Jet
    msjro.dll                  6.1.7601.17514              Jet and Replication Objects
    msjter40.dll               4.0.9756.0                  Microsoft Jet Database Engine Error DLL
    msjtes40.dll               4.0.9756.0                  Microsoft Jet Expression Service
    msls31.dll                 3.10.349.0                  Microsoft Line Services library file
    msltus40.dll               4.0.9756.0                  Microsoft Jet Lotus 1-2-3 Isam
    msmmsp.dll                 6.1.7600.16385              Mount Point Manger Sysprep Utility Library
    msmpeg2adec.dll            6.1.7140.0                  Microsoft DTV-DVD Audio Decoder
    msmpeg2enc.dll             6.1.7601.17514               Microsoft MPEG-2
    msmpeg2vdec.dll            6.1.7140.0                  Microsoft DTV-DVD Video Decoder
    msnetobj.dll               11.0.7601.17514             DRM ActiveX Network Object
    msobjs.dll                 6.1.7600.16385                 
    msoeacct.dll               6.1.7600.16385              Microsoft Internet Account Manager
    msoert2.dll                6.1.7600.16385              Microsoft Windows Mail RT Lib
    msorc32r.dll               6.1.7600.16385                ODBC  Oracle
    msorcl32.dll               6.1.7601.17514              ODBC Driver for Oracle
    mspatcha.dll               6.1.7600.16385              Microsoft File Patch Application API
    mspbda.dll                 6.1.7601.17514              Microsoft Protected Broadcast Digital Architecture Class Driver
    mspbdacoinst.dll           6.1.7600.16385              Microsoft Protected Broadcast Digital Architecture Class Driver CoInstaller
    mspbde40.dll               4.0.9756.0                  Microsoft Jet Paradox Isam
    msports.dll                6.1.7600.16385                 
    msprivs.dll                6.1.7600.16385                
    msrahc.dll                 6.1.7600.16385                 
    msrating.dll               8.0.7601.17514                   
    msrd2x40.dll               4.0.9756.0                  Microsoft (R) Red ISAM
    msrd3x40.dll               4.0.9756.0                  Microsoft (R) Red ISAM
    msrdc.dll                  6.1.7600.16385              Remote Differential Compression COM server
    msrdpwebaccess.dll         6.1.7600.16385              Microsoft Remote Desktop Services Web Access Control
    msrepl40.dll               4.0.9756.0                  Microsoft Replication Library
    msrle32.dll                6.1.7601.17514              Microsoft RLE Compressor
    msscntrs.dll               7.0.7600.16385              msscntrs.dll
    msscp.dll                  11.0.7601.17514             Windows Media Secure Content Provider
    mssha.dll                  6.1.7600.16385                  Windows
    msshavmsg.dll              6.1.7600.16385                     Windows
    msshooks.dll               7.0.7600.16385              MSSHooks.dll
    mssign32.dll               6.1.7600.16385               API  
    mssip32.dll                6.1.7600.16385              MSSIP32 Forwarder DLL
    mssitlb.dll                7.0.7600.16385              mssitlb
    mssph.dll                  7.0.7600.16385                 Microsoft
    mssphtb.dll                7.0.7601.17514              Outlook MSSearch Connector
    mssprxy.dll                7.0.7600.16385              Microsoft Search Proxy
    mssrch.dll                 7.0.7601.17514              mssrch.dll
    mssvp.dll                  7.0.7601.17514               Vista MSSearch
    msswch.dll                 6.1.7600.16385              msswch
    mstask.dll                 6.1.7601.17514                 
    mstext40.dll               4.0.9756.0                  Microsoft Jet Text Isam
    mstime.dll                 8.0.7601.17514              Microsoft (R) Timed Interactive Multimedia Extensions to HTML
    mstscax.dll                6.1.7601.17514              ActiveX-    
    msutb.dll                  6.1.7601.17514               (DLL)  MSUTB
    msv1_0.dll                 6.1.7601.17514              Microsoft Authentication Package v1.0
    msvbvm60.dll               6.0.98.15                   Visual Basic Virtual Machine
    msvcirt.dll                7.0.7600.16385              Windows NT IOStreams DLL
    msvcp60.dll                7.0.7600.16385              Windows NT C++ Runtime Library DLL
    msvcrt.dll                 7.0.7600.16385              Windows NT CRT DLL
    msvcrt20.dll               2.12.0.0                    Microsoft C Runtime Library
    msvcrt40.dll               6.1.7600.16385              VC 4.x CRT DLL (Forwarded to msvcrt.dll)
    msvfw32.dll                6.1.7601.17514               Microsoft Video  Windows
    msvidc32.dll               6.1.7601.17514                Microsoft Video 1
    msvidctl.dll               6.5.7601.17514               ActiveX  
    msvideo.dll                1.15.0.1                    Microsoft Video for Windows DLL
    mswdat10.dll               4.0.9756.0                  Microsoft Jet Sort Tables
    mswmdm.dll                 12.0.7600.16385               Windows Media Device Manager
    mswsock.dll                6.1.7601.17514                 API Microsoft Windows Sockets 2.0
    mswstr10.dll               4.0.9756.0                    Microsoft Jet
    msxactps.dll               6.1.7600.16385              OLE DB Transaction Proxies/Stubs
    msxbde40.dll               4.0.9756.0                  Microsoft Jet xBASE Isam
    msxml3.dll                 8.110.7601.17514            MSXML 3.0 SP11
    msxml3r.dll                8.110.7600.16385            XML Resources
    msxml6.dll                 6.30.7601.17514             MSXML 6.0 SP3
    msxml6r.dll                6.30.7600.16385             XML Resources
    msyuv.dll                  6.1.7601.17514              Microsoft UYVY Video Decompressor
    mtxclu.dll                 2001.12.8531.17514          Microsoft Distributed Transaction Coordinator Failover Clustering Support DLL
    mtxdm.dll                  2001.12.8530.16385          COM+
    mtxex.dll                  2001.12.8530.16385          COM+
    mtxlegih.dll               2001.12.8530.16385          COM+
    mtxoci.dll                 2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Database Support DLL for Oracle
    muifontsetup.dll           6.1.7601.17514              MUI Callback for font registry settings
    muilanguagecleanup.dll     6.1.7600.16385              MUI Callback for Language pack cleanup
    mycomput.dll               6.1.7600.16385               
    mydocs.dll                 6.1.7601.17514                 " "
    napcrypt.dll               6.1.7601.17514              NAP Cryptographic API helper
    napdsnap.dll               6.1.7601.17514               GPEdit    
    naphlpr.dll                6.1.7601.17514              NAP client config API helper
    napinsp.dll                6.1.7600.16385                    
    napipsec.dll               6.1.7600.16385                      IPSec
    napmontr.dll               6.1.7600.16385                NAP  Netsh
    nativehooks.dll            6.1.7600.16385              Microsoft Narrator Native hook handler
    naturallanguage6.dll       6.1.7601.17514              Natural Language Development Platform 6
    ncdprop.dll                6.1.7600.16385                 
    nci.dll                    6.1.7601.17514              CoInstaller: NET
    ncobjapi.dll               6.1.7600.16385              Microsoft Windows Operating System
    ncrypt.dll                 6.1.7600.16385                (Windows)
    ncryptui.dll               6.1.7601.17514               UI     Windows
    ncsi.dll                   6.1.7601.17514                 
    nddeapi.dll                6.1.7600.16385              Network DDE Share Management APIs
    ndfapi.dll                 6.1.7600.16385              API    
    ndfetw.dll                 6.1.7600.16385              Network Diagnostic Engine Event Interface
    ndfhcdiscovery.dll         6.1.7600.16385              Network Diagnostic Framework HC Discovery API
    ndiscapcfg.dll             6.1.7600.16385              NdisCap Notify Object
    ndishc.dll                 6.1.7600.16385                NDIS
    ndproxystub.dll            6.1.7600.16385              Network Diagnostic Engine Proxy/Stub
    negoexts.dll               6.1.7600.16385              NegoExtender Security Package
    netapi.dll                 3.11.0.300                  Microsoft Network Dynamic Link Library for Microsoft Windows
    netapi32.dll               6.1.7601.17514              Net Win32 API DLL
    netbios.dll                6.1.7600.16385              NetBIOS Interface Library
    netcenter.dll              6.1.7601.17514                 -  
    netcfgx.dll                6.1.7601.17514                
    netcorehc.dll              6.1.7600.16385                   
    netdiagfx.dll              6.1.7601.17514                
    netevent.dll               6.1.7600.16385                
    netfxperf.dll              4.0.40305.0                 Extensible Performance Counter Shim
    neth.dll                   6.1.7600.16385                 
    netid.dll                  6.1.7601.17514                  
    netiohlp.dll               6.1.7601.17514               DLL   Netio
    netjoin.dll                6.1.7601.17514              Domain Join DLL
    netlogon.dll               6.1.7601.17514                 Net Logon
    netman.dll                 6.1.7600.16385                
    netmsg.dll                 6.1.7600.16385                
    netplwiz.dll               6.1.7601.17514                   
    netprof.dll                6.1.7600.16385                 
    netprofm.dll               6.1.7600.16385                
    netprojw.dll               6.1.7600.16385                 
    netshell.dll               6.1.7601.17514                
    nettrace.dll               6.1.7600.16385                 
    netutils.dll               6.1.7601.17514              Net Win32 API Helpers DLL
    networkexplorer.dll        6.1.7601.17514               
    networkitemfactory.dll     6.1.7600.16385                
    networkmap.dll             6.1.7601.17514               
    newdev.dll                 6.0.5054.0                    
    nlaapi.dll                 6.1.7601.17514              Network Location Awareness 2
    nlahc.dll                  6.1.7600.16385                NLA
    nlasvc.dll                 6.1.7601.17514                   2
    nlhtml.dll                 2008.0.7600.16385            HTML
    nlmgp.dll                  6.1.7600.16385                 
    nlmsprep.dll               6.1.7600.16385              Network List Manager Sysprep Module
    nlsbres.dll                6.1.7601.17514              NLSBuild resource DLL
    nlsdata0000.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0001.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0002.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0003.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0007.dll            6.1.7600.16385              Microsoft German Natural Language Server Data and Code
    nlsdata0009.dll            6.1.7600.16385              Microsoft English Natural Language Server Data and Code
    nlsdata000a.dll            6.1.7600.16385              Microsoft Spanish Natural Language Server Data and Code
    nlsdata000c.dll            6.1.7600.16385              Microsoft French Natural Language Server Data and Code
    nlsdata000d.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata000f.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0010.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0011.dll            6.1.7600.16385              Microsoft Japanese Natural Language Server Data and Code
    nlsdata0013.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0018.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0019.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001b.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001d.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0020.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0021.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0022.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0024.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0026.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0027.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata002a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0039.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata003e.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0045.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0046.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0047.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0049.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004b.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004c.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004e.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0414.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0416.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0816.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata081a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0c1a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdl.dll                  6.1.7600.16385              Nls Downlevel DLL
    nlslexicons0001.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0002.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0003.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0007.dll        6.1.7600.16385              Microsoft German Natural Language Server Data and Code
    nlslexicons0009.dll        6.1.7600.16385              Microsoft English Natural Language Server Data and Code
    nlslexicons000a.dll        6.1.7600.16385              Microsoft Spanish Natural Language Server Data and Code
    nlslexicons000c.dll        6.1.7600.16385              Microsoft French Natural Language Server Data and Code
    nlslexicons000d.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons000f.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0010.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0011.dll        6.1.7600.16385              Microsoft Japanese Natural Language Server Data and Code
    nlslexicons0013.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0018.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0019.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001b.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001d.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0020.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0021.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0022.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0024.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0026.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0027.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons002a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0039.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons003e.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0045.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0046.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0047.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0049.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004b.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004c.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004e.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0414.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0416.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0816.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons081a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0c1a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsmodels0011.dll          6.1.7600.16385              Microsoft Japanese Natural Language Server Data and Code
    normaliz.dll               6.1.7600.16385              Unicode Normalization DLL
    npmproxy.dll               6.1.7600.16385              Network List Manager Proxy
    nrpsrv.dll                 6.1.7601.17514              Name Resolution Proxy (NRP) RPC interface
    nshhttp.dll                6.1.7600.16385               DLL netsh  HTTP
    nshipsec.dll               6.1.7601.17514               DLL  IPSec  Net
    nshwfp.dll                 6.1.7601.17514                  Windows  Netsh
    nsi.dll                    6.1.7600.16385              NSI User-mode interface DLL
    nsisvc.dll                 6.1.7600.16385              RPC-   
    ntdll.dll                  6.1.7601.17514                NT
    ntdsapi.dll                6.1.7600.16385              Active Directory Domain Services API
    ntlanman.dll               6.1.7601.17514              Microsoft LAN Manager
    ntlanui2.dll               6.1.7600.16385                  
    ntmarta.dll                6.1.7600.16385               Windows NT MARTA
    ntprint.dll                6.1.7601.17514                  
    ntshrui.dll                6.1.7601.17514               ,    
    ntvdmd.dll                 6.1.7600.16385              NTVDMD.DLL
    nvd3dum.dll                8.15.11.8593                NVIDIA Compatible Vista WDDM D3D Driver, Version 185.93 
    nvwgf2um.dll               8.15.11.8593                NVIDIA Compatible D3D10 Driver, Version 185.93 
    objsel.dll                 6.1.7600.16385                
    occache.dll                8.0.7601.17514                  
    ocsetapi.dll               6.1.7601.17514              Windows Optional Component Setup API
    odbc16gt.dll               3.510.3711.0                Microsoft ODBC Driver Generic Thunk
    odbc32.dll                 6.1.7601.17514              ODBC Driver Manager
    odbc32gt.dll               6.1.7600.16385              ODBC Driver Generic Thunk
    odbcbcp.dll                6.1.7600.16385              BCP for ODBC
    odbcconf.dll               6.1.7601.17514              ODBC Driver Configuration Program
    odbccp32.dll               6.1.7601.17514              ODBC Installer
    odbccr32.dll               6.1.7600.16385              ODBC Cursor Library
    odbccu32.dll               6.1.7600.16385              ODBC Cursor Library
    odbcint.dll                6.1.7600.16385              ODBC Resources
    odbcji32.dll               6.1.7600.16385              Microsoft ODBC Desktop Driver Pack 3.5
    odbcjt32.dll               6.1.7601.17514              Microsoft ODBC Desktop Driver Pack 3.5
    odbctrac.dll               6.1.7601.17514              ODBC Driver Manager Trace
    oddbse32.dll               6.1.7600.16385              ODBC (3.0) driver for DBase
    odexl32.dll                6.1.7600.16385              ODBC (3.0) driver for Excel
    odfox32.dll                6.1.7600.16385              ODBC (3.0) driver for FoxPro
    odpdx32.dll                6.1.7600.16385              ODBC (3.0) driver for Paradox
    odtext32.dll               6.1.7600.16385              ODBC (3.0) driver for text files
    offfilt.dll                2008.0.7600.16385            OFFICE
    ogldrv.dll                 6.1.7600.16385              MSOGL
    ole2.dll                   2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    ole2disp.dll               2.10.3050.1                 OLE 2.1 16/32 Interoperability Library
    ole2nls.dll                2.10.3050.1                 OLE 2.1 16/32 Interoperability Library
    ole32.dll                  6.1.7601.17514              Microsoft OLE   Windows
    oleacc.dll                 7.0.0.0                     Active Accessibility Core Component
    oleacchooks.dll            7.0.0.0                     Active Accessibility Event Hooks Library
    oleaccrc.dll               7.0.0.0                     Active Accessibility Resource DLL
    oleaut32.dll               6.1.7601.17514              
    olecli.dll                 1.32.0.0                    Object Linking and Embedding Client Library
    olecli32.dll               6.1.7600.16385                OLE
    oledb32.dll                6.1.7601.17514              OLE DB Core Services
    oledb32r.dll               6.1.7600.16385                 OLE DB
    oledlg.dll                 6.1.7600.16385                 OLE
    oleprn.dll                 6.1.7600.16385              Oleprn DLL
    olepro32.dll               6.1.7601.17514              
    oleres.dll                 6.1.7600.16385                OLE
    olesvr.dll                 1.11.0.0                    Object Linking and Embedding Server Library
    olesvr32.dll               6.1.7600.16385              Object Linking and Embedding Server Library
    olethk32.dll               6.1.7601.17514              Microsoft OLE for Windows
    onex.dll                   6.1.7601.17514                IEEE 802.1X
    onexui.dll                 6.1.7601.17514                 IEEE 802.1X
    onlineidcpl.dll            6.1.7601.17514                -  
    oobefldr.dll               6.1.7601.17514                
    opcservices.dll            6.1.7601.17514              Native Code OPC Services Library
    opengl32.dll               6.1.7600.16385              OpenGL Client DLL
    osbaseln.dll               6.1.7600.16385              Service Reporting API
    osuninst.dll               6.1.7600.16385              Uninstall Interface
    p2p.dll                    6.1.7600.16385                
    p2pcollab.dll              6.1.7600.16385                  
    p2pgraph.dll               6.1.7600.16385              Peer-to-Peer Graphing
    p2pnetsh.dll               6.1.7600.16385                 NetSh
    p2psvc.dll                 6.1.7600.16385               
    packager.dll               6.1.7600.16385               2
    panmap.dll                 6.1.7600.16385              PANOSE(tm) Font Mapper
    pautoenr.dll               6.1.7600.16385                
    pcadm.dll                  6.1.7600.16385              Program Compatibility Assistant Diagnostic Module
    pcaevts.dll                6.1.7600.16385                   
    pcasvc.dll                 6.1.7600.16385                  
    pcaui.dll                  6.1.7600.16385                  
    pcwum.dll                  6.1.7600.16385              Performance Counters for Windows Native DLL
    pcwutl.dll                 6.1.7600.16385                     
    pdh.dll                    6.1.7601.17514                  Windows
    pdhui.dll                  6.1.7601.17514                
    peerdist.dll               6.1.7600.16385                BranchCache
    peerdisthttptrans.dll      6.1.7600.16385              BranchCache HTTP Tansport
    peerdistsh.dll             6.1.7600.16385                BranchCache Netshell
    peerdistsvc.dll            6.1.7600.16385               BranchCache
    peerdistwsddiscoprov.dll   6.1.7600.16385              BranchCache WSD Discovery Provider
    perfcentercpl.dll          6.1.7601.17514               
    perfctrs.dll               6.1.7600.16385               
    perfdisk.dll               6.1.7600.16385                  Windows
    perfnet.dll                6.1.7600.16385                   Windows
    perfos.dll                 6.1.7600.16385                  Windows
    perfproc.dll               6.1.7600.16385                   Windows
    perftrack.dll              6.1.7600.16385              Microsoft Performance PerfTrack
    perfts.dll                 6.1.7601.17514              Windows Remote Desktop Services Performance Objects
    photometadatahandler.dll   6.1.7600.16385              Photo Metadata Handler
    photowiz.dll               6.1.7601.17514                
    pid.dll                    6.1.7600.16385              Microsoft PID
    pidgenx.dll                6.1.7600.16385              Pid Generation
    pifmgr.dll                 6.1.7601.17514              Windows NT PIF Manager Icon Resources Library
    pku2u.dll                  6.1.7600.16385              Pku2u Security Package
    pla.dll                    6.1.7601.17514                 
    playsndsrv.dll             6.1.7600.16385               PlaySound
    pmcsnap.dll                6.1.7600.16385              pmcsnap dll
    pmspl.dll                  2.10.0.1                    Microsoft LAN Manager 2.1 Network Dynamic Link Library for Microsoft Windows
    pngfilt.dll                8.0.7600.16385              IE PNG plugin image decoder
    pnidui.dll                 6.1.7601.17514                
    pnpsetup.dll               6.1.7600.16385              Pnp installer for CMI
    pnpts.dll                  6.1.7600.16385              PlugPlay Troubleshooter
    pnpui.dll                  5.2.3668.0                  DLL    
    pnpxassoc.dll              6.1.7600.16385              PNPX Association Dll
    pnpxassocprx.dll           6.1.7600.16385                PNPX
    pnrpauto.dll               6.1.7600.16385               DLL   PNRP
    pnrphc.dll                 6.1.7600.16385                 PNRP
    pnrpnsp.dll                6.1.7600.16385                 PNRP
    pnrpsvc.dll                6.1.7600.16385                PNRP
    polstore.dll               6.1.7600.16385              Policy Storage dll
    portabledeviceapi.dll      6.1.7601.17514               API    Windows
    portabledeviceclassextension.dll  6.1.7600.16385              Windows Portable Device Class Extension Component
    portabledeviceconnectapi.dll  6.1.7600.16385              Portable Device Connection API Components
    portabledevicestatus.dll   6.1.7601.17514                  Microsoft Windows
    portabledevicesyncprovider.dll  6.1.7601.17514                 Microsoft Windows
    portabledevicetypes.dll    6.1.7600.16385              Windows Portable Device (Parameter) Types Component
    portabledevicewiacompat.dll  6.1.7600.16385              PortableDevice WIA Compatibility Driver
    portabledevicewmdrm.dll    6.1.7600.16385              Windows Portable Device WMDRM Component
    pots.dll                   6.1.7600.16385               
    powercpl.dll               6.1.7601.17514                
    powrprof.dll               6.1.7600.16385              DLL     
    ppcsnap.dll                6.1.7600.16385              ppcsnap DLL
    presentationcffrasterizernative_v0300.dll  3.0.6920.4902               WinFX OpenType/CFF Rasterizer
    presentationhostproxy.dll  4.0.40305.0                 Windows Presentation Foundation Host Proxy
    presentationnative_v0300.dll  3.0.6920.4902               PresentationNative_v0300.dll
    prflbmsg.dll               6.1.7600.16385                  
    printfilterpipelineprxy.dll  6.1.7600.16385              Print Filter Pipeline Proxy
    printisolationproxy.dll    6.1.7601.17514              Print Sandbox COM Proxy Stub
    printui.dll                6.1.7601.17514                 
    prncache.dll               6.1.7601.17514              Print UI Cache
    prnfldr.dll                6.1.7601.17514              prnfldr dll
    prnntfy.dll                6.1.7600.16385              prnntfy DLL
    prntvpt.dll                6.1.7601.17514              Print Ticket Services Module
    procinst.dll               6.1.7600.16385                
    profapi.dll                6.1.7600.16385              User Profile Basic API
    profprov.dll               6.1.7601.17514              User Profile WMI Provider
    profsvc.dll                6.1.7601.17514              ProfSvc
    propsys.dll                7.0.7601.17514                 (Microsoft)
    provsvc.dll                6.1.7601.17514                Windows
    provthrd.dll               6.1.7600.16385              WMI Provider Thread & Log Library
    psapi.dll                  6.1.7600.16385              Process Status Helper
    psbase.dll                 6.1.7600.16385                
    pshed.dll                  6.1.7600.16385                ,   
    psisdecd.dll               6.6.7600.16385              Microsoft SI/PSI parser for MPEG2 based networks.
    pstorec.dll                6.1.7600.16385              Protected Storage COM interfaces
    pstorsvc.dll               6.1.7600.16385              Protected storage server
    puiapi.dll                 6.1.7600.16385               DLL puiapi
    puiobj.dll                 6.1.7601.17514               DLL  PrintUI
    pwrshplugin.dll            6.1.7600.16385              pwrshplugin.dll
    qagent.dll                 6.1.7601.17514                
    qagentrt.dll               6.1.7601.17514                  
    qasf.dll                   12.0.7601.17514             DirectShow ASF Support
    qcap.dll                   6.6.7601.17514                DirecxX DirectShow.
    qcliprov.dll               6.1.7601.17514               WMI   
    qdv.dll                    6.6.7601.17514                DirecxX DirectShow.
    qdvd.dll                   6.6.7601.17514              DirectShow DVD PlayBack Runtime.
    qedit.dll                  6.6.7601.17514               DirectShow
    qedwipes.dll               6.6.7600.16385              DirectShow Editing SMPTE Wipes
    qmgr.dll                   7.5.7601.17514                 
    qmgrprxy.dll               7.5.7600.16385              Background Intelligent Transfer Service Proxy
    qshvhost.dll               6.1.7601.17514                SHV
    qsvrmgmt.dll               6.1.7601.17514                
    quartz.dll                 6.6.7601.17514                DirecxX DirectShow.
    query.dll                  6.1.7601.17514                  
    qutil.dll                  6.1.7601.17514                
    qwave.dll                  6.1.7600.16385              Windows NT
    racengn.dll                6.1.7601.17514                  
    racpldlg.dll               6.1.7600.16385                 
    radardt.dll                6.1.7600.16385                   Windows
    radarrs.dll                6.1.7600.16385                   Microsoft Windows
    rasadhlp.dll               6.1.7600.16385              Remote Access AutoDial Helper
    rasapi32.dll               6.1.7600.16385              Remote Access API
    rasauto.dll                6.1.7600.16385                   
    rascfg.dll                 6.1.7600.16385                RAS
    raschap.dll                6.1.7601.17514                 PPP CHAP
    rasctrs.dll                6.1.7600.16385                     Windows NT
    rasdiag.dll                6.1.7600.16385                  RAS
    rasdlg.dll                 6.1.7600.16385              API     
    rasgcw.dll                 6.1.7600.16385                RAS
    rasman.dll                 6.1.7600.16385              Remote Access Connection Manager
    rasmans.dll                6.1.7601.17514                 
    rasmbmgr.dll               6.1.7600.16385                 VPN -         .
    rasmm.dll                  6.1.7600.16385                RAS
    rasmontr.dll               6.1.7600.16385                RAS
    rasmxs.dll                 6.1.7600.16385              Remote Access Device DLL for modems, PADs and switches
    rasplap.dll                6.1.7600.16385                 RAS PLAP
    rasppp.dll                 6.1.7601.17514              Remote Access PPP
    rasser.dll                 6.1.7600.16385              Remote Access Media DLL for COM ports
    rastapi.dll                6.1.7601.17514              Remote Access TAPI Compliance Layer
    rastls.dll                 6.1.7601.17514                 PPP EAP-TLS
    rdpcfgex.dll               6.1.7601.17514                  ,       ,   RDP
    rdpcore.dll                6.1.7601.17514              RDP Core DLL
    rdpcorekmts.dll            6.1.7601.17514               DLL RDPCore TS (KM)
    rdpcorets.dll              6.1.7601.17514               DLL RDPCore  
    rdpd3d.dll                 6.1.7601.17514              RDP Direct3D Remoting DLL
    rdpdd.dll                  6.1.7601.17514              RDP Display Driver
    rdpencdd.dll               6.1.7601.17514              RDP Encoder Mirror Driver
    rdpencom.dll               6.1.7601.17514              RDPSRAPI COM Objects
    rdpendp.dll                6.1.7601.17514                 RDP
    rdprefdd.dll               6.1.7601.17514              Microsoft RDP Reflector Display Driver
    rdprefdrvapi.dll           6.1.7601.17514              Reflector Driver API
    rdpudd.dll                 6.1.7601.17514              UMRDP Display Driver
    rdpwsx.dll                 6.1.7601.17514              RDP Extension DLL
    reagent.dll                6.1.7601.17514               DLL   Microsoft Windows
    recovery.dll               6.1.7601.17514                
    regapi.dll                 6.1.7601.17514              Registry Configuration APIs
    regctrl.dll                6.1.7600.16385              RegCtrl
    regidle.dll                6.1.7600.16385                 RegIdle
    regsvc.dll                 6.1.7600.16385                 
    remotepg.dll               6.1.7601.17514              CPL-  
    resampledmo.dll            6.1.7600.16385              Windows Media Resampler
    resutils.dll               6.1.7601.17514              Microsoft Cluster Resource Utility DLL
    rgb9rast.dll               6.1.7600.16385              Microsoft Windows Operating System
    riched20.dll               5.31.23.1230                Rich Text Edit Control, v3.1
    riched32.dll               6.1.7601.17514              Wrapper Dll for Richedit 1.0
    rnr20.dll                  6.1.7600.16385              Windows Socket2 NameSpace DLL
    rpcdiag.dll                6.1.7600.16385              RPC Diagnostics
    rpcepmap.dll               6.1.7600.16385                 RPC

    rpchttp.dll                6.1.7601.17514              RPC HTTP DLL
    rpcndfp.dll                1.0.0.1                        RPC NDF
    rpcns4.dll                 6.1.7600.16385                    (RPC)
    rpcnsh.dll                 6.1.7600.16385                RPC Netshell
    rpcrt4.dll                 6.1.7601.17514                 
    rpcrtremote.dll            6.1.7601.17514              Remote RPC Extension
    rpcss.dll                  6.1.7601.17514              Distributed COM Services
    rsaenh.dll                 6.1.7600.16385              Microsoft Enhanced Cryptographic Provider
    rshx32.dll                 6.1.7600.16385                
    rstrtmgr.dll               6.1.7600.16385               
    rtffilt.dll                2008.0.7600.16385            RTF
    rtm.dll                    6.1.7600.16385                
    rtutils.dll                6.1.7601.17514              Routing Utilities
    samcli.dll                 6.1.7601.17514              Security Accounts Manager Client DLL
    samlib.dll                 6.1.7600.16385              SAM Library DLL
    sampleres.dll              6.1.7600.16385               (Microsoft)
    samsrv.dll                 6.1.7601.17514                  
    sas.dll                    6.1.7600.16385              WinLogon Software SAS Library
    sbe.dll                    6.6.7601.17514              DirectShow Stream Buffer Filter.
    sbeio.dll                  12.0.7600.16385             Stream Buffer IO DLL
    sberes.dll                 6.6.7600.16385                  DirectShow.
    scansetting.dll            6.1.7601.17514                    Microsoft Windows(TM)
    scarddlg.dll               6.1.7600.16385              SCardDlg -   -
    scardsvr.dll               6.1.7600.16385                 -
    scavengeui.dll             6.1.7601.17514                
    sccls.dll                  6.1.7600.16385               DLL    -
    scecli.dll                 6.1.7601.17514                 
    scesrv.dll                 6.1.7601.17514                
    scext.dll                  6.1.7600.16385                DLL      minwin-
    schannel.dll               6.1.7601.17514              TLS / SSL Security Provider
    schedcli.dll               6.1.7601.17514              Scheduler Service Client DLL
    schedsvc.dll               6.1.7601.17514                
    scksp.dll                  6.1.7600.16385              Microsoft Smart Card Key Storage Provider
    scripto.dll                6.6.7600.16385              Microsoft ScriptO
    scrobj.dll                 5.8.7600.16385              Windows  Script Component Runtime
    scrptadm.dll               6.1.7601.17514                
    scrrun.dll                 5.8.7600.16385              Microsoft  Script Runtime
    sdautoplay.dll             6.1.7600.16385                  Microsoft Windows
    sdcpl.dll                  6.1.7601.17514                  
    sdengin2.dll               6.1.7601.17514                Microsoft Windows
    sdhcinst.dll               6.1.7600.16385              Secure Digital Host Controller Class Installer
    sdiageng.dll               6.1.7600.16385                 
    sdiagprv.dll               6.1.7600.16385              API    Windows
    sdiagschd.dll              6.1.7600.16385                 
    sdohlp.dll                 6.1.7600.16385                 SDO NPS
    sdrsvc.dll                 6.1.7601.17514                Microsoft Windows
    sdshext.dll                6.1.7600.16385                 Microsoft Windows
    searchfolder.dll           6.1.7601.17514              SearchFolder
    sechost.dll                6.1.7600.16385              Host for SCM/SDDL/LSA Lookup APIs
    seclogon.dll               6.1.7600.16385              DLL   
    secproc.dll                6.1.7601.17514              Windows Rights Management Desktop Security Processor
    secproc_isv.dll            6.1.7601.17514              Windows Rights Management Desktop Security Processor
    secproc_ssp.dll            6.1.7601.17514              Windows Rights Management Services Server Security Processor
    secproc_ssp_isv.dll        6.1.7601.17514              Windows Rights Management Services Server Security Processor (Pre-production)
    secur32.dll                6.1.7601.17514              Security Support Provider Interface
    security.dll               6.1.7600.16385              Security Support Provider Interface
    sendmail.dll               6.1.7600.16385               
    sens.dll                   6.1.7600.16385                   (SENS)
    sensapi.dll                6.1.7600.16385              SENS Connectivity API DLL
    sensorsapi.dll             6.1.7600.16385              Sensor API
    sensorsclassextension.dll  6.1.7600.16385              Sensor Driver Class Extension component
    sensorscpl.dll             6.1.7601.17514                "    "
    sensrsvc.dll               6.1.7600.16385                  Microsoft Windows
    serialui.dll               6.1.7600.16385                
    serwvdrv.dll               6.1.7600.16385                Unimodem
    sessenv.dll                6.1.7601.17514                   
    setbcdlocale.dll           6.1.7601.17514              MUI Callback for Bcd
    setupapi.dll               6.1.7601.17514              Windows Setup API
    setupcln.dll               6.1.7601.17514                
    setupetw.dll               6.1.7600.16385                  Windows  
    sfc.dll                    6.1.7600.16385              Windows File Protection
    sfc_os.dll                 6.1.7600.16385              Windows File Protection
    shacct.dll                 6.1.7601.17514              Shell Accounts Classes
    sharemediacpl.dll          6.1.7601.17514                    
    shdocvw.dll                6.1.7601.17514                    
    shell.dll                  3.10.0.103                  Windows Shell library
    shell32.dll                6.1.7601.17514                 Windows
    shellstyle.dll             6.1.7600.16385              Windows Shell Style Resource Dll
    shfolder.dll               6.1.7600.16385              Shell Folder Service
    shgina.dll                 6.1.7601.17514              Windows Shell User Logon
    shimeng.dll                6.1.7600.16385              Shim Engine DLL
    shimgvw.dll                6.1.7601.17514               
    shlwapi.dll                6.1.7601.17514                 
    shpafact.dll               6.1.7600.16385              Windows Shell LUA/PA Elevation Factory Dll
    shsetup.dll                6.1.7601.17514              Shell setup helper
    shsvcs.dll                 6.1.7601.17514               DLL   Windows
    shunimpl.dll               6.1.7601.17514              Windows Shell Obsolete APIs
    shwebsvc.dll               6.1.7601.17514              -  Windows
    signdrv.dll                6.1.7600.16385              WMI provider for Signed Drivers
    sisbkup.dll                6.1.7601.17514              Single-Instance Store Backup Support Functions
    slc.dll                    6.1.7600.16385              Software Licensing Client DLL
    slcext.dll                 6.1.7600.16385              Software Licensing Client Extension Dll
    slwga.dll                  6.1.7601.17514              Software Licensing WGA API
    smartcardcredentialprovider.dll  6.1.7601.17514                 - Windows
    smbhelperclass.dll         1.0.0.1                        SMB (   )    
    smiengine.dll              6.1.7601.17514              WMI Configuration Core
    sndvolsso.dll              6.1.7601.17514               SCA 
    snmpapi.dll                6.1.7600.16385              SNMP Utility Library
    sntsearch.dll              6.1.7600.16385               DLL  
    softkbd.dll                6.1.7600.16385                  
    softpub.dll                6.1.7600.16385              Softpub Forwarder DLL
    sortserver2003compat.dll   6.1.7600.16385              Sort Version Server 2003
    sortwindows6compat.dll     6.1.7600.16385              Sort Version Windows 6.0
    spbcd.dll                  6.1.7601.17514              BCD Sysprep Plugin
    spcmsg.dll                 6.1.7600.16385               Dll    
    sperror.dll                6.1.7600.16385                
    spfileq.dll                6.1.7600.16385              Windows SPFILEQ
    spinf.dll                  6.1.7600.16385              Windows SPINF
    spnet.dll                  6.1.7600.16385              Net Sysprep Plugin
    spoolss.dll                6.1.7600.16385              Spooler SubSystem DLL
    spopk.dll                  6.1.7601.17514              OPK Sysprep Plugin
    spp.dll                    6.1.7601.17514                  Microsoft Windows
    sppc.dll                   6.1.7601.17514              Software Licensing Client DLL
    sppcc.dll                  6.1.7600.16385                  
    sppcext.dll                6.1.7600.16385              Software Protection Platform Client Extension Dll
    sppcomapi.dll              6.1.7601.17514                 
    sppcommdlg.dll             6.1.7600.16385              API     
    sppinst.dll                6.1.7601.17514              SPP CMI Installer Plug-in DLL
    sppnp.dll                  6.1.7601.17514              PnP- SysPrep
    sppobjs.dll                6.1.7601.17514              Software Protection Platform Plugins
    sppuinotify.dll            6.1.7601.17514                SPP
    sppwinob.dll               6.1.7601.17514              Software Protection Platform Windows Plugin
    sppwmi.dll                 6.1.7600.16385              Software Protection Platform WMI provider
    spwinsat.dll               6.1.7600.16385              WinSAT Sysprep Plugin
    spwizeng.dll               6.1.7601.17514              Setup Wizard Framework
    spwizimg.dll               6.1.7600.16385              Setup Wizard Framework Resources
    spwizres.dll               6.1.7601.17514                 
    spwizui.dll                6.1.7601.17514               UI SPC
    spwmp.dll                  6.1.7601.17514              Windows Media Player System Preparation DLL
    sqlceoledb30.dll           3.0.7600.0                  Microsoft SQL Mobile
    sqlceqp30.dll              3.0.7600.0                  Microsoft SQL Mobile
    sqlcese30.dll              3.0.7601.0                  Microsoft SQL Mobile
    sqloledb.dll               6.1.7601.17514              OLE DB Provider for SQL Server
    sqlsrv32.dll               6.1.7601.17514              SQL Server ODBC Driver
    sqlunirl.dll               2000.80.728.0               String Function .DLL for SQL Enterprise Components
    sqlwid.dll                 1999.10.20.0                Unicode Function .DLL for SQL Enterprise Components
    sqlwoa.dll                 1999.10.20.0                Unicode/ANSI Function .DLL for SQL Enterprise Components
    sqlxmlx.dll                6.1.7600.16385              XML extensions for SQL Server
    sqmapi.dll                 6.1.7601.17514              SQM Client
    srchadmin.dll              7.0.7601.17514               
    srclient.dll               6.1.7600.16385              Microsoft Windows System Restore Client Library
    srcore.dll                 6.1.7601.17514                  Microsoft Windows
    srhelper.dll               6.1.7600.16385              Microsoft Windows driver and windows update enumeration library
    srpuxnativesnapin.dll      6.1.7600.16385                     
    srrstr.dll                 6.1.7601.17514                  Microsoft Windows
    srvcli.dll                 6.1.7601.17514              Server Service Client DLL
    srvsvc.dll                 6.1.7601.17514               (DLL)    
    srwmi.dll                  6.1.7600.16385              Microsoft Windows System Restore WMI Provider
    sscore.dll                 6.1.7601.17514               DLL-  
    ssdpapi.dll                6.1.7600.16385              SSDP Client API DLL
    ssdpsrv.dll                6.1.7600.16385               DLL  SSDP
    sspicli.dll                6.1.7601.17514              Security Support Provider Interface
    sspisrv.dll                6.1.7601.17514              LSA SSPI RPC interface DLL
    ssshim.dll                 6.1.7600.16385              Windows Componentization Platform Servicing API
    sstpsvc.dll                6.1.7600.16385                 SSTP        VPN.
    stclient.dll               2001.12.8530.16385          COM+ Configuration Catalog Client
    sti.dll                    6.1.7600.16385                   
    sti_ci.dll                 6.1.7600.16385                 
    stobject.dll               6.1.7601.17514                 Systray
    storage.dll                2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    storagecontexthandler.dll  6.1.7600.16385                   
    storprop.dll               6.1.7600.16385                  
    streamci.dll               6.1.7600.16385              Streaming Device Class Installer
    structuredquery.dll        7.0.7601.17514              Structured Query
    sud.dll                    6.1.7601.17514                SUD
    swprv.dll                  6.1.7600.16385                 Microsoft Volume Shadow Copy Service
    sxproxy.dll                6.1.7600.16385                  Microsoft Windows
    sxs.dll                    6.1.7601.17514              Fusion 2.5
    sxshared.dll               6.1.7600.16385              Microsoft Windows SX Shared Library
    sxssrv.dll                 6.1.7600.16385              Windows SxS Server DLL
    sxsstore.dll               6.1.7600.16385              Sxs Store DLL
    synccenter.dll             6.1.7601.17514                
    synceng.dll                6.1.7600.16385              Windows Briefcase Engine
    synchostps.dll             6.1.7600.16385              Proxystub for sync host
    syncinfrastructure.dll     6.1.7600.16385                Microsoft Windows.
    syncinfrastructureps.dll   6.1.7600.16385              Microsoft Windows sync infrastructure proxy stub.
    syncreg.dll                2007.94.7600.16385          Microsoft Synchronization Framework Registration
    syncui.dll                 6.1.7601.17514               Windows
    sysclass.dll               6.1.7601.17514                 
    sysfxui.dll                6.1.7600.16385                   
    sysmain.dll                6.1.7601.17514                Superfetch
    sysntfy.dll                6.1.7600.16385              Windows Notifications Dynamic Link Library
    sysprepmce.dll             6.1.7600.16385              Windows Media Center SysPrep DLL
    syssetup.dll               6.1.7601.17514              Windows NT System Setup
    systemcpl.dll              6.1.7601.17514              CPL 
    t2embed.dll                6.1.7601.17514              Microsoft T2Embed Font Embedding
    tabbtn.dll                 6.1.7600.16385                  (Microsoft)
    tabbtnex.dll               6.1.7600.16385              Microsoft Tablet PC Extended Buttons Component
    tabsvc.dll                 6.1.7601.17514                  (Microsoft)
    tapi.dll                   3.10.0.103                  Microsoft Windows(TM) Telephony Server16
    tapi3.dll                  6.1.7600.16385              Microsoft TAPI3
    tapi32.dll                 6.1.7600.16385               API  Microsoft Windows
    tapilua.dll                6.1.7600.16385              Microsoft Windows(TM) Phone And Modem Lua Elevation Dll
    tapimigplugin.dll          6.1.7600.16385              Microsoft Windows(TM) TAPI Migration Plugin Dll
    tapiperf.dll               6.1.7600.16385              Microsoft Windows(TM) Telephony Performance Monitor
    tapisrv.dll                6.1.7601.17514                 Microsoft Windows
    tapisysprep.dll            6.1.7600.16385              Microsoft Windows(TM) Telephony Sysprep Work
    tapiui.dll                 6.1.7600.16385               DLL   Microsoft Windows
    taskbarcpl.dll             6.1.7601.17514                -  
    taskcomp.dll               6.1.7601.17514                  
    taskschd.dll               6.1.7601.17514              Task Scheduler COM API
    taskschdps.dll             6.1.7600.16385              Task Scheduler Interfaces Proxy
    tbs.dll                    6.1.7600.16385              TBS
    tbssvc.dll                 6.1.7600.16385               TBS
    tcpipcfg.dll               6.1.7601.17514                
    tcpmib.dll                 6.1.7600.16385              Standard TCP/IP Port Monitor Helper DLL
    tcpmon.dll                 6.1.7600.16385                 TCP/IP
    tcpmonui.dll               6.1.7600.16385                  TCP/IP
    tdh.dll                    6.1.7600.16385                 
    termmgr.dll                6.1.7601.17514              Microsoft TAPI3 Terminal Manager
    termsrv.dll                6.1.7601.17514                  ,       
    thawbrkr.dll               6.1.7600.16385              Thai Word Breaker
    themecpl.dll               6.1.7601.17514              CPL 
    themeservice.dll           6.1.7600.16385               DLL    Windows
    themeui.dll                6.1.7601.17514              API   Windows
    thumbcache.dll             6.1.7601.17514                
    timedatemuicallback.dll    6.1.7600.16385              Time Date Control UI Language Change plugin
    tlscsp.dll                 6.1.7601.17514              Microsoft Remote Desktop Services Cryptographic Utility
    toolhelp.dll               3.10.0.103                  Windows Debug/Tool helper library
    tpmcompc.dll               6.1.7600.16385                
    tquery.dll                 7.0.7601.17514              tquery.dll
    traffic.dll                6.1.7600.16385              Microsoft Traffic Control 1.0 DLL
    trapi.dll                  6.1.7601.17514              Microsoft Narrator Text Renderer
    trkwks.dll                 6.1.7600.16385                 
    tsbyuv.dll                 6.1.7601.17514              Toshiba Video Codec
    tscfgwmi.dll               6.1.7601.17514              Remote Desktop Session Host Server Configuration WMI provider
    tschannel.dll              6.1.7600.16385              Task Scheduler Proxy
    tsddd.dll                  6.1.7600.16385              Framebuffer Display Driver
    tserrredir.dll             6.1.7600.16385              Remote Desktop Services Logon Error Redirector
    tsgqec.dll                 6.1.7601.17514                      
    tsmf.dll                   6.1.7601.17514                MF    
    tspkg.dll                  6.1.7601.17514              Web Service Security Package
    tspnprdrcoinstaller.dll    6.1.7600.16385              Remote Desktop PnP Redirected Device Co-Installer
    tspubwmi.dll               6.1.7601.17514              Remote Desktop Programs WMI provider
    tssrvlic.dll               6.1.7601.17514              RD Server Licensing Policy Module
    tsusbgdcoinstaller.dll     6.1.7601.17514                 USB   
    tsusbredirectiongrouppolicyextension.dll  6.1.7601.17514                GP USB   
    tsworkspace.dll            6.1.7601.17514                      RemoteApp
    tvratings.dll              6.6.7600.16385              Module for managing TV ratings
    twext.dll                  6.1.7601.17514              :  
    txflog.dll                 2001.12.8530.16385          COM+
    txfw32.dll                 6.1.7600.16385              TxF Win32 DLL
    typelib.dll                2.10.3029.1                 OLE 2.1 16/32 Interoperability Library
    tzres.dll                  6.1.7601.17514               DLL   
    ubpm.dll                   6.1.7600.16385               DLL    
    ucmhc.dll                  6.1.7600.16385                 UCM
    udhisapi.dll               6.1.7600.16385              UPnP Device Host ISAPI Extension
    udwm.dll                   6.1.7600.16385                  
    uexfat.dll                 6.1.7600.16385              eXfat Utility DLL
    ufat.dll                   6.1.7600.16385              FAT Utility DLL
    uianimation.dll            6.1.7600.16385              Windows Animation Manager
    uiautomationcore.dll       7.0.0.0                        Microsoft UI
    uicom.dll                  6.1.7600.16385              Add/Remove Modems
    uihub.dll                  6.1.7600.16385                     (Microsoft)
    uiribbon.dll               6.1.7601.17514                Windows
    uiribbonres.dll            6.1.7601.17514              Windows Ribbon Framework Resources
    ulib.dll                   6.1.7600.16385              DLL   
    umb.dll                    6.1.7601.17514              User Mode Bus Driver Interface Dll
    umdmxfrm.dll               6.1.7600.16385              Unimodem Tranform Module
    umpnpmgr.dll               6.1.7601.17514                  (Plug-and-Play)
    umpo.dll                   6.1.7601.17514                 
    umrdp.dll                  6.1.7601.17514                    
    unattend.dll               6.1.7601.17514              Unattend Library
    unimdmat.dll               6.1.7601.17514              - AT   Unimodem
    uniplat.dll                6.1.7600.16385              Unimodem AT Mini Driver Platform Driver for Windows NT
    unrar.dll                  4.0.100.60                  
    untfs.dll                  6.1.7601.17514              NTFS Utility DLL
    upnp.dll                   6.1.7601.17514              API   UPnP
    upnphost.dll               6.1.7600.16385                PNP-
    ureg.dll                   6.1.7600.16385              Registry Utility DLL
    url.dll                    8.0.7600.16385              Internet Shortcut Shell Extension DLL
    urlmon.dll                 8.0.7601.17514               OLE32  Win32
    usbceip.dll                6.1.7600.16385               USBCEIP
    usbmon.dll                 6.1.7600.16385              Standard Dynamic Printing Port Monitor DLL
    usbperf.dll                6.1.7600.16385               DLL   USB
    usbui.dll                  6.1.7600.16385              USB UI Dll
    user32.dll                 6.1.7601.17514                 USER API Windows
    useraccountcontrolsettings.dll  6.1.7601.17514                  
    usercpl.dll                6.1.7601.17514                
    userenv.dll                6.1.7601.17514              Userenv
    usp10.dll                  1.626.7601.17514            Uniscribe Unicode script processor
    utildll.dll                6.1.7601.17514                WinStation
    uudf.dll                   6.1.7600.16385              UDF Utility DLL
    uxinit.dll                 6.1.7600.16385              Windows User Experience Session Initialization Dll
    uxlib.dll                  6.1.7601.17514              Setup Wizard Framework
    uxlibres.dll               6.1.7600.16385              UXLib Resources
    uxsms.dll                  6.1.7600.16385              Microsoft User Experience Session Management Service
    uxtheme.dll                6.1.7600.16385                UxTheme (Microsoft)
    van.dll                    6.1.7601.17514                
    vault.dll                  6.1.7601.17514                -  Windows
    vaultcli.dll               6.1.7600.16385              Credential Vault Client Library
    vaultcredprovider.dll      6.1.7600.16385                 Vault
    vaultsvc.dll               6.1.7601.17514                 
    vbajet32.dll               6.0.1.9431                  Visual Basic for Applications Development Environment - Expression Service Loader
    vbscript.dll               5.8.7601.17514              Microsoft  VBScript
    vdmdbg.dll                 6.1.7600.16385              VDMDBG.DLL
    vdmredir.dll               6.1.7600.16385              Virtual Dos Machine Network Interface Library
    vds_ps.dll                 6.1.7600.16385              Microsoft Virtual Disk Service proxy/stub
    vdsbas.dll                 6.1.7601.17514                  
    vdsdyn.dll                 6.1.7600.16385                  VDS,  2.1.0.1
    vdsutil.dll                6.1.7601.17514                  
    vdsvd.dll                  6.1.7600.16385              VDS Virtual Disk Provider, Version 1.0
    ver.dll                    3.10.0.103                  Version Checking and File Installation Libraries
    verifier.dll               6.1.7600.16385              Standard application verifier provider dll
    version.dll                6.1.7600.16385              Version Checking and File Installation Libraries
    vfpodbc.dll                1.0.2.0                     vfpodbc
    vfwwdm32.dll               6.1.7601.17514               VfW MM Driver    WDM-
    vga.dll                    6.1.7600.16385              VGA 16 Colour Display Driver
    vga256.dll                 6.1.7600.16385              256 Color VGA\SVGA Display Driver
    vga64k.dll                 6.1.7600.16385              32K/64K color VGA\SVGA Display Driver
    vidreszr.dll               6.1.7600.16385              Windows Media Resizer
    virtdisk.dll               6.1.7600.16385              Virtual Disk API DLL
    vmbuscoinstaller.dll       6.1.7601.17514              Hyper-V VMBUS Coinstaller
    vmbuspipe.dll              6.1.7601.17514              VmBus User Mode Pipe DLL
    vmbusres.dll               6.1.7601.17514                 VMBus
    vmdcoinstall.dll           6.1.7601.17514              Hyper-V Integration Components Coinstaller
    vmicres.dll                6.1.7601.17514                    
    vmictimeprovider.dll       6.1.7601.17514              Virtual Machine Integration Component Time Sync Provider Library
    vmstorfltres.dll           6.1.7601.17514                   
    vpnike.dll                 6.1.7601.17514              VPNIKE Protocol Engine - Test dll
    vpnikeapi.dll              6.1.7601.17514              VPN IKE API's
    vss_ps.dll                 6.1.7600.16385              Microsoft Volume Shadow Copy Service proxy/stub
    vssapi.dll                 6.1.7601.17514              Microsoft Volume Shadow Copy Requestor/Writer Services API DLL
    vsstrace.dll               6.1.7600.16385                    Microsoft
    w32time.dll                6.1.7600.16385                Windows
    w32topl.dll                6.1.7600.16385              Windows NT Topology Maintenance Tool
    wab32.dll                  6.1.7600.16385              Microsoft (R) Contacts DLL
    wab32res.dll               6.1.7600.16385               Microsoft (R) DLL
    wabsyncprovider.dll        6.1.7600.16385                 Microsoft Windows
    wavdest.dll                6.1.7601.17514              Windows Sound Recorder
    wavemsp.dll                6.1.7601.17514              Microsoft Wave MSP
    wbemcomn.dll               6.1.7601.17514              WMI
    wbiosrvc.dll               6.1.7600.16385                Windows
    wcnapi.dll                 6.1.7600.16385              Windows Connect Now - API Helper DLL
    wcncsvc.dll                6.1.7601.17514                Windows -   
    wcneapauthproxy.dll        6.1.7600.16385              Windows Connect Now - WCN EAP Authenticator Proxy
    wcneappeerproxy.dll        6.1.7600.16385              Windows Connect Now - WCN EAP PEER Proxy
    wcnnetsh.dll               6.1.7600.16385               DLL    Netsh  WCN
    wcnwiz.dll                 6.1.7600.16385                Windows Connect Now
    wcspluginservice.dll       6.1.7600.16385               DLL WcsPlugInService
    wdc.dll                    6.1.7601.17514               
    wdi.dll                    6.1.7600.16385                Windows
    wdiasqmmodule.dll          6.1.7601.17514              Adaptive SQM WDI Plugin
    wdigest.dll                6.1.7600.16385              Microsoft Digest Access
    wdscore.dll                6.1.7601.17514              Panther Engine Module
    webcheck.dll               8.0.7601.17514               -
    webclnt.dll                6.1.7601.17514               DLL - DAV
    webio.dll                  6.1.7601.17514              API    
    webservices.dll            6.1.7601.17514                - Windows
    wecapi.dll                 6.1.7600.16385              Event Collector Configuration API
    wecsvc.dll                 6.1.7600.16385                
    wer.dll                    6.1.7601.17514                  Windows
    werconcpl.dll              6.1.7601.17514              PRS CPL
    wercplsupport.dll          6.1.7600.16385                   
    werdiagcontroller.dll      6.1.7600.16385              WER Diagnostic Controller
    wersvc.dll                 6.1.7600.16385                 Windows
    werui.dll                  6.1.7600.16385               DLL      Windows
    wevtapi.dll                6.1.7600.16385              API    
    wevtfwd.dll                6.1.7600.16385              WS-Management Event Forwarding Plug-in
    wevtsvc.dll                6.1.7601.17514                
    wfapigp.dll                6.1.7600.16385              Windows Firewall GPO Helper dll
    wfhc.dll                   6.1.7600.16385               Windows.   
    wfsr.dll                   6.1.7600.16385                  Windows
    whealogr.dll               6.1.7600.16385                WHEA
    whhelper.dll               6.1.7600.16385              DLL     winHttp
    wiaaut.dll                 6.1.7600.16385               WIA-
    wiadefui.dll               6.1.7601.17514                  WIA
    wiadss.dll                 6.1.7600.16385               WIA -  TWAIN
    wiarpc.dll                 6.1.7601.17514              Windows Image Acquisition RPC client DLL
    wiascanprofiles.dll        6.1.7600.16385              Microsoft Windows ScanProfiles
    wiaservc.dll               6.1.7601.17514                  
    wiashext.dll               6.1.7600.16385                     
    wiatrace.dll               6.1.7600.16385              WIA Tracing
    wiavideo.dll               6.1.7601.17514              WIA Video
    wifeman.dll                3.10.0.103                  Windows WIFE interface core component
    wimgapi.dll                6.1.7601.17514               Windows Imaging
    win32spl.dll               6.1.7601.17514                    
    win87em.dll                                            
    winbio.dll                 6.1.7600.16385              API   Windows
    winbrand.dll               6.1.7600.16385              Windows Branding Resources
    wincredprovider.dll        6.1.7600.16385               DLL wincredprovider
    windowscodecs.dll          6.1.7601.17514              Microsoft Windows Codecs Library
    windowscodecsext.dll       6.1.7600.16385              Microsoft Windows Codecs Extended Library
    winethc.dll                6.1.7600.16385                 WinInet
    winfax.dll                 6.1.7600.16385              Microsoft  Fax API Support DLL
    winhttp.dll                6.1.7601.17514               HTTP Windows
    wininet.dll                8.0.7601.17514                 Win32
    winipsec.dll               6.1.7600.16385              Windows IPsec SPD Client DLL
    winmm.dll                  6.1.7601.17514              MCI API DLL
    winnls.dll                 3.10.0.103                  Windows IME interface core component
    winnsi.dll                 6.1.7600.16385              Network Store Information RPC interface
    winrnr.dll                 6.1.7600.16385              LDAP RnR Provider DLL
    winrscmd.dll               6.1.7600.16385              remtsvc
    winrsmgr.dll               6.1.7600.16385              WSMan Shell API
    winrssrv.dll               6.1.7600.16385              winrssrv
    winsatapi.dll              6.1.7601.17514              Windows System Assessment Tool API
    winscard.dll               6.1.7601.17514              API - (Microsoft)
    winshfhc.dll               6.1.7600.16385              File Risk Estimation
    winsock.dll                3.10.0.103                  Windows Socket 16-Bit DLL
    winsockhc.dll              6.1.7600.16385                   Winsock
    winsrpc.dll                6.1.7600.16385              WINS RPC LIBRARY
    winsrv.dll                 6.1.7601.17514                 Windows
    winsta.dll                 6.1.7601.17514              Winstation Library
    winsync.dll                2007.94.7600.16385          Synchronization Framework
    winsyncmetastore.dll       2007.94.7600.16385          Windows Synchronization Metadata Store
    winsyncproviders.dll       2007.94.7600.16385          Windows Synchronization Provider Framework
    wintrust.dll               6.1.7601.17514              Microsoft Trust Verification APIs
    winusb.dll                 6.1.7600.16385              Windows USB Driver User Library
    wkscli.dll                 6.1.7601.17514              Workstation Service Client DLL
    wksprtps.dll               6.1.7600.16385              WorkspaceRuntime ProxyStub DLL
    wkssvc.dll                 6.1.7601.17514               DLL   
    wlanapi.dll                6.1.7600.16385              Windows WLAN AutoConfig Client Side API DLL
    wlancfg.dll                6.1.7600.16385               DLL    Netsh  WLAN
    wlanconn.dll               6.1.7600.16385                Dot11
    wlandlg.dll                6.1.7600.16385                   
    wlangpui.dll               6.1.7601.17514               "   "
    wlanhc.dll                 6.1.7600.16385                   
    wlanhlp.dll                6.1.7600.16385              Windows Wireless LAN 802.11 Client Side Helper API
    wlaninst.dll               6.1.7600.16385              Windows NET Device Class Co-Installer for Wireless LAN
    wlanmm.dll                 6.1.7600.16385                Dot11   
    wlanmsm.dll                6.1.7601.17514              Windows Wireless LAN 802.11 MSM DLL
    wlanpref.dll               6.1.7601.17514                
    wlansec.dll                6.1.7600.16385              Windows Wireless LAN 802.11 MSM Security Module DLL
    wlansvc.dll                6.1.7600.16385               DLL       Windows
    wlanui.dll                 6.1.7601.17514                 
    wlanutil.dll               6.1.7600.16385               DLL     Windows   802.11
    wldap32.dll                6.1.7601.17514              Win32 LDAP API DLL
    wlgpclnt.dll               6.1.7600.16385                 802.11
    wls0wndh.dll               6.1.7600.16385              Session0 Viewer Window Hook DLL
    wmadmod.dll                6.1.7601.17514              Windows Media Audio Decoder
    wmadmoe.dll                6.1.7600.16385              Windows Media Audio 10 Encoder/Transcoder
    wmalfxgfxdsp.dll           6.1.7600.16385              SysFx DSP
    wmasf.dll                  12.0.7600.16385             Windows Media ASF DLL
    wmcodecdspps.dll           6.1.7600.16385              Windows Media CodecDSP Proxy Stub Dll
    wmdmlog.dll                12.0.7600.16385             Windows Media Device Manager Logger
    wmdmps.dll                 12.0.7600.16385             Windows Media Device Manager Proxy Stub
    wmdrmdev.dll               12.0.7601.17514             Windows Media DRM for Network Devices Registration DLL
    wmdrmnet.dll               12.0.7601.17514             Windows Media DRM for Network Devices DLL
    wmdrmsdk.dll               11.0.7601.17514             Windows Media DRM SDK DLL
    wmerror.dll                12.0.7600.16385               Windows Media ()
    wmi.dll                    6.1.7600.16385              WMI DC and DP functionality
    wmicmiplugin.dll           6.1.7601.17514              WMI CMI Plugin
    wmidx.dll                  12.0.7600.16385             Windows Media Indexer DLL
    wmiprop.dll                6.1.7600.16385                  WDM
    wmnetmgr.dll               12.0.7601.17514             Windows Media Network Plugin Manager DLL
    wmp.dll                    12.0.7601.17514             Windows Media Player
    wmpcm.dll                  12.0.7600.16385             Windows Media Player Compositing Mixer
    wmpdui.dll                 12.0.7600.16385             Windows Media Player UI Engine
    wmpdxm.dll                 12.0.7601.17514             Windows Media Player Extension
    wmpeffects.dll             12.0.7601.17514             Windows Media Player Effects
    wmpencen.dll               12.0.7601.17514             Windows Media Player Encoding Module
    wmphoto.dll                6.1.7601.17514               Windows Media
    wmploc.dll                 12.0.7601.17514               Windows Media
    wmpmde.dll                 12.0.7601.17514             WMPMDE DLL
    wmpps.dll                  12.0.7601.17514             Windows Media Player Proxy Stub Dll
    wmpshell.dll               12.0.7601.17514                Windows Media
    wmpsrcwp.dll               12.0.7601.17514             WMPSrcWp Module
    wmsgapi.dll                6.1.7600.16385              WinLogon IPC Client
    wmspdmod.dll               6.1.7601.17514              Windows Media Audio Voice Decoder
    wmspdmoe.dll               6.1.7600.16385              Windows Media Audio Voice Encoder
    wmvcore.dll                12.0.7601.17514             Windows Media Playback/Authoring DLL
    wmvdecod.dll               6.1.7601.17514              Windows Media Video Decoder
    wmvdspa.dll                6.1.7600.16385              Windows Media Video DSP Components - Advanced
    wmvencod.dll               6.1.7600.16385              Windows Media Video 9 Encoder
    wmvsdecd.dll               6.1.7601.17514              Windows Media Screen Decoder
    wmvsencd.dll               6.1.7600.16385              Windows Media Screen Encoder
    wmvxencd.dll               6.1.7600.16385              Windows Media Video Encoder
    wow32.dll                  6.1.7600.16385              32-bit WOW Subsystem Library
    wpc.dll                    1.0.0.1                        
    wpcao.dll                  6.1.7600.16385                WPC
    wpccpl.dll                 6.1.7601.17514                 " "
    wpcmig.dll                 1.0.0.1                         Windows
    wpcsvc.dll                 1.0.0.1                         Windows
    wpcumi.dll                 1.0.0.1                        Windows
    wpd_ci.dll                 6.1.7601.17514                     Windows
    wpdbusenum.dll             6.1.7601.17514                
    wpdshext.dll               6.1.7601.17514                  
    wpdshserviceobj.dll        6.1.7601.17514              Windows Portable Device Shell Service Object
    wpdsp.dll                  6.1.7601.17514              WMDM Service Provider for Windows Portable Devices
    wpdwcn.dll                 6.1.7601.17514                    WCN
    ws2_32.dll                 6.1.7601.17514              32-  Windows Socket 2.0
    ws2help.dll                6.1.7600.16385              Windows Socket 2.0 Helper for Windows NT
    wscapi.dll                 6.1.7601.17514              Windows Security Center API
    wscinterop.dll             6.1.7600.16385              Windows Health Center WSC Interop
    wscisvif.dll               6.1.7600.16385              Windows Security Center ISV API
    wscmisetup.dll             6.1.7600.16385              Installers for Winsock Transport and Name Space Providers
    wscproxystub.dll           6.1.7600.16385              Windows Security Center ISV Proxy Stub
    wscsvc.dll                 6.1.7600.16385                  Windows
    wsdapi.dll                 6.1.7601.17514              -   DLL API- 
    wsdchngr.dll               6.1.7601.17514              WSD Challenge Component
    wsdmon.dll                 6.1.7600.16385                 WSD
    wsdprintproxy.dll          6.1.7600.16385              Function Discovery Printer Proxy Dll
    wsdscanproxy.dll           6.1.7600.16385              Function Discovery WSD Scanner Proxy Dll
    wsecedit.dll               6.1.7600.16385                 
    wsepno.dll                 7.0.7600.16385                     Windows Search
    wshbth.dll                 6.1.7601.17514              Windows Sockets Helper DLL
    wshcon.dll                 5.8.7600.16385              Microsoft  Windows Script Controller
    wshelper.dll               6.1.7600.16385               DLL    Winsock Net
    wshext.dll                 5.8.7600.16385              Microsoft  Shell Extension for Windows Script Host
    wship6.dll                 6.1.7600.16385               DLL  Winsock2 (TL/IPv6)
    wshirda.dll                6.1.7601.17514              Windows Sockets Helper DLL
    wshnetbs.dll               6.1.7600.16385              Netbios Windows Sockets Helper DLL
    wshqos.dll                 6.1.7600.16385               DLL   QoS Winsock2
    wshrm.dll                  6.1.7600.16385                DLL   Windows  PGM
    wshtcpip.dll               6.1.7600.16385               DLL   Winsock2 (TL/IPv4)
    wsmanmigrationplugin.dll   6.1.7600.16385              WinRM Migration Plugin
    wsmauto.dll                6.1.7600.16385              WSMAN Automation
    wsmplpxy.dll               6.1.7600.16385              wsmplpxy
    wsmres.dll                 6.1.7600.16385               DLL  WSMan
    wsmsvc.dll                 6.1.7601.17514               WSMan
    wsmwmipl.dll               6.1.7600.16385              WSMAN WMI Provider
    wsnmp32.dll                6.1.7601.17514              Microsoft WinSNMP v2.0 Manager API
    wsock32.dll                6.1.7600.16385              Windows Socket 32-Bit DLL
    wtsapi32.dll               6.1.7601.17514              Windows Remote Desktop Session Host Server SDK APIs
    wuapi.dll                  7.5.7601.17514              API    Windows
    wuaueng.dll                7.5.7601.17514                Windows
    wucltux.dll                7.5.7601.17514                   Windows
    wudfcoinstaller.dll        6.1.7601.17514              Windows Driver Foundation - User-mode Platform Device Co-Installer
    wudfplatform.dll           6.1.7601.17514              Windows Driver Foundation -    
    wudfsvc.dll                6.1.7601.17514              Windows Driver Foundation (WDF) -     
    wudfx.dll                  6.1.7601.17514              WDF:UMDF Framework Library
    wudriver.dll               7.5.7601.17514              Windows Update WUDriver Stub
    wups.dll                   7.5.7601.17514              Windows Update client proxy stub
    wups2.dll                  7.5.7601.17514              Windows Update client proxy stub 2
    wuwebv.dll                 7.5.7601.17514              Windows Update Vista Web Control
    wvc.dll                    6.1.7601.17514              Windows Visual Components
    wwanadvui.dll              8.1.2.0                         
    wwanapi.dll                6.1.7600.16385              Mbnapi
    wwancfg.dll                6.1.7600.16385                DLL  Netsh  MBN
    wwanconn.dll               8.1.7601.17514                  
    wwanhc.dll                 8.1.2.0                         
    wwaninst.dll               8.1.2.0                     Windows NET Device Class Co-Installer for Wireless WAN
    wwanmm.dll                 8.1.2.0                         
    wwanpref.dll               8.1.2.0                          
    wwanprotdim.dll            8.1.7601.17514              WWAN Device Interface Module
    wwansvc.dll                8.1.2.0                       WWAN
    wwapi.dll                  8.1.2.0                     WWAN API
    wzcdlg.dll                 6.1.7600.16385              Windows Connect Now - Flash Config Enrollee
    x3daudio1_0.dll            9.11.519.0                  X3DAudio
    x3daudio1_1.dll            9.15.779.0                  X3DAudio
    x3daudio1_2.dll            9.21.1148.0                 X3DAudio
    x3daudio1_3.dll            9.22.1284.0                 X3DAudio
    x3daudio1_4.dll            9.23.1350.0                 X3DAudio
    x3daudio1_5.dll            9.25.1476.0                 X3DAudio
    x3daudio1_6.dll            9.26.1590.0                 3D Audio Library
    x3daudio1_7.dll            9.28.1886.0                 3D Audio Library
    xactengine2_0.dll          9.11.519.0                  XACT Engine API
    xactengine2_1.dll          9.12.589.0                  XACT Engine API
    xactengine2_10.dll         9.21.1148.0                 XACT Engine API
    xactengine2_2.dll          9.13.644.0                  XACT Engine API
    xactengine2_3.dll          9.14.701.0                  XACT Engine API
    xactengine2_4.dll          9.15.779.0                  XACT Engine API
    xactengine2_5.dll          9.16.857.0                  XACT Engine API
    xactengine2_6.dll          9.17.892.0                  XACT Engine API
    xactengine2_7.dll          9.18.944.0                  XACT Engine API
    xactengine2_8.dll          9.19.1007.0                 XACT Engine API
    xactengine2_9.dll          9.20.1057.0                 XACT Engine API
    xactengine3_0.dll          9.22.1284.0                 XACT Engine API
    xactengine3_1.dll          9.23.1350.0                 XACT Engine API
    xactengine3_2.dll          9.24.1400.0                 XACT Engine API
    xactengine3_3.dll          9.25.1476.0                 XACT Engine API
    xactengine3_4.dll          9.26.1590.0                 XACT Engine API
    xactengine3_5.dll          9.27.1734.0                 XACT Engine API
    xactengine3_6.dll          9.28.1886.0                 XACT Engine API
    xactengine3_7.dll          9.29.1962.0                 XACT Engine API
    xapofx1_0.dll              9.23.1350.0                 XAPOFX
    xapofx1_1.dll              9.24.1400.0                 XAPOFX
    xapofx1_2.dll              9.25.1476.0                 XAPOFX
    xapofx1_3.dll              9.26.1590.0                 Audio Effect Library
    xapofx1_4.dll              9.28.1886.0                 Audio Effect Library
    xapofx1_5.dll              9.29.1962.0                 Audio Effect Library
    xaudio2_0.dll              9.22.1284.0                 XAudio2 Game Audio API
    xaudio2_1.dll              9.23.1350.0                 XAudio2 Game Audio API
    xaudio2_2.dll              9.24.1400.0                 XAudio2 Game Audio API
    xaudio2_3.dll              9.25.1476.0                 XAudio2 Game Audio API
    xaudio2_4.dll              9.26.1590.0                 XAudio2 Game Audio API
    xaudio2_5.dll              9.27.1734.0                 XAudio2 Game Audio API
    xaudio2_6.dll              9.28.1886.0                 XAudio2 Game Audio API
    xaudio2_7.dll              9.29.1962.0                 XAudio2 Game Audio API
    xinput1_1.dll              9.12.589.0                  Microsoft Common Controller API
    xinput1_2.dll              9.14.701.0                  Microsoft Common Controller API
    xinput1_3.dll              9.18.944.0                  Microsoft Common Controller API
    xinput9_1_0.dll            6.1.7600.16385                XNA
    xmlfilter.dll              2008.0.7600.16385            XML
    xmllite.dll                1.3.1000.0                  Microsoft XmlLite Library
    xmlprovi.dll               6.1.7600.16385              Network Provisioning Service Client API
    xolehlp.dll                2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Helper APIs DLL
    xpsfilt.dll                6.1.7600.16385              XML Paper Specification Document IFilter
    xpsgdiconverter.dll        6.1.7601.17514              XPS to GDI Converter
    xpsprint.dll               6.1.7601.17514              XPS Printing DLL
    xpsrasterservice.dll       6.1.7601.17514              XPS Rasterization Service Component
    xpsservices.dll            6.1.7601.17514              Xps Object Model in memory creation and deserialization
    xpsshhdr.dll               6.1.7600.16385              Package Document Shell Extension Handler
    xpssvcs.dll                6.1.7600.16385              Native Code Xps Services Library
    xvidcore.dll                                           
    xvidvfw.dll                                            
    xwizards.dll               6.1.7600.16385                 
    xwreg.dll                  6.1.7600.16385              Extensible Wizard Registration Manager Module
    xwtpdui.dll                6.1.7600.16385                   DUI
    xwtpw32.dll                6.1.7600.16385                   Win32
    zgmprxy.dll                6.1.7600.16385              Internal file used by the Internet Games
    zipfldr.dll                6.1.7601.17514               ZIP-


--------[   ]------------------------------------------------------------------------------------------------

     :
                         30.12.1899
                           30.12.1899
                                            06.01.2002 14:59:00
                                             580  (0 ., 0 , 9 , 40 )

      :
                                     30.12.1899
                            30.12.1899
                                        580  (0 ., 0 , 9 , 40 )
                                       0  (0 ., 0 , 0 , 0 )
                                  580  (0 ., 0 , 9 , 40 )
                                 0  (0 ., 0 , 0 , 0 )
                                       0
                                100.00%

      (" "):
                                              0

    :
                                                    


--------[   ]-----------------------------------------------------------------------------------------------

    ADMIN$                                    Admin                           C:\Windows
    C$                                                           C:\
    D$                                                           D:\
    IPC$                            IPC            IPC                             


--------[  ]------------------------------------------------------------------------------------------------

       :
                                          
                                             user-PC
                              
                      
      ./.                      0 / 42 .
                                  0 
                                     
                                       
                                30 
                                30 


--------[    ]----------------------------------------------------------------------------------------------

    user                                          USER-PC                   user-PC
    user                                          USER-PC                   user-PC


--------[  ]------------------------------------------------------------------------------------------------

  [ user ]

     :
                                         user
                                               user
                                               
                                     52
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [  ]

     :
                                         
                                               
                                                 /
                                               
                                     6
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [  ]

     :
                                         
                                               
                                                      
                                               
                                     0
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            


--------[   ]--------------------------------------------------------------------------------------------

  [ IIS_IUSRS ]

      :
                                              ,    IIS.

     :
      IUSR                                              

  [  ]

      :
                                               ,         

     :
      user                                              
                                           

  [  ]

      :
                                                   ,   ,     "",     .

     :
                                                   

  [   ]

      :
                                                 .

  [   ]

      :
                                                         .

  [    ]

      :
                                                         

  [   ]

      :
                                                        

  [  DCOM ]

      :
                                                 ,     DCOM   .

  [    ]

      :
                                                     ,         ,        .

  [    ]

      :
                                                  ,       

  [     ]

      :
                                                     

  [  ]

      :
                                                         

     :
                                           
                                       

  [  ]

      :
                                                 

  [    ]

      :
                                                      


--------[   ]-------------------------------------------------------------------------------------------

  [ None ]

      :
                                             Ordinary users

     :
      user                                              
                                           
                                                   


--------[  Windows ]-----------------------------------------------------------------------------------------------

  [ NVIDIA GeForce 8600 GT (Microsoft Corporation - WDDM v1.1) ]

     :
                                      NVIDIA GeForce 8600 GT (Microsoft Corporation - WDDM v1.1)
                                          GeForce 8600 GT
       BIOS                                       Version 60.84.54.0.0
                                      GeForce 8600 GT
       DAC                                           Integrated RAMDAC
                                            14.05.2009
                                          8.15.11.8593 - nVIDIA ForceWare 185.93
                                       NVIDIA
                                           512 

     :
      nvd3dum                                           8.15.11.8593 - nVIDIA ForceWare 185.93
      nvwgf2um                                          8.15.11.8593

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://driveragent.com?ref=59

  [ NVIDIA GeForce 8600 GT (Microsoft Corporation - WDDM v1.1) ]

     :
                                      NVIDIA GeForce 8600 GT (Microsoft Corporation - WDDM v1.1)
                                          GeForce 8600 GT
       BIOS                                       Version 60.84.54.0.0
                                      GeForce 8600 GT
       DAC                                           Integrated RAMDAC
                                            14.05.2009
                                          8.15.11.8593 - nVIDIA ForceWare 185.93
                                       NVIDIA
                                           512 

     :
      nvd3dum                                           8.15.11.8593 - nVIDIA ForceWare 185.93
      nvwgf2um                                          8.15.11.8593

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://driveragent.com?ref=59


--------[  PCI / AGP ]---------------------------------------------------------------------------------------------

    nVIDIA GeForce 8600 GT                                                            
    nVIDIA GeForce 8600 GT                                                            3D-


--------[   ]---------------------------------------------------------------------------------------

  [ PCI Express 1.0 x16: nVIDIA GeForce 8600 GT ]

      :
                                            nVIDIA GeForce 8600 GT
       BIOS                                       60.84.54.00
                                       G84GT
      PCI-                                    10DE-0402 / 0000-0000  (Rev A2)
                                       289 .
                                  80 nm
                                         169 mm2
                                                 PCI Express 1.0 x16 @ x16
                                           512 
        (Geometric Domain)                     540   (: 540 MHz)
        (Shader Domain)                        1188   (: 1188 MHz)
       RAMDAC                                    400 
                                     8
      TMU                                     1
                                     32  (v4.0)
        DirectX                      DirectX v10
                            4320 /
                            8640 /

      :
                                                 DDR2
                                              128 
                                         301  (DDR)  (: 300 MHz)
                                      602 
                                   9632 /

    :
                                     100%

      :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://driveragent.com?ref=59

    nVIDIA GPU Registers:
      nv-000000                                         084200A2
      nv-0010F0                                         00000000
      nv-001218                                         00000000
      nv-001540                                         F3030003
      nv-0015F4                                         00000000
      nv-0015F8                                         00000000
      nv-0015FC                                         00000000
      nv-001600                                         00000000
      nv-001850                                         00000000
      nv-004000                                         00000000
      nv-004004                                         00000000
      nv-004008                                         80016400
      nv-00400C                                         00002707
      nv-004018                                         00000000
      nv-00401C                                         00000000
      nv-004020                                         80000000
      nv-004024                                         00001602
      nv-004028                                         A0090000
      nv-00402C                                         00001402
      nv-00C040                                         2E801BB3
      nv-00E114                                         00000001
      nv-00E118                                         00000000
      nv-00E11C                                         00000100
      nv-00E120                                         000000FF
      nv-020014                                         FE4202C7
      nv-020400                                         00000033
      nv-100000                                         0000C042
      nv-100200                                         01201000
      nv-10020C                                         20000000
      nv-100214                                         00000033
      nv-100474                                         00000000
      nv-100714                                         00000111
      nv-100914                                         00000000
      nv-101000                                         8040889A


--------[  ]-----------------------------------------------------------------------------------------------------

  [ LG L1918S ]

     :
                                             LG L1918S
      ID                                        GSM4B31
                                                   
                                             19" LCD (SXGA)
                                              7 / 2007
                                           170786967
      .                         38 cm x 30 cm (19.1")
                                       5:4
                                            30 - 83 
                                           56 - 75 
                                  1280 x 1024
                                                   2.20
        DPMS                        Standby, Suspend, Active-Off

     :
      640 x 480                                         75 
      800 x 600                                         75 
      1024 x 768                                        75 
      1152 x 864                                        75 
      1280 x 768                                        75 
      1280 x 800                                        75 
      1280 x 1024                                       75 

     :
                                                   LG Electronics
                                     http://www.lge.com/products/category/list/computer%20products_monitor.jhtml
                                       http://www.lge.com/support/main.jhtml
                                     http://driveragent.com?ref=59


--------[   ]------------------------------------------------------------------------------------------------

      :
                                     
                                              1280 x 1024
                                            32 
                                       1
                                        96 dpi
        /                         36 / 36
                                     51
                                      60 
                                    C:\Users\user\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg

      :
       -                             
                                              
                                      
                              
      ClearType                                         
             
                                
                                  
                                      
                                  
                                 
                                            
                                   
       /           
                                           
                              
                               
                            
                              
      Windows Aero                                      
       Windows Plus!                               


--------[  ]-----------------------------------------------------------------------------------------------

    \\.\DISPLAY1           (0,0)          (1280,1024)


--------[  ]-------------------------------------------------------------------------------------------------

    640 x 480           8   59 Hz
    640 x 480           8   60 Hz
    640 x 480           8   60 Hz
    640 x 480           8   60 Hz
    640 x 480           8   72 Hz
    640 x 480           8   75 Hz
    640 x 480          16   59 Hz
    640 x 480          16   60 Hz
    640 x 480          16   60 Hz
    640 x 480          16   60 Hz
    640 x 480          16   72 Hz
    640 x 480          16   75 Hz
    640 x 480          32   59 Hz
    640 x 480          32   60 Hz
    640 x 480          32   60 Hz
    640 x 480          32   60 Hz
    640 x 480          32   72 Hz
    640 x 480          32   75 Hz
    720 x 480           8   56 Hz
    720 x 480           8   56 Hz
    720 x 480           8   56 Hz
    720 x 480           8   60 Hz
    720 x 480           8   60 Hz
    720 x 480           8   60 Hz
    720 x 480           8   72 Hz
    720 x 480           8   72 Hz
    720 x 480           8   72 Hz
    720 x 480           8   75 Hz
    720 x 480           8   75 Hz
    720 x 480           8   75 Hz
    720 x 480          16   56 Hz
    720 x 480          16   56 Hz
    720 x 480          16   56 Hz
    720 x 480          16   60 Hz
    720 x 480          16   60 Hz
    720 x 480          16   60 Hz
    720 x 480          16   72 Hz
    720 x 480          16   72 Hz
    720 x 480          16   72 Hz
    720 x 480          16   75 Hz
    720 x 480          16   75 Hz
    720 x 480          16   75 Hz
    720 x 480          32   56 Hz
    720 x 480          32   56 Hz
    720 x 480          32   56 Hz
    720 x 480          32   60 Hz
    720 x 480          32   60 Hz
    720 x 480          32   60 Hz
    720 x 480          32   72 Hz
    720 x 480          32   72 Hz
    720 x 480          32   72 Hz
    720 x 480          32   75 Hz
    720 x 480          32   75 Hz
    720 x 480          32   75 Hz
    720 x 576           8   56 Hz
    720 x 576           8   56 Hz
    720 x 576           8   56 Hz
    720 x 576           8   60 Hz
    720 x 576           8   60 Hz
    720 x 576           8   60 Hz
    720 x 576           8   72 Hz
    720 x 576           8   72 Hz
    720 x 576           8   72 Hz
    720 x 576           8   75 Hz
    720 x 576           8   75 Hz
    720 x 576           8   75 Hz
    720 x 576          16   56 Hz
    720 x 576          16   56 Hz
    720 x 576          16   56 Hz
    720 x 576          16   60 Hz
    720 x 576          16   60 Hz
    720 x 576          16   60 Hz
    720 x 576          16   72 Hz
    720 x 576          16   72 Hz
    720 x 576          16   72 Hz
    720 x 576          16   75 Hz
    720 x 576          16   75 Hz
    720 x 576          16   75 Hz
    720 x 576          32   56 Hz
    720 x 576          32   56 Hz
    720 x 576          32   56 Hz
    720 x 576          32   60 Hz
    720 x 576          32   60 Hz
    720 x 576          32   60 Hz
    720 x 576          32   72 Hz
    720 x 576          32   72 Hz
    720 x 576          32   72 Hz
    720 x 576          32   75 Hz
    720 x 576          32   75 Hz
    720 x 576          32   75 Hz
    800 x 600           8   56 Hz
    800 x 600           8   60 Hz
    800 x 600           8   60 Hz
    800 x 600           8   60 Hz
    800 x 600           8   72 Hz
    800 x 600           8   75 Hz
    800 x 600          16   56 Hz
    800 x 600          16   60 Hz
    800 x 600          16   60 Hz
    800 x 600          16   60 Hz
    800 x 600          16   72 Hz
    800 x 600          16   75 Hz
    800 x 600          32   56 Hz
    800 x 600          32   60 Hz
    800 x 600          32   60 Hz
    800 x 600          32   60 Hz
    800 x 600          32   72 Hz
    800 x 600          32   75 Hz
    1024 x 768          8   60 Hz
    1024 x 768          8   60 Hz
    1024 x 768          8   60 Hz
    1024 x 768          8   70 Hz
    1024 x 768          8   75 Hz
    1024 x 768         16   60 Hz
    1024 x 768         16   60 Hz
    1024 x 768         16   60 Hz
    1024 x 768         16   70 Hz
    1024 x 768         16   75 Hz
    1024 x 768         32   60 Hz
    1024 x 768         32   60 Hz
    1024 x 768         32   60 Hz
    1024 x 768         32   70 Hz
    1024 x 768         32   75 Hz
    1152 x 864          8   60 Hz
    1152 x 864          8   60 Hz
    1152 x 864          8   60 Hz
    1152 x 864          8   75 Hz
    1152 x 864          8   75 Hz
    1152 x 864          8   75 Hz
    1152 x 864         16   60 Hz
    1152 x 864         16   60 Hz
    1152 x 864         16   60 Hz
    1152 x 864         16   75 Hz
    1152 x 864         16   75 Hz
    1152 x 864         16   75 Hz
    1152 x 864         32   60 Hz
    1152 x 864         32   60 Hz
    1152 x 864         32   60 Hz
    1152 x 864         32   75 Hz
    1152 x 864         32   75 Hz
    1152 x 864         32   75 Hz
    1280 x 720          8   60 Hz
    1280 x 720          8   60 Hz
    1280 x 720          8   60 Hz
    1280 x 720          8   75 Hz
    1280 x 720          8   75 Hz
    1280 x 720          8   75 Hz
    1280 x 720         16   60 Hz
    1280 x 720         16   60 Hz
    1280 x 720         16   60 Hz
    1280 x 720         16   75 Hz
    1280 x 720         16   75 Hz
    1280 x 720         16   75 Hz
    1280 x 720         32   60 Hz
    1280 x 720         32   60 Hz
    1280 x 720         32   60 Hz
    1280 x 720         32   75 Hz
    1280 x 720         32   75 Hz
    1280 x 720         32   75 Hz
    1280 x 768          8   60 Hz
    1280 x 768          8   60 Hz
    1280 x 768          8   60 Hz
    1280 x 768          8   75 Hz
    1280 x 768          8   75 Hz
    1280 x 768          8   75 Hz
    1280 x 768         16   60 Hz
    1280 x 768         16   60 Hz
    1280 x 768         16   60 Hz
    1280 x 768         16   75 Hz
    1280 x 768         16   75 Hz
    1280 x 768         16   75 Hz
    1280 x 768         32   60 Hz
    1280 x 768         32   60 Hz
    1280 x 768         32   60 Hz
    1280 x 768         32   75 Hz
    1280 x 768         32   75 Hz
    1280 x 768         32   75 Hz
    1280 x 1024         8   60 Hz
    1280 x 1024         8   75 Hz
    1280 x 1024        16   60 Hz
    1280 x 1024        16   75 Hz
    1280 x 1024        32   60 Hz
    1280 x 1024        32   75 Hz


--------[ OpenGL ]------------------------------------------------------------------------------------------------------

     OpenGL:
                                           Microsoft Corporation
      Renderer                                          GDI Generic
                                                  1.1.0
      OpenGL DLL                                        6.1.7600.16385(win7_rtm.090713-1255)
      Sub-Pixel Precision                               3 
      Max Viewport Size                                 16384 x 16384
      Max Clipping Planes                               6
      Max Display-List Nesting Level                    64
      Max Evaluator Order                               30
      Max Light Sources                                 8
      Max Pixel Map Table Size                          65536

     OpenGL:
      OpenGL 1.1                                          (100%)
      OpenGL 1.2                                          (12%)
      OpenGL 1.3                                          (0%)
      OpenGL 1.4                                          (0%)
      OpenGL 1.5                                          (0%)
      OpenGL 2.0                                          (0%)
      OpenGL 2.1                                          (0%)
      OpenGL 3.0                                          (0%)

    Max Stack Depth:
      Attribute Stack                                   16
      Client Attribute Stack                            16
      Modelview Matrix Stack                            32
      Name Stack                                        128
      Projection Matrix Stack                           10
      Texture Matrix Stack                              10

     OpenGL:
      GL_3DFX_multisample                                
      GL_3DFX_tbuffer                                    
      GL_3DFX_texture_compression_FXT1                   
      GL_3DL_direct_texture_access2                      
      GL_3Dlabs_multisample_transparency_id              
      GL_3Dlabs_multisample_transparency_range           
      GL_AMD_performance_monitor                         
      GL_AMD_texture_texture4                            
      GL_AMDX_vertex_shader_tessellator                  
      GL_APPLE_aux_depth_stencil                         
      GL_APPLE_client_storage                            
      GL_APPLE_element_array                             
      GL_APPLE_fence                                     
      GL_APPLE_float_pixels                              
      GL_APPLE_flush_buffer_range                        
      GL_APPLE_flush_render                              
      GL_APPLE_packed_pixel                              
      GL_APPLE_packed_pixels                             
      GL_APPLE_pixel_buffer                              
      GL_APPLE_specular_vector                           
      GL_APPLE_texture_range                             
      GL_APPLE_transform_hint                            
      GL_APPLE_vertex_array_object                       
      GL_APPLE_vertex_array_range                        
      GL_APPLE_vertex_program_evaluators                 
      GL_APPLE_ycbcr_422                                 
      GL_ARB_color_buffer_float                          
      GL_ARB_depth_buffer_float                          
      GL_ARB_depth_texture                               
      GL_ARB_draw_buffers                                
      GL_ARB_draw_instanced                              
      GL_ARB_fragment_program                            
      GL_ARB_fragment_program_shadow                     
      GL_ARB_fragment_shader                             
      GL_ARB_framebuffer_object                          
      GL_ARB_framebuffer_sRGB                            
      GL_ARB_geometry_shader4                            
      GL_ARB_half_float_pixel                            
      GL_ARB_half_float_vertex                           
      GL_ARB_imaging                                     
      GL_ARB_instanced_arrays                            
      GL_ARB_map_buffer_range                            
      GL_ARB_matrix_palette                              
      GL_ARB_multisample                                 
      GL_ARB_multitexture                                
      GL_ARB_occlusion_query                             
      GL_ARB_pixel_buffer_object                         
      GL_ARB_point_parameters                            
      GL_ARB_point_sprite                                
      GL_ARB_shader_objects                              
      GL_ARB_shader_texture_lod                          
      GL_ARB_shading_language_100                        
      GL_ARB_shadow                                      
      GL_ARB_shadow_ambient                              
      GL_ARB_texture_border_clamp                        
      GL_ARB_texture_buffer_object                       
      GL_ARB_texture_compression                         
      GL_ARB_texture_compression_rgtc                    
      GL_ARB_texture_cube_map                            
      GL_ARB_texture_env_add                             
      GL_ARB_texture_env_combine                         
      GL_ARB_texture_env_crossbar                        
      GL_ARB_texture_env_dot3                            
      GL_ARB_texture_float                               
      GL_ARB_texture_mirrored_repeat                     
      GL_ARB_texture_non_power_of_two                    
      GL_ARB_texture_rectangle                           
      GL_ARB_texture_rg                                  
      GL_ARB_transpose_matrix                            
      GL_ARB_vertex_array_object                         
      GL_ARB_vertex_blend                                
      GL_ARB_vertex_buffer_object                        
      GL_ARB_vertex_program                              
      GL_ARB_vertex_shader                               
      GL_ARB_window_pos                                  
      GL_ATI_array_rev_comps_in_4_bytes                  
      GL_ATI_blend_equation_separate                     
      GL_ATI_blend_weighted_minmax                       
      GL_ATI_draw_buffers                                
      GL_ATI_element_array                               
      GL_ATI_envmap_bumpmap                              
      GL_ATI_fragment_shader                             
      GL_ATI_lock_texture                                
      GL_ATI_map_object_buffer                           
      GL_ATI_meminfo                                     
      GL_ATI_pixel_format_float                          
      GL_ATI_pn_triangles                                
      GL_ATI_point_cull_mode                             
      GL_ATI_separate_stencil                            
      GL_ATI_shader_texture_lod                          
      GL_ATI_text_fragment_shader                        
      GL_ATI_texture_compression_3dc                     
      GL_ATI_texture_env_combine3                        
      GL_ATI_texture_float                               
      GL_ATI_texture_mirror_once                         
      GL_ATI_vertex_array_object                         
      GL_ATI_vertex_attrib_array_object                  
      GL_ATI_vertex_blend                                
      GL_ATI_vertex_shader                               
      GL_ATI_vertex_streams                              
      GL_ATIX_pn_triangles                               
      GL_ATIX_texture_env_combine3                       
      GL_ATIX_texture_env_route                          
      GL_ATIX_vertex_shader_output_point_size            
      GL_Autodesk_facet_normal                           
      GL_Autodesk_valid_back_buffer_hint                 
      GL_DIMD_YUV                                        
      GL_EXT_422_pixels                                  
      GL_EXT_abgr                                        
      GL_EXT_bgra                                       
      GL_EXT_bindable_uniform                            
      GL_EXT_blend_color                                 
      GL_EXT_blend_equation_separate                     
      GL_EXT_blend_func_separate                         
      GL_EXT_blend_logic_op                              
      GL_EXT_blend_minmax                                
      GL_EXT_blend_subtract                              
      GL_EXT_Cg_shader                                   
      GL_EXT_clip_volume_hint                            
      GL_EXT_cmyka                                       
      GL_EXT_color_matrix                                
      GL_EXT_color_subtable                              
      GL_EXT_color_table                                 
      GL_EXT_compiled_vertex_array                       
      GL_EXT_convolution                                 
      GL_EXT_convolution_border_modes                    
      GL_EXT_coordinate_frame                            
      GL_EXT_copy_texture                                
      GL_EXT_cull_vertex                                 
      GL_EXT_depth_bounds_test                           
      GL_EXT_depth_buffer_float                          
      GL_EXT_direct_state_access                         
      GL_EXT_draw_buffers2                               
      GL_EXT_draw_instanced                              
      GL_EXT_draw_range_elements                         
      GL_EXT_fog_coord                                   
      GL_EXT_fog_function                                
      GL_EXT_fog_offset                                  
      GL_EXT_fragment_lighting                           
      GL_EXT_framebuffer_blit                            
      GL_EXT_framebuffer_multisample                     
      GL_EXT_framebuffer_object                          
      GL_EXT_framebuffer_sRGB                            
      GL_EXT_generate_mipmap                             
      GL_EXT_geometry_shader4                            
      GL_EXT_gpu_program_parameters                      
      GL_EXT_gpu_shader4                                 
      GL_EXT_histogram                                   
      GL_EXT_index_array_formats                         
      GL_EXT_index_func                                  
      GL_EXT_index_material                              
      GL_EXT_index_texture                               
      GL_EXT_interlace                                   
      GL_EXT_light_texture                               
      GL_EXT_misc_attribute                              
      GL_EXT_multi_draw_arrays                           
      GL_EXT_multisample                                 
      GL_EXT_packed_depth_stencil                        
      GL_EXT_packed_float                                
      GL_EXT_packed_pixels                               
      GL_EXT_packed_pixels_12                            
      GL_EXT_paletted_texture                           
      GL_EXT_pixel_buffer_object                         
      GL_EXT_pixel_format                                
      GL_EXT_pixel_texture                               
      GL_EXT_pixel_transform                             
      GL_EXT_pixel_transform_color_table                 
      GL_EXT_point_parameters                            
      GL_EXT_polygon_offset                              
      GL_EXT_rescale_normal                              
      GL_EXT_scene_marker                                
      GL_EXT_secondary_color                             
      GL_EXT_separate_specular_color                     
      GL_EXT_shadow_funcs                                
      GL_EXT_shared_texture_palette                      
      GL_EXT_stencil_clear_tag                           
      GL_EXT_stencil_two_side                            
      GL_EXT_stencil_wrap                                
      GL_EXT_subtexture                                  
      GL_EXT_swap_control                                
      GL_EXT_texgen_reflection                           
      GL_EXT_texture                                     
      GL_EXT_texture_array                               
      GL_EXT_texture_border_clamp                        
      GL_EXT_texture_buffer_object                       
      GL_EXT_texture_color_table                         
      GL_EXT_texture_compression_dxt1                    
      GL_EXT_texture_compression_latc                    
      GL_EXT_texture_compression_rgtc                    
      GL_EXT_texture_compression_s3tc                    
      GL_EXT_texture_cube_map                            
      GL_EXT_texture_edge_clamp                          
      GL_EXT_texture_env                                 
      GL_EXT_texture_env_add                             
      GL_EXT_texture_env_combine                         
      GL_EXT_texture_env_dot3                            
      GL_EXT_texture_filter_anisotropic                  
      GL_EXT_texture_integer                             
      GL_EXT_texture_lod                                 
      GL_EXT_texture_lod_bias                            
      GL_EXT_texture_mirror_clamp                        
      GL_EXT_texture_object                              
      GL_EXT_texture_perturb_normal                      
      GL_EXT_texture_rectangle                           
      GL_EXT_texture_shared_exponent                     
      GL_EXT_texture_sRGB                                
      GL_EXT_texture_swizzle                             
      GL_EXT_texture3D                                   
      GL_EXT_texture4D                                   
      GL_EXT_timer_query                                 
      GL_EXT_transform_feedback                          
      GL_EXT_vertex_array                                
      GL_EXT_vertex_array_bgra                           
      GL_EXT_vertex_shader                               
      GL_EXT_vertex_weighting                            
      GL_EXTX_framebuffer_mixed_formats                  
      GL_EXTX_packed_depth_stencil                       
      GL_FGL_lock_texture                                
      GL_GL2_geometry_shader                             
      GL_GREMEDY_frame_terminator                        
      GL_GREMEDY_string_marker                           
      GL_HP_convolution_border_modes                     
      GL_HP_image_transform                              
      GL_HP_occlusion_test                               
      GL_HP_texture_lighting                             
      GL_I3D_argb                                        
      GL_I3D_color_clamp                                 
      GL_I3D_interlace_read                              
      GL_IBM_clip_check                                  
      GL_IBM_cull_vertex                                 
      GL_IBM_load_named_matrix                           
      GL_IBM_multi_draw_arrays                           
      GL_IBM_multimode_draw_arrays                       
      GL_IBM_occlusion_cull                              
      GL_IBM_pixel_filter_hint                           
      GL_IBM_rasterpos_clip                              
      GL_IBM_rescale_normal                              
      GL_IBM_static_data                                 
      GL_IBM_texture_clamp_nodraw                        
      GL_IBM_texture_mirrored_repeat                     
      GL_IBM_vertex_array_lists                          
      GL_IBM_YCbCr                                       
      GL_INGR_blend_func_separate                        
      GL_INGR_color_clamp                                
      GL_INGR_interlace_read                             
      GL_INGR_multiple_palette                           
      GL_INTEL_parallel_arrays                           
      GL_INTEL_texture_scissor                           
      GL_KTX_buffer_region                               
      GL_MESA_pack_invert                                
      GL_MESA_resize_buffers                             
      GL_MESA_window_pos                                 
      GL_MESA_ycbcr_texture                              
      GL_MESAX_texture_stack                             
      GL_MTX_fragment_shader                             
      GL_MTX_precision_dpi                               
      GL_NV_blend_square                                 
      GL_NV_centroid_sample                              
      GL_NV_conditional_render                           
      GL_NV_copy_depth_to_color                          
      GL_NV_depth_buffer_float                           
      GL_NV_depth_clamp                                  
      GL_NV_depth_range_unclamped                        
      GL_NV_evaluators                                   
      GL_NV_explicit_multisample                         
      GL_NV_fence                                        
      GL_NV_float_buffer                                 
      GL_NV_fog_distance                                 
      GL_NV_fragment_program                             
      GL_NV_fragment_program_option                      
      GL_NV_fragment_program2                            
      GL_NV_fragment_program4                            
      GL_NV_framebuffer_multisample_coverage             
      GL_NV_framebuffer_multisample_ex                   
      GL_NV_geometry_program4                            
      GL_NV_geometry_shader4                             
      GL_NV_gpu_program4                                 
      GL_NV_half_float                                   
      GL_NV_light_max_exponent                           
      GL_NV_multisample_coverage                         
      GL_NV_multisample_filter_hint                      
      GL_NV_occlusion_query                              
      GL_NV_packed_depth_stencil                         
      GL_NV_parameter_buffer_object                      
      GL_NV_pixel_buffer_object                          
      GL_NV_pixel_data_range                             
      GL_NV_point_sprite                                 
      GL_NV_present_video                                
      GL_NV_primitive_restart                            
      GL_NV_register_combiners                           
      GL_NV_register_combiners2                          
      GL_NV_texgen_emboss                                
      GL_NV_texgen_reflection                            
      GL_NV_texture_compression_latc                     
      GL_NV_texture_compression_vtc                      
      GL_NV_texture_env_combine4                         
      GL_NV_texture_expand_normal                        
      GL_NV_texture_rectangle                            
      GL_NV_texture_shader                               
      GL_NV_texture_shader2                              
      GL_NV_texture_shader3                              
      GL_NV_timer_query                                  
      GL_NV_transform_feedback                           
      GL_NV_transform_feedback2                          
      GL_NV_vertex_array_range                           
      GL_NV_vertex_array_range2                          
      GL_NV_vertex_program                               
      GL_NV_vertex_program1_1                            
      GL_NV_vertex_program2                              
      GL_NV_vertex_program2_option                       
      GL_NV_vertex_program3                              
      GL_NV_vertex_program4                              
      GL_NVX_conditional_render                          
      GL_NVX_flush_hold                                  
      GL_NVX_ycrcb                                       
      GL_OES_byte_coordinates                            
      GL_OES_compressed_paletted_texture                 
      GL_OES_fixed_point                                 
      GL_OES_query_matrix                                
      GL_OES_read_format                                 
      GL_OES_single_precision                            
      GL_OML_interlace                                   
      GL_OML_resample                                    
      GL_OML_subsample                                   
      GL_PGI_misc_hints                                  
      GL_PGI_vertex_hints                                
      GL_REND_screen_coordinates                         
      GL_S3_performance_analyzer                         
      GL_S3_s3tc                                         
      GL_SGI_color_matrix                                
      GL_SGI_color_table                                 
      GL_SGI_compiled_vertex_array                       
      GL_SGI_cull_vertex                                 
      GL_SGI_index_array_formats                         
      GL_SGI_index_func                                  
      GL_SGI_index_material                              
      GL_SGI_index_texture                               
      GL_SGI_make_current_read                           
      GL_SGI_texture_add_env                             
      GL_SGI_texture_color_table                         
      GL_SGI_texture_edge_clamp                          
      GL_SGI_texture_lod                                 
      GL_SGIS_color_range                                
      GL_SGIS_detail_texture                             
      GL_SGIS_fog_function                               
      GL_SGIS_generate_mipmap                            
      GL_SGIS_multisample                                
      GL_SGIS_multitexture                               
      GL_SGIS_pixel_texture                              
      GL_SGIS_point_line_texgen                          
      GL_SGIS_sharpen_texture                            
      GL_SGIS_texture_border_clamp                       
      GL_SGIS_texture_color_mask                         
      GL_SGIS_texture_edge_clamp                         
      GL_SGIS_texture_filter4                            
      GL_SGIS_texture_lod                                
      GL_SGIS_texture_select                             
      GL_SGIS_texture4D                                  
      GL_SGIX_async                                      
      GL_SGIX_async_histogram                            
      GL_SGIX_async_pixel                                
      GL_SGIX_blend_alpha_minmax                         
      GL_SGIX_clipmap                                    
      GL_SGIX_convolution_accuracy                       
      GL_SGIX_depth_pass_instrument                      
      GL_SGIX_depth_texture                              
      GL_SGIX_flush_raster                               
      GL_SGIX_fog_offset                                 
      GL_SGIX_framezoom                                  
      GL_SGIX_instruments                                
      GL_SGIX_interlace                                  
      GL_SGIX_ir_instrument1                             
      GL_SGIX_list_priority                              
      GL_SGIX_pbuffer                                    
      GL_SGIX_pixel_texture                              
      GL_SGIX_pixel_texture_bits                         
      GL_SGIX_reference_plane                            
      GL_SGIX_resample                                   
      GL_SGIX_shadow                                     
      GL_SGIX_shadow_ambient                             
      GL_SGIX_sprite                                     
      GL_SGIX_subsample                                  
      GL_SGIX_tag_sample_buffer                          
      GL_SGIX_texture_add_env                            
      GL_SGIX_texture_coordinate_clamp                   
      GL_SGIX_texture_lod_bias                           
      GL_SGIX_texture_multi_buffer                       
      GL_SGIX_texture_range                              
      GL_SGIX_texture_scale_bias                         
      GL_SGIX_vertex_preclip                             
      GL_SGIX_vertex_preclip_hint                        
      GL_SGIX_ycrcb                                      
      GL_SGIX_ycrcb_subsample                            
      GL_SUN_convolution_border_modes                    
      GL_SUN_global_alpha                                
      GL_SUN_mesh_array                                  
      GL_SUN_multi_draw_arrays                           
      GL_SUN_slice_accum                                 
      GL_SUN_triangle_list                               
      GL_SUN_vertex                                      
      GL_SUNX_constant_data                              
      GL_WGL_ARB_extensions_string                       
      GL_WGL_EXT_extensions_string                       
      GL_WGL_EXT_swap_control                            
      GL_WIN_phong_shading                               
      GL_WIN_specular_fog                                
      GL_WIN_swap_hint                                  
      GLU_EXT_nurbs_tessellator                          
      GLU_EXT_object_space_tess                          
      GLU_SGI_filter4_parameters                         
      GLX_ARB_create_context                             
      GLX_ARB_fbconfig_float                             
      GLX_ARB_framebuffer_sRGB                           
      GLX_ARB_get_proc_address                           
      GLX_ARB_multisample                                
      GLX_EXT_fbconfig_packed_float                      
      GLX_EXT_framebuffer_sRGB                           
      GLX_EXT_import_context                             
      GLX_EXT_scene_marker                               
      GLX_EXT_texture_from_pixmap                        
      GLX_EXT_visual_info                                
      GLX_EXT_visual_rating                              
      GLX_MESA_agp_offset                                
      GLX_MESA_copy_sub_buffer                           
      GLX_MESA_pixmap_colormap                           
      GLX_MESA_release_buffers                           
      GLX_MESA_set_3dfx_mode                             
      GLX_NV_present_video                               
      GLX_NV_swap_group                                  
      GLX_NV_video_output                                
      GLX_OML_swap_method                                
      GLX_OML_sync_control                               
      GLX_SGI_cushion                                    
      GLX_SGI_make_current_read                          
      GLX_SGI_swap_control                               
      GLX_SGI_video_sync                                 
      GLX_SGIS_blended_overlay                           
      GLX_SGIS_color_range                               
      GLX_SGIS_multisample                               
      GLX_SGIX_dm_buffer                                 
      GLX_SGIX_fbconfig                                  
      GLX_SGIX_hyperpipe                                 
      GLX_SGIX_pbuffer                                   
      GLX_SGIX_swap_barrier                              
      GLX_SGIX_swap_group                                
      GLX_SGIX_video_resize                              
      GLX_SGIX_video_source                              
      GLX_SGIX_visual_select_group                       
      GLX_SUN_get_transparent_index                      
      GLX_SUN_video_resize                               
      WGL_3DFX_gamma_control                             
      WGL_3DFX_multisample                               
      WGL_3DL_stereo_control                             
      WGL_ARB_buffer_region                              
      WGL_ARB_create_context                             
      WGL_ARB_extensions_string                          
      WGL_ARB_framebuffer_sRGB                           
      WGL_ARB_make_current_read                          
      WGL_ARB_multisample                                
      WGL_ARB_pbuffer                                    
      WGL_ARB_pixel_format                               
      WGL_ARB_pixel_format_float                         
      WGL_ARB_render_texture                             
      WGL_ATI_pbuffer_memory_hint                        
      WGL_ATI_pixel_format_float                         
      WGL_ATI_render_texture_rectangle                   
      WGL_EXT_buffer_region                              
      WGL_EXT_depth_float                                
      WGL_EXT_display_color_table                        
      WGL_EXT_extensions_string                          
      WGL_EXT_framebuffer_sRGB                           
      WGL_EXT_framebuffer_sRGBWGL_ARB_create_context     
      WGL_EXT_gamma_control                              
      WGL_EXT_make_current_read                          
      WGL_EXT_multisample                                
      WGL_EXT_pbuffer                                    
      WGL_EXT_pixel_format                               
      WGL_EXT_pixel_format_packed_float                  
      WGL_EXT_render_texture                             
      WGL_EXT_swap_control                               
      WGL_EXT_swap_interval                              
      WGL_I3D_digital_video_control                      
      WGL_I3D_gamma                                      
      WGL_I3D_genlock                                    
      WGL_I3D_image_buffer                               
      WGL_I3D_swap_frame_lock                            
      WGL_I3D_swap_frame_usage                           
      WGL_MTX_video_preview                              
      WGL_NV_float_buffer                                
      WGL_NV_gpu_affinity                                
      WGL_NV_multisample_coverage                        
      WGL_NV_present_video                               
      WGL_NV_render_depth_texture                        
      WGL_NV_render_texture_rectangle                    
      WGL_NV_swap_group                                  
      WGL_NV_video_output                                
      WGL_OML_sync_control                               

       :
      RGB DXT1                                           
      RGBA DXT1                                          
      RGBA DXT3                                          
      RGBA DXT5                                          
      RGB FXT1                                           
      RGBA FXT1                                          
      3Dc                                                


--------[  ]------------------------------------------------------------------------------------------------------

    @Batang                                   Roman       Regular                      16 x 32   40 %
    @Batang                                   Roman       Regular                       16 x 32   40 %
    @Batang                                   Roman       Regular                        16 x 32   40 %
    @Batang                                   Roman       Regular                   16 x 32   40 %
    @Batang                                   Roman       Regular                        16 x 32   40 %
    @Batang                                   Roman       Regular                         16 x 32   40 %
    @Batang                                   Roman       Regular           16 x 32   40 %
    @BatangChe                                Modern      Regular                      16 x 32   40 %
    @BatangChe                                Modern      Regular                       16 x 32   40 %
    @BatangChe                                Modern      Regular                        16 x 32   40 %
    @BatangChe                                Modern      Regular                   16 x 32   40 %
    @BatangChe                                Modern      Regular                        16 x 32   40 %
    @BatangChe                                Modern      Regular                         16 x 32   40 %
    @BatangChe                                Modern      Regular           16 x 32   40 %
    @DFKai-SB                                 Script      Regular                        16 x 32   40 %
    @DFKai-SB                                 Script      Regular         (BIG5)        16 x 32   40 %
    @Dotum                                    Swiss       Regular                      16 x 32   40 %
    @Dotum                                    Swiss       Regular                       16 x 32   40 %
    @Dotum                                    Swiss       Regular                        16 x 32   40 %
    @Dotum                                    Swiss       Regular                   16 x 32   40 %
    @Dotum                                    Swiss       Regular                        16 x 32   40 %
    @Dotum                                    Swiss       Regular                         16 x 32   40 %
    @Dotum                                    Swiss       Regular           16 x 32   40 %
    @DotumChe                                 Modern      Regular                      16 x 32   40 %
    @DotumChe                                 Modern      Regular                       16 x 32   40 %
    @DotumChe                                 Modern      Regular                        16 x 32   40 %
    @DotumChe                                 Modern      Regular                   16 x 32   40 %
    @DotumChe                                 Modern      Regular                        16 x 32   40 %
    @DotumChe                                 Modern      Regular                         16 x 32   40 %
    @DotumChe                                 Modern      Regular           16 x 32   40 %
    @FangSong                                 Modern                              16 x 32   40 %
    @FangSong                                 Modern               (2312)        16 x 32   40 %
    @Gulim                                    Swiss       Regular                      16 x 32   40 %
    @Gulim                                    Swiss       Regular                       16 x 32   40 %
    @Gulim                                    Swiss       Regular                        16 x 32   40 %
    @Gulim                                    Swiss       Regular                   16 x 32   40 %
    @Gulim                                    Swiss       Regular                        16 x 32   40 %
    @Gulim                                    Swiss       Regular                         16 x 32   40 %
    @Gulim                                    Swiss       Regular           16 x 32   40 %
    @GulimChe                                 Modern      Regular                      16 x 32   40 %
    @GulimChe                                 Modern      Regular                       16 x 32   40 %
    @GulimChe                                 Modern      Regular                        16 x 32   40 %
    @GulimChe                                 Modern      Regular                   16 x 32   40 %
    @GulimChe                                 Modern      Regular                        16 x 32   40 %
    @GulimChe                                 Modern      Regular                         16 x 32   40 %
    @GulimChe                                 Modern      Regular           16 x 32   40 %
    @Gungsuh                                  Roman       Regular                      16 x 32   40 %
    @Gungsuh                                  Roman       Regular                       16 x 32   40 %
    @Gungsuh                                  Roman       Regular                        16 x 32   40 %
    @Gungsuh                                  Roman       Regular                   16 x 32   40 %
    @Gungsuh                                  Roman       Regular                        16 x 32   40 %
    @Gungsuh                                  Roman       Regular                         16 x 32   40 %
    @Gungsuh                                  Roman       Regular           16 x 32   40 %
    @GungsuhChe                               Modern      Regular                      16 x 32   40 %
    @GungsuhChe                               Modern      Regular                       16 x 32   40 %
    @GungsuhChe                               Modern      Regular                        16 x 32   40 %
    @GungsuhChe                               Modern      Regular                   16 x 32   40 %
    @GungsuhChe                               Modern      Regular                        16 x 32   40 %
    @GungsuhChe                               Modern      Regular                         16 x 32   40 %
    @GungsuhChe                               Modern      Regular           16 x 32   40 %
    @KaiTi                                    Modern                              16 x 32   40 %
    @KaiTi                                    Modern               (2312)        16 x 32   40 %
    @Malgun Gothic                            Swiss       Regular                        15 x 43   40 %
    @Malgun Gothic                            Swiss       Regular                         15 x 43   40 %
    @Meiryo UI                                Swiss                             17 x 41   40 %
    @Meiryo UI                                Swiss                              17 x 41   40 %
    @Meiryo UI                                Swiss                               17 x 41   40 %
    @Meiryo UI                                Swiss                          17 x 41   40 %
    @Meiryo UI                                Swiss                               17 x 41   40 %
    @Meiryo UI                                Swiss                  17 x 41   40 %
    @Meiryo UI                                Swiss                               17 x 41   40 %
    @Meiryo                                   Swiss                             31 x 48   40 %
    @Meiryo                                   Swiss                              31 x 48   40 %
    @Meiryo                                   Swiss                               31 x 48   40 %
    @Meiryo                                   Swiss                          31 x 48   40 %
    @Meiryo                                   Swiss                               31 x 48   40 %
    @Meiryo                                   Swiss                  31 x 48   40 %
    @Meiryo                                   Swiss                               31 x 48   40 %
    @Microsoft JhengHei                       Swiss                              15 x 43   40 %
    @Microsoft JhengHei                       Swiss                               15 x 43   40 %
    @Microsoft JhengHei                       Swiss                (BIG5)        15 x 43   40 %
    @Microsoft YaHei                          Swiss                              15 x 42   40 %
    @Microsoft YaHei                          Swiss                               15 x 42   40 %
    @Microsoft YaHei                          Swiss                          15 x 42   40 %
    @Microsoft YaHei                          Swiss                (2312)        15 x 42   40 %
    @Microsoft YaHei                          Swiss                               15 x 42   40 %
    @Microsoft YaHei                          Swiss                  15 x 42   40 %
    @MingLiU                                  Modern      Regular                        16 x 32   40 %
    @MingLiU                                  Modern      Regular         (BIG5)        16 x 32   40 %
    @MingLiU_HKSCS                            Roman       Regular                        16 x 32   40 %
    @MingLiU_HKSCS                            Roman       Regular         (BIG5)        16 x 32   40 %
    @MingLiU_HKSCS-ExtB                       Roman       Regular                        16 x 32   40 %
    @MingLiU_HKSCS-ExtB                       Roman       Regular         (BIG5)        16 x 32   40 %
    @MingLiU-ExtB                             Roman       Regular                        16 x 32   40 %
    @MingLiU-ExtB                             Roman       Regular         (BIG5)        16 x 32   40 %
    @MS Gothic                                Modern      Regular                      16 x 32   40 %
    @MS Gothic                                Modern      Regular                       16 x 32   40 %
    @MS Gothic                                Modern      Regular                        16 x 32   40 %
    @MS Gothic                                Modern      Regular                   16 x 32   40 %
    @MS Gothic                                Modern      Regular                        16 x 32   40 %
    @MS Gothic                                Modern      Regular           16 x 32   40 %
    @MS Gothic                                Modern      Regular                        16 x 32   40 %
    @MS Mincho                                Modern      Regular                      16 x 32   40 %
    @MS Mincho                                Modern      Regular                       16 x 32   40 %
    @MS Mincho                                Modern      Regular                        16 x 32   40 %
    @MS Mincho                                Modern      Regular                   16 x 32   40 %
    @MS Mincho                                Modern      Regular                        16 x 32   40 %
    @MS Mincho                                Modern      Regular           16 x 32   40 %
    @MS Mincho                                Modern      Regular                        16 x 32   40 %
    @MS PGothic                               Swiss       Regular                      13 x 32   40 %
    @MS PGothic                               Swiss       Regular                       13 x 32   40 %
    @MS PGothic                               Swiss       Regular                        13 x 32   40 %
    @MS PGothic                               Swiss       Regular                   13 x 32   40 %
    @MS PGothic                               Swiss       Regular                        13 x 32   40 %
    @MS PGothic                               Swiss       Regular           13 x 32   40 %
    @MS PGothic                               Swiss       Regular                        13 x 32   40 %
    @MS PMincho                               Roman       Regular                      13 x 32   40 %
    @MS PMincho                               Roman       Regular                       13 x 32   40 %
    @MS PMincho                               Roman       Regular                        13 x 32   40 %
    @MS PMincho                               Roman       Regular                   13 x 32   40 %
    @MS PMincho                               Roman       Regular                        13 x 32   40 %
    @MS PMincho                               Roman       Regular           13 x 32   40 %
    @MS PMincho                               Roman       Regular                        13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                      13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                       13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                        13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                   13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                        13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular           13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                        13 x 32   40 %
    @NSimSun                                  Modern      Regular                        16 x 32   40 %
    @NSimSun                                  Modern      Regular         (2312)        16 x 32   40 %
    @PMingLiU                                 Roman       Regular                        16 x 32   40 %
    @PMingLiU                                 Roman       Regular         (BIG5)        16 x 32   40 %
    @PMingLiU-ExtB                            Roman       Regular                        16 x 32   40 %
    @PMingLiU-ExtB                            Roman       Regular         (BIG5)        16 x 32   40 %
    @SimHei                                   Modern                              16 x 32   40 %
    @SimHei                                   Modern               (2312)        16 x 32   40 %
    @SimSun                                   Special     Regular                        16 x 32   40 %
    @SimSun                                   Special     Regular         (2312)        16 x 32   40 %
    @SimSun-ExtB                              Modern                              16 x 32   40 %
    @SimSun-ExtB                              Modern               (2312)        16 x 32   40 %
    Aharoni                                   Special                             15 x 32   70 %
    Andalus                                   Roman       Regular                        15 x 49   40 %
    Andalus                                   Roman       Regular                        15 x 49   40 %
    Angsana New                               Roman                                8 x 43   40 %
    Angsana New                               Roman                                 8 x 43   40 %
    AngsanaUPC                                Roman                                8 x 43   40 %
    AngsanaUPC                                Roman                                 8 x 43   40 %
    Aparajita                                 Swiss       Regular                        16 x 38   40 %
    Arabic Typesetting                        Script                               9 x 36   40 %
    Arabic Typesetting                        Script                             9 x 36   40 %
    Arabic Typesetting                        Script                               9 x 36   40 %
    Arabic Typesetting                        Script                               9 x 36   40 %
    Arabic Typesetting                        Script                  9 x 36   40 %
    Arial Black                               Swiss                             18 x 45   90 %
    Arial Black                               Swiss                              18 x 45   90 %
    Arial Black                               Swiss                               18 x 45   90 %
    Arial Black                               Swiss                          18 x 45   90 %
    Arial Black                               Swiss                               18 x 45   90 %
    Arial Black                               Swiss                  18 x 45   90 %
    Arial                                     Swiss                               14 x 36   40 %
    Arial                                     Swiss                             14 x 36   40 %
    Arial                                     Swiss                            14 x 36   40 %
    Arial                                     Swiss                              14 x 36   40 %
    Arial                                     Swiss                               14 x 36   40 %
    Arial                                     Swiss                                  14 x 36   40 %
    Arial                                     Swiss                          14 x 36   40 %
    Arial                                     Swiss                               14 x 36   40 %
    Arial                                     Swiss                  14 x 36   40 %
    Batang                                    Roman       Regular                      16 x 32   40 %
    Batang                                    Roman       Regular                       16 x 32   40 %
    Batang                                    Roman       Regular                        16 x 32   40 %
    Batang                                    Roman       Regular                   16 x 32   40 %
    Batang                                    Roman       Regular                        16 x 32   40 %
    Batang                                    Roman       Regular                         16 x 32   40 %
    Batang                                    Roman       Regular           16 x 32   40 %
    BatangChe                                 Modern      Regular                      16 x 32   40 %
    BatangChe                                 Modern      Regular                       16 x 32   40 %
    BatangChe                                 Modern      Regular                        16 x 32   40 %
    BatangChe                                 Modern      Regular                   16 x 32   40 %
    BatangChe                                 Modern      Regular                        16 x 32   40 %
    BatangChe                                 Modern      Regular                         16 x 32   40 %
    BatangChe                                 Modern      Regular           16 x 32   40 %
    Browallia New                             Swiss       Regular                         9 x 40   40 %
    Browallia New                             Swiss       Regular                          9 x 40   40 %
    BrowalliaUPC                              Swiss       Regular                         9 x 40   40 %
    BrowalliaUPC                              Swiss       Regular                          9 x 40   40 %
    Calibri                                   Swiss       Regular                      17 x 39   40 %
    Calibri                                   Swiss       Regular                     17 x 39   40 %
    Calibri                                   Swiss       Regular                       17 x 39   40 %
    Calibri                                   Swiss       Regular                        17 x 39   40 %
    Calibri                                   Swiss       Regular                   17 x 39   40 %
    Calibri                                   Swiss       Regular                        17 x 39   40 %
    Calibri                                   Swiss       Regular           17 x 39   40 %
    Cambria Math                              Roman       Regular                      20 x 179   40 %
    Cambria Math                              Roman       Regular                     20 x 179   40 %
    Cambria Math                              Roman       Regular                       20 x 179   40 %
    Cambria Math                              Roman       Regular                        20 x 179   40 %
    Cambria Math                              Roman       Regular                   20 x 179   40 %
    Cambria Math                              Roman       Regular                        20 x 179   40 %
    Cambria Math                              Roman       Regular           20 x 179   40 %
    Cambria                                   Roman       Regular                      20 x 38   40 %
    Cambria                                   Roman       Regular                     20 x 38   40 %
    Cambria                                   Roman       Regular                       20 x 38   40 %
    Cambria                                   Roman       Regular                        20 x 38   40 %
    Cambria                                   Roman       Regular                   20 x 38   40 %
    Cambria                                   Roman       Regular                        20 x 38   40 %
    Cambria                                   Roman       Regular           20 x 38   40 %
    Candara                                   Swiss       Regular                      17 x 39   40 %
    Candara                                   Swiss       Regular                     17 x 39   40 %
    Candara                                   Swiss       Regular                       17 x 39   40 %
    Candara                                   Swiss       Regular                        17 x 39   40 %
    Candara                                   Swiss       Regular                   17 x 39   40 %
    Candara                                   Swiss       Regular                        17 x 39   40 %
    Candara                                   Swiss       Regular           17 x 39   40 %
    Comic Sans MS                             Script                            15 x 45   40 %
    Comic Sans MS                             Script                             15 x 45   40 %
    Comic Sans MS                             Script                              15 x 45   40 %
    Comic Sans MS                             Script                         15 x 45   40 %
    Comic Sans MS                             Script                              15 x 45   40 %
    Comic Sans MS                             Script                 15 x 45   40 %
    Consolas                                  Modern      Regular                      18 x 37   40 %
    Consolas                                  Modern      Regular                     18 x 37   40 %
    Consolas                                  Modern      Regular                       18 x 37   40 %
    Consolas                                  Modern      Regular                        18 x 37   40 %
    Consolas                                  Modern      Regular                   18 x 37   40 %
    Consolas                                  Modern      Regular                        18 x 37   40 %
    Consolas                                  Modern      Regular           18 x 37   40 %
    Constantia                                Roman       Regular                      17 x 39   40 %
    Constantia                                Roman       Regular                     17 x 39   40 %
    Constantia                                Roman       Regular                       17 x 39   40 %
    Constantia                                Roman       Regular                        17 x 39   40 %
    Constantia                                Roman       Regular                   17 x 39   40 %
    Constantia                                Roman       Regular                        17 x 39   40 %
    Constantia                                Roman       Regular           17 x 39   40 %
    Corbel                                    Swiss       Regular                      17 x 39   40 %
    Corbel                                    Swiss       Regular                     17 x 39   40 %
    Corbel                                    Swiss       Regular                       17 x 39   40 %
    Corbel                                    Swiss       Regular                        17 x 39   40 %
    Corbel                                    Swiss       Regular                   17 x 39   40 %
    Corbel                                    Swiss       Regular                        17 x 39   40 %
    Corbel                                    Swiss       Regular           17 x 39   40 %
    Cordia New                                Swiss       Regular                         9 x 44   40 %
    Cordia New                                Swiss       Regular                          9 x 44   40 %
    CordiaUPC                                 Swiss       Regular                         9 x 44   40 %
    CordiaUPC                                 Swiss       Regular                          9 x 44   40 %
    Courier New                               Modern                              19 x 36   40 %
    Courier New                               Modern                            19 x 36   40 %
    Courier New                               Modern                           19 x 36   40 %
    Courier New                               Modern                             19 x 36   40 %
    Courier New                               Modern                              19 x 36   40 %
    Courier New                               Modern                                 19 x 36   40 %
    Courier New                               Modern                         19 x 36   40 %
    Courier New                               Modern                              19 x 36   40 %
    Courier New                               Modern                 19 x 36   40 %
    Courier                                   Roman                                  8 x 13   40 %
    DaunPenh                                  Special                             12 x 43   40 %
    David                                     Swiss       Regular                           13 x 31   40 %
    DFKai-SB                                  Script      Regular                        16 x 32   40 %
    DFKai-SB                                  Script      Regular         (BIG5)        16 x 32   40 %
    DilleniaUPC                               Roman                                9 x 42   40 %
    DilleniaUPC                               Roman                                 9 x 42   40 %
    DokChampa                                 Swiss                               19 x 62   40 %
    DokChampa                                 Swiss                                19 x 62   40 %
    Dotum                                     Swiss       Regular                      16 x 32   40 %
    Dotum                                     Swiss       Regular                       16 x 32   40 %
    Dotum                                     Swiss       Regular                        16 x 32   40 %
    Dotum                                     Swiss       Regular                   16 x 32   40 %
    Dotum                                     Swiss       Regular                        16 x 32   40 %
    Dotum                                     Swiss       Regular                         16 x 32   40 %
    Dotum                                     Swiss       Regular           16 x 32   40 %
    DotumChe                                  Modern      Regular                      16 x 32   40 %
    DotumChe                                  Modern      Regular                       16 x 32   40 %
    DotumChe                                  Modern      Regular                        16 x 32   40 %
    DotumChe                                  Modern      Regular                   16 x 32   40 %
    DotumChe                                  Modern      Regular                        16 x 32   40 %
    DotumChe                                  Modern      Regular                         16 x 32   40 %
    DotumChe                                  Modern      Regular           16 x 32   40 %
    Ebrima                                    Special                           19 x 43   40 %
    Ebrima                                    Special                             19 x 43   40 %
    Ebrima                                    Special                             19 x 43   40 %
    Ebrima                                    Special                19 x 43   40 %
    Estrangelo Edessa                         Script                              16 x 36   40 %
    EucrosiaUPC                               Roman                                9 x 39   40 %
    EucrosiaUPC                               Roman                                 9 x 39   40 %
    Euphemia                                  Swiss       Regular                        22 x 42   40 %
    FangSong                                  Modern                              16 x 32   40 %
    FangSong                                  Modern               (2312)        16 x 32   40 %
    Fixedsys                                  Swiss                                  8 x 16   40 %
    Franklin Gothic Medium                    Swiss                             14 x 36   40 %
    Franklin Gothic Medium                    Swiss                              14 x 36   40 %
    Franklin Gothic Medium                    Swiss                               14 x 36   40 %
    Franklin Gothic Medium                    Swiss                          14 x 36   40 %
    Franklin Gothic Medium                    Swiss                               14 x 36   40 %
    Franklin Gothic Medium                    Swiss                  14 x 36   40 %
    FrankRuehl                                Swiss       Regular                           13 x 30   40 %
    FreesiaUPC                                Swiss       Regular                         9 x 38   40 %
    FreesiaUPC                                Swiss       Regular                          9 x 38   40 %
    Gabriola                                  Decorative  Regular                      16 x 59   40 %
    Gabriola                                  Decorative  Regular                       16 x 59   40 %
    Gabriola                                  Decorative  Regular                        16 x 59   40 %
    Gabriola                                  Decorative  Regular                   16 x 59   40 %
    Gabriola                                  Decorative  Regular                        16 x 59   40 %
    Gabriola                                  Decorative  Regular           16 x 59   40 %
    Gautami                                   Swiss       Regular                        18 x 56   40 %
    Georgia                                   Roman                             14 x 36   40 %
    Georgia                                   Roman                              14 x 36   40 %
    Georgia                                   Roman                               14 x 36   40 %
    Georgia                                   Roman                          14 x 36   40 %
    Georgia                                   Roman                               14 x 36   40 %
    Georgia                                   Roman                  14 x 36   40 %
    Gisha                                     Swiss                               16 x 38   40 %
    Gisha                                     Swiss                                  16 x 38   40 %
    Gulim                                     Swiss       Regular                      16 x 32   40 %
    Gulim                                     Swiss       Regular                       16 x 32   40 %
    Gulim                                     Swiss       Regular                        16 x 32   40 %
    Gulim                                     Swiss       Regular                   16 x 32   40 %
    Gulim                                     Swiss       Regular                        16 x 32   40 %
    Gulim                                     Swiss       Regular                         16 x 32   40 %
    Gulim                                     Swiss       Regular           16 x 32   40 %
    GulimChe                                  Modern      Regular                      16 x 32   40 %
    GulimChe                                  Modern      Regular                       16 x 32   40 %
    GulimChe                                  Modern      Regular                        16 x 32   40 %
    GulimChe                                  Modern      Regular                   16 x 32   40 %
    GulimChe                                  Modern      Regular                        16 x 32   40 %
    GulimChe                                  Modern      Regular                         16 x 32   40 %
    GulimChe                                  Modern      Regular           16 x 32   40 %
    Gungsuh                                   Roman       Regular                      16 x 32   40 %
    Gungsuh                                   Roman       Regular                       16 x 32   40 %
    Gungsuh                                   Roman       Regular                        16 x 32   40 %
    Gungsuh                                   Roman       Regular                   16 x 32   40 %
    Gungsuh                                   Roman       Regular                        16 x 32   40 %
    Gungsuh                                   Roman       Regular                         16 x 32   40 %
    Gungsuh                                   Roman       Regular           16 x 32   40 %
    GungsuhChe                                Modern      Regular                      16 x 32   40 %
    GungsuhChe                                Modern      Regular                       16 x 32   40 %
    GungsuhChe                                Modern      Regular                        16 x 32   40 %
    GungsuhChe                                Modern      Regular                   16 x 32   40 %
    GungsuhChe                                Modern      Regular                        16 x 32   40 %
    GungsuhChe                                Modern      Regular                         16 x 32   40 %
    GungsuhChe                                Modern      Regular           16 x 32   40 %
    Impact                                    Swiss                             13 x 39   40 %
    Impact                                    Swiss                              13 x 39   40 %
    Impact                                    Swiss                               13 x 39   40 %
    Impact                                    Swiss                          13 x 39   40 %
    Impact                                    Swiss                               13 x 39   40 %
    Impact                                    Swiss                  13 x 39   40 %
    IrisUPC                                   Swiss       Regular                         9 x 40   40 %
    IrisUPC                                   Swiss       Regular                          9 x 40   40 %
    Iskoola Pota                              Swiss                               22 x 36   40 %
    JasmineUPC                                Roman       Regular                         9 x 34   40 %
    JasmineUPC                                Roman       Regular                          9 x 34   40 %
    KaiTi                                     Modern                              16 x 32   40 %
    KaiTi                                     Modern               (2312)        16 x 32   40 %
    Kalinga                                   Swiss       Regular                        19 x 48   40 %
    Kartika                                   Roman       Regular                        27 x 46   40 %
    Khmer UI                                  Swiss                               21 x 36   40 %
    KodchiangUPC                              Roman       Regular                         9 x 31   40 %
    KodchiangUPC                              Roman       Regular                          9 x 31   40 %
    Kokila                                    Swiss       Regular                        13 x 37   40 %
    Lao UI                                    Swiss                               18 x 43   40 %
    Latha                                     Swiss       Regular                        23 x 44   40 %
    Leelawadee                                Swiss                               17 x 38   40 %
    Leelawadee                                Swiss                                17 x 38   40 %
    Levenim MT                                Special     Regular                           16 x 42   40 %
    LilyUPC                                   Swiss                                9 x 30   40 %
    LilyUPC                                   Swiss                                 9 x 30   40 %
    Lucida Console                            Modern                             19 x 32   40 %
    Lucida Console                            Modern                              19 x 32   40 %
    Lucida Console                            Modern                         19 x 32   40 %
    Lucida Console                            Modern                              19 x 32   40 %
    Lucida Console                            Modern                 19 x 32   40 %
    Lucida Sans Unicode                       Swiss                             16 x 49   40 %
    Lucida Sans Unicode                       Swiss                              16 x 49   40 %
    Lucida Sans Unicode                       Swiss                               16 x 49   40 %
    Lucida Sans Unicode                       Swiss                                  16 x 49   40 %
    Lucida Sans Unicode                       Swiss                          16 x 49   40 %
    Lucida Sans Unicode                       Swiss                               16 x 49   40 %
    Lucida Sans Unicode                       Swiss                  16 x 49   40 %
    Malgun Gothic                             Swiss       Regular                        15 x 43   40 %
    Malgun Gothic                             Swiss       Regular                         15 x 43   40 %
    Mangal                                    Roman       Regular                        19 x 54   40 %
    Marlett                                   Special     Regular                      31 x 32   50 %
    Meiryo UI                                 Swiss                             17 x 41   40 %
    Meiryo UI                                 Swiss                              17 x 41   40 %
    Meiryo UI                                 Swiss                               17 x 41   40 %
    Meiryo UI                                 Swiss                          17 x 41   40 %
    Meiryo UI                                 Swiss                               17 x 41   40 %
    Meiryo UI                                 Swiss                  17 x 41   40 %
    Meiryo UI                                 Swiss                               17 x 41   40 %
    Meiryo                                    Swiss                             31 x 48   40 %
    Meiryo                                    Swiss                              31 x 48   40 %
    Meiryo                                    Swiss                               31 x 48   40 %
    Meiryo                                    Swiss                          31 x 48   40 %
    Meiryo                                    Swiss                               31 x 48   40 %
    Meiryo                                    Swiss                  31 x 48   40 %
    Meiryo                                    Swiss                               31 x 48   40 %
    Microsoft Himalaya                        Special                             13 x 32   40 %
    Microsoft JhengHei                        Swiss                              15 x 43   40 %
    Microsoft JhengHei                        Swiss                               15 x 43   40 %
    Microsoft JhengHei                        Swiss                (BIG5)        15 x 43   40 %
    Microsoft New Tai Lue                     Swiss       Regular                        19 x 42   40 %
    Microsoft PhagsPa                         Swiss       Regular                        24 x 41   40 %
    Microsoft Sans Serif                      Swiss                               14 x 36   40 %
    Microsoft Sans Serif                      Swiss                             14 x 36   40 %
    Microsoft Sans Serif                      Swiss                            14 x 36   40 %
    Microsoft Sans Serif                      Swiss                              14 x 36   40 %
    Microsoft Sans Serif                      Swiss                               14 x 36   40 %
    Microsoft Sans Serif                      Swiss                                  14 x 36   40 %
    Microsoft Sans Serif                      Swiss                          14 x 36   40 %
    Microsoft Sans Serif                      Swiss                                14 x 36   40 %
    Microsoft Sans Serif                      Swiss                               14 x 36   40 %
    Microsoft Sans Serif                      Swiss                  14 x 36   40 %
    Microsoft Tai Le                          Swiss       Regular                        19 x 41   40 %
    Microsoft Uighur                          Special                             13 x 32   40 %
    Microsoft Uighur                          Special                             13 x 32   40 %
    Microsoft YaHei                           Swiss                              15 x 42   40 %
    Microsoft YaHei                           Swiss                               15 x 42   40 %
    Microsoft YaHei                           Swiss                          15 x 42   40 %
    Microsoft YaHei                           Swiss                (2312)        15 x 42   40 %
    Microsoft YaHei                           Swiss                               15 x 42   40 %
    Microsoft YaHei                           Swiss                  15 x 42   40 %
    Microsoft Yi Baiti                        Script                              21 x 32   40 %
    MingLiU                                   Modern      Regular                        16 x 32   40 %
    MingLiU                                   Modern      Regular         (BIG5)        16 x 32   40 %
    MingLiU_HKSCS                             Roman       Regular                        16 x 32   40 %
    MingLiU_HKSCS                             Roman       Regular         (BIG5)        16 x 32   40 %
    MingLiU_HKSCS-ExtB                        Roman       Regular                        16 x 32   40 %
    MingLiU_HKSCS-ExtB                        Roman       Regular         (BIG5)        16 x 32   40 %
    MingLiU-ExtB                              Roman       Regular                        16 x 32   40 %
    MingLiU-ExtB                              Roman       Regular         (BIG5)        16 x 32   40 %
    Miriam Fixed                              Modern      Regular                           19 x 32   40 %
    Miriam                                    Swiss       Regular                           13 x 32   40 %
    Modern                                    Modern                     OEM/DOS                 19 x 37   40 %
    Mongolian Baiti                           Script                              14 x 34   40 %
    MoolBoran                                 Swiss                               13 x 43   40 %
    MS Gothic                                 Modern      Regular                      16 x 32   40 %
    MS Gothic                                 Modern      Regular                       16 x 32   40 %
    MS Gothic                                 Modern      Regular                        16 x 32   40 %
    MS Gothic                                 Modern      Regular                   16 x 32   40 %
    MS Gothic                                 Modern      Regular                        16 x 32   40 %
    MS Gothic                                 Modern      Regular           16 x 32   40 %
    MS Gothic                                 Modern      Regular                        16 x 32   40 %
    MS Mincho                                 Modern      Regular                      16 x 32   40 %
    MS Mincho                                 Modern      Regular                       16 x 32   40 %
    MS Mincho                                 Modern      Regular                        16 x 32   40 %
    MS Mincho                                 Modern      Regular                   16 x 32   40 %
    MS Mincho                                 Modern      Regular                        16 x 32   40 %
    MS Mincho                                 Modern      Regular           16 x 32   40 %
    MS Mincho                                 Modern      Regular                        16 x 32   40 %
    MS PGothic                                Swiss       Regular                      13 x 32   40 %
    MS PGothic                                Swiss       Regular                       13 x 32   40 %
    MS PGothic                                Swiss       Regular                        13 x 32   40 %
    MS PGothic                                Swiss       Regular                   13 x 32   40 %
    MS PGothic                                Swiss       Regular                        13 x 32   40 %
    MS PGothic                                Swiss       Regular           13 x 32   40 %
    MS PGothic                                Swiss       Regular                        13 x 32   40 %
    MS PMincho                                Roman       Regular                      13 x 32   40 %
    MS PMincho                                Roman       Regular                       13 x 32   40 %
    MS PMincho                                Roman       Regular                        13 x 32   40 %
    MS PMincho                                Roman       Regular                   13 x 32   40 %
    MS PMincho                                Roman       Regular                        13 x 32   40 %
    MS PMincho                                Roman       Regular           13 x 32   40 %
    MS PMincho                                Roman       Regular                        13 x 32   40 %
    MS Sans Serif                             Swiss                                  5 x 13   40 %
    MS Serif                                  Roman                                  5 x 13   40 %
    MS UI Gothic                              Swiss       Regular                      13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                       13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                        13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                   13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                        13 x 32   40 %
    MS UI Gothic                              Swiss       Regular           13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                        13 x 32   40 %
    MV Boli                                   Special                             18 x 52   40 %
    Narkisim                                  Swiss       Regular                           12 x 32   40 %
    NSimSun                                   Modern      Regular                        16 x 32   40 %
    NSimSun                                   Modern      Regular         (2312)        16 x 32   40 %
    Nyala                                     Special                           18 x 33   40 %
    Nyala                                     Special                             18 x 33   40 %
    Nyala                                     Special                             18 x 33   40 %
    Nyala                                     Special                18 x 33   40 %
    Palatino Linotype                         Roman                             14 x 43   40 %
    Palatino Linotype                         Roman                            14 x 43   40 %
    Palatino Linotype                         Roman                              14 x 43   40 %
    Palatino Linotype                         Roman                               14 x 43   40 %
    Palatino Linotype                         Roman                          14 x 43   40 %
    Palatino Linotype                         Roman                               14 x 43   40 %
    Palatino Linotype                         Roman                  14 x 43   40 %
    Plantagenet Cherokee                      Roman                               14 x 41   40 %
    PMingLiU                                  Roman       Regular                        16 x 32   40 %
    PMingLiU                                  Roman       Regular         (BIG5)        16 x 32   40 %
    PMingLiU-ExtB                             Roman       Regular                        16 x 32   40 %
    PMingLiU-ExtB                             Roman       Regular         (BIG5)        16 x 32   40 %
    Raavi                                     Swiss       Regular                        13 x 53   40 %
    Rod                                       Modern      Regular                           19 x 31   40 %
    Roman                                     Roman                      OEM/DOS                 22 x 37   40 %
    Sakkal Majalla                            Special                             16 x 45   40 %
    Sakkal Majalla                            Special                           16 x 45   40 %
    Sakkal Majalla                            Special                             16 x 45   40 %
    Sakkal Majalla                            Special                             16 x 45   40 %
    Sakkal Majalla                            Special                16 x 45   40 %
    Script                                    Script                     OEM/DOS                 16 x 36   40 %
    Segoe Print                               Special     Regular                      21 x 56   40 %
    Segoe Print                               Special     Regular                       21 x 56   40 %
    Segoe Print                               Special     Regular                        21 x 56   40 %
    Segoe Print                               Special     Regular                   21 x 56   40 %
    Segoe Print                               Special     Regular                        21 x 56   40 %
    Segoe Print                               Special     Regular           21 x 56   40 %
    Segoe Script                              Swiss                             22 x 51   40 %
    Segoe Script                              Swiss                              22 x 51   40 %
    Segoe Script                              Swiss                               22 x 51   40 %
    Segoe Script                              Swiss                          22 x 51   40 %
    Segoe Script                              Swiss                               22 x 51   40 %
    Segoe Script                              Swiss                  22 x 51   40 %
    Segoe UI Light                            Swiss       Regular                      17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                     17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                       17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                        17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                   17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                        17 x 43   30 %
    Segoe UI Light                            Swiss       Regular           17 x 43   30 %
    Segoe UI Semibold                         Swiss       Regular                      18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                     18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                       18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                        18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                   18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                        18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular           18 x 43   60 %
    Segoe UI Symbol                           Swiss                               23 x 43   40 %
    Segoe UI                                  Swiss                               17 x 43   40 %
    Segoe UI                                  Swiss                             17 x 43   40 %
    Segoe UI                                  Swiss                            17 x 43   40 %
    Segoe UI                                  Swiss                              17 x 43   40 %
    Segoe UI                                  Swiss                               17 x 43   40 %
    Segoe UI                                  Swiss                          17 x 43   40 %
    Segoe UI                                  Swiss                               17 x 43   40 %
    Segoe UI                                  Swiss                  17 x 43   40 %
    Shonar Bangla                             Swiss       Regular                        16 x 41   40 %
    Shruti                                    Swiss       Regular                        14 x 54   40 %
    SimHei                                    Modern                              16 x 32   40 %
    SimHei                                    Modern               (2312)        16 x 32   40 %
    Simplified Arabic Fixed                   Modern      Regular                        19 x 35   40 %
    Simplified Arabic Fixed                   Modern      Regular                        19 x 35   40 %
    Simplified Arabic                         Roman       Regular                        13 x 53   40 %
    Simplified Arabic                         Roman       Regular                        13 x 53   40 %
    SimSun                                    Special     Regular                        16 x 32   40 %
    SimSun                                    Special     Regular         (2312)        16 x 32   40 %
    SimSun-ExtB                               Modern                              16 x 32   40 %
    SimSun-ExtB                               Modern               (2312)        16 x 32   40 %
    Small Fonts                               Swiss                                   1 x 3   40 %
    Sylfaen                                   Roman                             13 x 42   40 %
    Sylfaen                                   Roman                              13 x 42   40 %
    Sylfaen                                   Roman                               13 x 42   40 %
    Sylfaen                                   Roman                          13 x 42   40 %
    Sylfaen                                   Roman                               13 x 42   40 %
    Sylfaen                                   Roman                  13 x 42   40 %
    Symbol                                    Roman                             19 x 39   40 %
    System                                    Swiss                                  7 x 16   70 %
    Tahoma                                    Swiss                               14 x 39   40 %
    Tahoma                                    Swiss                             14 x 39   40 %
    Tahoma                                    Swiss                            14 x 39   40 %
    Tahoma                                    Swiss                              14 x 39   40 %
    Tahoma                                    Swiss                               14 x 39   40 %
    Tahoma                                    Swiss                                  14 x 39   40 %
    Tahoma                                    Swiss                          14 x 39   40 %
    Tahoma                                    Swiss                                14 x 39   40 %
    Tahoma                                    Swiss                               14 x 39   40 %
    Tahoma                                    Swiss                  14 x 39   40 %
    Terminal                                  Modern                     OEM/DOS                  8 x 12   40 %
    Times New Roman                           Roman                               13 x 35   40 %
    Times New Roman                           Roman                             13 x 35   40 %
    Times New Roman                           Roman                            13 x 35   40 %
    Times New Roman                           Roman                              13 x 35   40 %
    Times New Roman                           Roman                               13 x 35   40 %
    Times New Roman                           Roman                                  13 x 35   40 %
    Times New Roman                           Roman                          13 x 35   40 %
    Times New Roman                           Roman                               13 x 35   40 %
    Times New Roman                           Roman                  13 x 35   40 %
    Traditional Arabic                        Roman       Regular                        15 x 48   40 %
    Traditional Arabic                        Roman       Regular                        15 x 48   40 %
    Trebuchet MS                              Swiss                             15 x 37   40 %
    Trebuchet MS                              Swiss                              15 x 37   40 %
    Trebuchet MS                              Swiss                               15 x 37   40 %
    Trebuchet MS                              Swiss                          15 x 37   40 %
    Trebuchet MS                              Swiss                               15 x 37   40 %
    Trebuchet MS                              Swiss                  15 x 37   40 %
    Tunga                                     Swiss       Regular                        18 x 53   40 %
    Utsaah                                    Swiss       Regular                        13 x 36   40 %
    Vani                                      Swiss       Regular                        23 x 54   40 %
    Verdana                                   Swiss                             16 x 39   40 %
    Verdana                                   Swiss                            16 x 39   40 %
    Verdana                                   Swiss                              16 x 39   40 %
    Verdana                                   Swiss                               16 x 39   40 %
    Verdana                                   Swiss                          16 x 39   40 %
    Verdana                                   Swiss                               16 x 39   40 %
    Verdana                                   Swiss                  16 x 39   40 %
    Vijaya                                    Swiss       Regular                        19 x 32   40 %
    Vrinda                                    Swiss       Regular                        20 x 44   40 %
    Webdings                                  Roman                             31 x 32   40 %
    Wingdings                                 Special     Regular                      28 x 36   40 %


--------[  Windows ]-----------------------------------------------------------------------------------------------

    midi-out.0   0001 001B  Microsoft GS Wavetable Synth
    mixer.0      0001 FFFF    (S/PDIF) (2- 
    wave-out.0   0001 FFFF    (S/PDIF) (2- 


--------[  PCI / PnP ]---------------------------------------------------------------------------------------------

    Realtek ALC883 @ nVIDIA MCP65 - High Definition Audio Controller                  PCI


--------[ HD Audio ]----------------------------------------------------------------------------------------------------

  [ nVIDIA MCP65 - High Definition Audio Controller ]

     :
                                      nVIDIA MCP65 - High Definition Audio Controller
        (Windows)                      High Definition Audio (Microsoft)
                                                 PCI
      ID                                      10DE-044A
                               1043-8286
                                                  A1
       ID                                     PCI\VEN_10DE&DEV_044A&SUBSYS_82861043&REV_A1

  [ Realtek ALC883 ]

     :
                                      Realtek ALC883
        (Windows)                        High Definition Audio
                                           Audio
                                                 HDAUDIO
      ID                                      10EC-0883
                               1043-8286
                                                  1000
       ID                                     HDAUDIO\FUNC_01&VEN_10EC&DEV_0883&SUBSYS_10438286&REV_1000


--------[   ]------------------------------------------------------------------------------------------------

  [ Fraunhofer IIS MPEG Layer-3 Codec (decode only) ]

      ACM:
                                        Fraunhofer IIS MPEG Layer-3 Codec (decode only)
      Copyright-                                  Copyright  1996-1999 Fraunhofer Institut Integrierte Schaltungen IIS
                                         decoder only version
                                          1.09

  [  ADPCM (Microsoft) ]

      ACM:
                                         ADPCM (Microsoft)
      Copyright-                                    , 1992-1996.
                                             Microsoft ADPCM.
                                          4.00

  [  CCITT G.711 A-Law  u-Law (Microsoft) ]

      ACM:
                                         CCITT G.711 A-Law  u-Law (Microsoft)
      Copyright-                                  ()  , 1993-1996.
                                             CCITT G.711 A-Law / u-Law.
                                          4.00

  [  GSM 6.10 (Microsoft) ]

      ACM:
                                         GSM 6.10 (Microsoft)
      Copyright-                                  ()  , 1993-1996.
                                                 ETSI-GSM (European Telecommunications Standards Institute-Groupe Special Mobile)  6.10.
                                          4.00

  [  IMA ADPCM (Microsoft) ]

      ACM:
                                         IMA ADPCM (Microsoft)
      Copyright-                                    , 1992-1996.
                                             IMA ADPCM.
                                          4.00

  [  PCM Microsoft ]

      ACM:
                                         PCM Microsoft
      Copyright-                                    , 1992-1996.
                                                PCM.
                                          5.00


--------[   ]------------------------------------------------------------------------------------------------

    iccvid.dll                 1.10.0.11                            Cinepak
    iyuv_32.dll                6.1.7600.16385 (win7_rtm.090713-1255)  Intel Indeo(R) Video YUV 
    msrle32.dll                6.1.7600.16385 (win7_rtm.090713-1255)  Microsoft RLE Compressor
    msvidc32.dll               6.1.7600.16385 (win7_rtm.090713-1255)    Microsoft Video 1
    msyuv.dll                  6.1.7601.17514 (win7sp1_rtm.101119-1850)  Microsoft UYVY Video Decompressor
    tsbyuv.dll                 6.1.7601.17514 (win7sp1_rtm.101119-1850)  Toshiba Video Codec


--------[ MCI ]---------------------------------------------------------------------------------------------------------

  [ AVIVideo ]

      MCI:
                                              AVIVideo
                                                       Windows
                                                 MCI Video  Windows
                                                     Digital Video Device
                                                 mciavi32.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                 
                                                  
                                        
      ''                             
                                      
                                         
                                         
                                            
                                          
                                          
                                

  [ CDAudio ]

      MCI:
                                              CDAudio
                                                     -
                                                 MCI   cdaudio
                                                     CD Audio Device
                                                 mcicda.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                                  
                                        
                                          
                                          

  [ MPEGVideo ]

      MCI:
                                              MPEGVideo
                                                     DirectShow
                                                 MCI DirectShow
                                                     Digital Video Device
                                                 mciqtz32.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                 
                                                  
                                        
      ''                             
                                      
                                         
                                         
                                            
                                          
                                          
                                

  [ Sequencer ]

      MCI:
                                              Sequencer
                                                      MIDI
                                                 MCI   MIDI
                                                     Sequencer Device
                                                 mciseq.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                                  
                                        
                                          
                                          

  [ WaveAudio ]

      MCI:
                                              WaveAudio
                                                     Sound
                                                 MCI   
                                                     Waveform Audio Device
                                                 mciwave.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                                  
                                        
                                          
                                          


--------[   Windows ]-------------------------------------------------------------------------------------

  [ ST3250410AS ATA Device ]

     :
                                        ST3250410AS ATA Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf

       :
                                           Seagate
                                   Barracuda 7200.10 250410
      -                                       3.5"
                                  250 
                                                   1
                                 2
                                      146.99 x 101.6 x 19.99 mm
                                         365 g
                                4.16 ms
                                        7200 RPM
                                               SATA-II
        '-'                300 /
                                             16 

     :
                                                   Seagate Technology LLC
                                     http://www.seagate.com/products

  [ PIONEER DVD-RW  DVR-219L ATA Device ]

     :
                                        PIONEER DVD-RW  DVR-219L ATA Device
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          cdrom.inf

     :
                                                   Pioneer Corporation
                                     http://www.pioneer-eur.com/eur/productgroups.jsp
       firmware                                 http://www.pioneer-eur.com/eur/content/support/support.html

  [ ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          mshdc.inf

     :
      IRQ                                               14
                                                    01F0-01F7
                                                    03F6-03F6

  [ ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          mshdc.inf

  [ ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          mshdc.inf

     :
      IRQ                                               15
                                                    0170-0177
                                                    0376-0376

  [ ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          mshdc.inf

  [    PCI IDE ]

     :
                                           PCI IDE
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          mshdc.inf

     :
      IRQ                                               21
                                                  DBFF2000-DBFF3FFF
                                                    0E00-0E03
                                                    0E80-0E87
                                                    0F00-0F03
                                                    0F80-0F87
                                                    C480-C48F

  [    PCI IDE ]

     :
                                           PCI IDE
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          mshdc.inf

     :
                                                    FFA0-FFAF

  [     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          fdc.inf

     :
      DMA                                               02
      IRQ                                               06
                                                    03F0-03F5
                                                    03F7-03F7


--------[   ]--------------------------------------------------------------------------------------------

    C:                                               NTFS          20002       10065        9937    50 %  B4AA-E5BC
    D: (WORK)                                        NTFS         218469      173149       45320    21 %  00CA-A46F
    E:                                                                                                               


--------[   ]--------------------------------------------------------------------------------------------

  [  #1 - ST3250410AS (232 ) ]

    #1 ()    NTFS             C:                                              0 MB    20002 MB
    #2               NTFS             D: (WORK)                                   20002 MB   218469 MB


--------[   ]---------------------------------------------------------------------------------------

  [ E:\  PIONEER DVD-RW  DVR-219L ATA Device ]

      :
                                      PIONEER DVD-RW  DVR-219L ATA Device
                                           JJQC359977WL
       firmware                                   1.01
                                             2000 
                                              
                               5
                                      4

      :
      BD-ROM                                             
      BD-R                                               
      BD-RE                                              
      HD DVD-ROM                                         
      HD DVD-R                                           
      HD DVD-RW                                          
      DVD-ROM                                           
      DVD+R9 Dual Layer                                  + 
      DVD+R                                              + 
      DVD+RW                                             + 
      DVD-R9 Dual Layer                                  + 
      DVD-R                                              + 
      DVD-RW                                             + 
      DVD-RAM                                            + 
      CD-ROM                                            
      CD-R                                               + 
      CD-RW                                              + 

      :
      Buffer Underrun Protection                        
      C2 Error Pointers                                 
      CD+G                                              
      CD-Text                                           
      Hybrid Disc                                        
      JustLink                                          
      LabelFlash                                        
      Layer-Jump Recording                              
      LightScribe                                        
      Mount Rainier                                      
      SMART                                             
      CSS                                               
      CPRM                                              
      AACS                                               
      VCPS                                               
      BD CPS                                             


--------[ ATA ]---------------------------------------------------------------------------------------------------------

  [ ST3250410AS (6RY150QB) ]

      ATA:
      ID                                          ST3250410AS
                                           6RY150QB
                                                  3.AAA
                                           SATA
                                               : 484521, : 16,   : 63,   : 512
       LBA                                       488397168
                                                   16 
                                           16
       ECC                                         4
                                238475 

      ATA:
      48-bit LBA                                        
       (APM)                             
      Automatic Acoustic Management                      
      Device Configuration Overlay                      
      DMA Setup Auto-Activate                            
      General Purpose Logging                           
      Host Protected Area                               , 
      In-Order Data Delivery                             
      Native Command Queuing                            
      Phy Event Counters                                
                                          , 
      Power-Up In Standby                                
      Read Look-Ahead                                   , 
      Release Interrupt                                  
                                       , 
      SMART                                             , 
      SMART Error Logging                               
      SMART Self-Test                                   
      Software Settings Preservation                    , 
      Streaming                                          
      Tagged Command Queuing                             
                                               , 

       ATA:
                                           Seagate
                                   Barracuda 7200.10 250410
      -                                       3.5"
                                  250 
                                                   1
                                 2
                                      146.99 x 101.6 x 19.99 mm
                                         365 g
                                4.16 ms
                                        7200 RPM
                                               SATA-II
        '-'                300 /
                                             16 

     ATA-:
                                                   Seagate Technology LLC
                                     http://www.seagate.com/products


--------[ SMART ]-------------------------------------------------------------------------------------------------------

  [ ST3250410AS (6RY150QB) ]

    01  Raw Read Error Rate                  6    114  99     68445599  OK:  
    03  Spinup Time                          0    97   97            0  OK:  
    04  Start/Stop Count                     20   97   97         3688  OK:  
    05  Reallocated Sector Count             36   100  100           0  OK:  
    07  Seek Error Rate                      30   80   60    106740224  OK:  
    09  Power-On Time Count                  0    94   94         5835  OK:  
    0A  Spinup Retry Count                   97   100  100           0  OK:  
    0C  Power Cycle Count                    20   97   97         3356  OK:  
    BB  <  >              0    100  100           0  OK:  
    BD  <  >              0    100  100           0  OK:  
    BE  Airflow Temperature                  45   65   52    589365283  OK:  
    C2  Temperature                          0    35   48           35  OK:  
    C3  Hardware ECC Recovered               0    73   60    157270008  OK:  
    C5  Current Pending Sector Count         0    100  100           0  OK:  
    C6  Offline Uncorrectable Sector Count   0    100  100           0  OK:  
    C7  Ultra ATA CRC Error Rate             0    200  200           0  OK:  
    C8  Write Error Rate                     0    100  253           0  OK:  
    CA  Data Address Mark Errors             0    100  253           0  OK:  


--------[  Windows ]------------------------------------------------------------------------------------------------

  [   NVIDIA nForce ]

      :
                                            NVIDIA nForce
                                           Ethernet
                                         00-1B-FC-89-6F-8C
                                                  2
      MTU                                               1500 
                                            0
                                          0


--------[  PCI / PnP ]----------------------------------------------------------------------------------------------

    nVIDIA MCP65 - LAN Controller (PHY: Atheros AR8012)                               PCI


--------[ IAM ]---------------------------------------------------------------------------------------------------------

  [ Microsoft Communities ]

      :
                                        Microsoft Communities
      ID                                   account{AA373812-A8C4-4489-AD74-FF0E943AED1C}.oeaccount
                                         ( )
                                                (IE  )
      NNTP-                                       msnews.microsoft.com

      :
        NNTP                                
        NNTP                     
        NNTP                        
         NNTP             
       NNTP                
       NNTP   HTML                         

  [ Active Directory ]

      :
                                        Active Directory
      ID                                   account{AF166C9D-E9FA-4C58-A3B4-EF2E89B95CB7}.oeaccount
                                        LDAP
                                                (IE  )
      LDAP-                                       NULL:3268
        LDAP                             NULL
        LDAP                               NULL
        LDAP                               1 

      :
        LDAP                      
        LDAP                     
        LDAP                        
         LDAP                     

  [    VeriSign ]

      :
                                           VeriSign
      ID                                   account{2B6A4889-E2B7-4B7E-B84D-C377C5C3A3C6}.oeaccount
                                        LDAP
                                                (IE  )
      LDAP-                                       directory.verisign.com
      LDAP URL                                          http://www.verisign.com
        LDAP                               NULL
        LDAP                               1 

      :
        LDAP                      
        LDAP                     
        LDAP                        
         LDAP                     


--------[  ]----------------------------------------------------------------------------------------------------

     :
                                        http://go.microsoft.com/fwlink/?LinkId=69157
                                          http://go.microsoft.com/fwlink/?LinkId=54896
                               

     :
                                            

    LAN-:
                                            


--------[  ]----------------------------------------------------------------------------------------------------

                127.0.0.0        255.0.0.0        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
                127.0.0.1  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
          127.255.255.255  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
                224.0.0.0        240.0.0.0        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
          255.255.255.255  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)


--------[   ]--------------------------------------------------------------------------------------------

    2002-01-04 21:39:00  user@file:///E:/Activators/Readme.txt
    2002-01-04 23:16:18  user@file:///C:/Windows/Minidump/010202-13462-01.dmp
    2002-01-06 14:50:07  user@file:///C:/Users/user/Desktop/Report.htm


--------[  DirectX ]-----------------------------------------------------------------------------------------------

    amstream.dll                              6.06.7601.17514   Final Retail                         70656  20.11.2010 23:29:07
    bdaplgin.ax                               6.01.7600.16385   Final Retail                         74240  14.07.2009 3:14:10
    d3d8.dll                                  6.01.7600.16385   Final Retail                    1036800  14.07.2009 3:15:08
    d3d8thk.dll                               6.01.7600.16385   Final Retail                      11264  14.07.2009 3:15:08
    d3d9.dll                                  6.01.7601.17514   Final Retail                    1828352  20.11.2010 23:29:19
    d3dim.dll                                 6.01.7600.16385   Final Retail                     386048  14.07.2009 3:15:08
    d3dim700.dll                              6.01.7600.16385   Final Retail                     817664  14.07.2009 3:15:08
    d3dramp.dll                               6.01.7600.16385   Final Retail                     593920  14.07.2009 3:15:08
    d3dxof.dll                                6.01.7600.16385   Final Retail                      53760  14.07.2009 3:15:08
    ddraw.dll                                 6.01.7600.16385   Final Retail                        531968  14.07.2009 3:15:10
    ddrawex.dll                               6.01.7600.16385   Final Retail                      30208  14.07.2009 3:15:10
    devenum.dll                               6.06.7600.16385   Final Retail                         66560  14.07.2009 3:15:10
    dinput.dll                                6.01.7600.16385   Final Retail                        136704  14.07.2009 3:15:11
    dinput8.dll                               6.01.7600.16385   Final Retail                        145408  14.07.2009 3:15:11
    dmband.dll                                6.01.7600.16385   Final Retail                      30720  14.07.2009 3:15:12
    dmcompos.dll                              6.01.7600.16385   Final Retail                      63488  14.07.2009 3:15:12
    dmime.dll                                 6.01.7600.16385   Final Retail                     179712  14.07.2009 3:15:12
    dmloader.dll                              6.01.7600.16385   Final Retail                      38400  14.07.2009 3:15:12
    dmscript.dll                              6.01.7600.16385   Final Retail                      86016  14.07.2009 3:15:12
    dmstyle.dll                               6.01.7600.16385   Final Retail                     105984  14.07.2009 3:15:12
    dmsynth.dll                               6.01.7600.16385   Final Retail                     105472  14.07.2009 3:15:12
    dmusic.dll                                6.01.7600.16385   Final Retail                        101376  14.07.2009 3:15:12
    dplaysvr.exe                              6.01.7600.16385   Final Retail                         29184  14.07.2009 3:14:18
    dplayx.dll                                6.01.7600.16385   Final Retail                     213504  14.07.2009 3:15:12
    dpmodemx.dll                              6.01.7600.16385   Final Retail                         23040  14.07.2009 3:15:12
    dpnaddr.dll                               6.01.7601.17514   Final Retail                       2560  20.11.2010 23:29:06
    dpnet.dll                                 6.01.7600.16385   Final Retail                        376832  14.07.2009 3:15:12
    dpnhpast.dll                              6.01.7600.16385   Final Retail                       7168  14.07.2009 3:15:12
    dpnhupnp.dll                              6.01.7600.16385   Final Retail                       7168  14.07.2009 3:15:12
    dpnlobby.dll                              6.01.7600.16385   Final Retail                       2560  14.07.2009 3:04:52
    dpnsvr.exe                                6.01.7600.16385   Final Retail                         33280  14.07.2009 3:14:18
    dpwsockx.dll                              6.01.7600.16385   Final Retail                         44032  14.07.2009 3:15:12
    dsdmo.dll                                 6.01.7600.16385   Final Retail                     173568  14.07.2009 3:15:13
    dsound.dll                                6.01.7600.16385   Final Retail                        453632  14.07.2009 3:15:13
    dswave.dll                                6.01.7600.16385   Final Retail                      20992  14.07.2009 3:15:13
    dxapi.sys                                 6.01.7600.16385   Final Retail                      13312  14.07.2009 1:25:26
    dxdiagn.dll                               6.01.7601.17514   Final Retail                        210432  20.11.2010 23:29:19
    dxmasf.dll                                12.00.7601.17514  Final Retail                       4096  20.11.2010 23:29:41
    encapi.dll                                6.01.7600.16385   Final Retail                      20992  14.07.2009 3:15:14
    gcdef.dll                                 6.01.7600.16385   Final Retail                        120832  14.07.2009 3:15:22
    iac25_32.ax                               2.00.0005.0053    Final Retail                        197632  14.07.2009 3:14:10
    ir41_32.ax                                4.51.0016.0003    Final Retail                        839680  14.07.2009 3:14:10
    ir41_qc.dll                               4.30.0062.0002    Final Retail                     120320  14.07.2009 3:15:34
    ir41_qcx.dll                              4.30.0062.0002    Final Retail                     120320  14.07.2009 3:15:34
    ir50_32.dll                               5.2562.0015.0055  Final Retail                        746496  14.07.2009 3:15:34
    ir50_qc.dll                               5.00.0063.0048    Final Retail                     200192  14.07.2009 3:15:34
    ir50_qcx.dll                              5.00.0063.0048    Final Retail                     200192  14.07.2009 3:15:34
    ivfsrc.ax                                 5.10.0002.0051    Final Retail                        146944  14.07.2009 3:14:10
    joy.cpl                                   6.01.7600.16385   Final Retail                        138240  14.07.2009 3:14:09
    ks.sys                                    6.01.7601.17514   Final Retail                        190976  20.11.2010 23:29:21
    ksproxy.ax                                6.01.7601.17514   Final Retail                        193536  20.11.2010 23:29:24
    kstvtune.ax                               6.01.7601.17514   Final Retail                         84480  20.11.2010 23:29:38
    ksuser.dll                                6.01.7600.16385   Final Retail                          4608  14.07.2009 3:15:35
    kswdmcap.ax                               6.01.7601.17514   Final Retail                        107008  20.11.2010 23:29:13
    ksxbar.ax                                 6.01.7601.17514   Final Retail                         48640  20.11.2010 23:29:38
    mciqtz32.dll                              6.06.7601.17514   Final Retail                         36352  20.11.2010 23:29:07
    mfc40.dll                                 4.01.0000.6151    Beta Retail                         954752  20.11.2010 23:29:07
    mfc42.dll                                 6.06.8063.0000    Beta Retail                        1136640  14.07.2009 3:15:39
    Microsoft.DirectX.AudioVideoPlayback.dll  5.04.0000.2904    Final Retail                      53248  08.06.2010 12:06:29
    Microsoft.DirectX.Diagnostics.dll         5.04.0000.2904    Final Retail                      12800  08.06.2010 12:06:29
    Microsoft.DirectX.Direct3D.dll            9.05.0132.0000    Final Retail                     473600  08.06.2010 12:06:30
    Microsoft.DirectX.Direct3DX.dll           5.04.0000.3900    Final Retail                    2676224  08.06.2010 12:06:02
    Microsoft.DirectX.Direct3DX.dll           9.04.0091.0000    Final Retail                    2846720  08.06.2010 12:06:08
    Microsoft.DirectX.Direct3DX.dll           9.05.0132.0000    Final Retail                     563712  08.06.2010 12:06:11
    Microsoft.DirectX.Direct3DX.dll           9.06.0168.0000    Final Retail                     567296  08.06.2010 12:06:12
    Microsoft.DirectX.Direct3DX.dll           9.07.0239.0000    Final Retail                     576000  08.06.2010 12:06:14
    Microsoft.DirectX.Direct3DX.dll           9.08.0299.0000    Final Retail                     577024  08.06.2010 12:06:16
    Microsoft.DirectX.Direct3DX.dll           9.09.0376.0000    Final Retail                     577536  08.06.2010 12:06:18
    Microsoft.DirectX.Direct3DX.dll           9.10.0455.0000    Final Retail                     577536  08.06.2010 12:06:19
    Microsoft.DirectX.Direct3DX.dll           9.11.0519.0000    Final Retail                     578560  08.06.2010 12:06:21
    Microsoft.DirectX.Direct3DX.dll           9.12.0589.0000    Final Retail                     578560  08.06.2010 12:06:31
    Microsoft.DirectX.DirectDraw.dll          5.04.0000.2904    Final Retail                     145920  08.06.2010 12:06:32
    Microsoft.DirectX.DirectInput.dll         5.04.0000.2904    Final Retail                     159232  08.06.2010 12:06:32
    Microsoft.DirectX.DirectPlay.dll          5.04.0000.2904    Final Retail                     364544  08.06.2010 12:06:32
    Microsoft.DirectX.DirectSound.dll         5.04.0000.2904    Final Retail                     178176  08.06.2010 12:06:32
    Microsoft.DirectX.dll                     5.04.0000.2904    Final Retail                     223232  08.06.2010 12:06:28
    mpeg2data.ax                              6.06.7601.17514   Final Retail                         72704  20.11.2010 23:29:38
    mpg2splt.ax                               6.06.7601.17514   Final Retail                     199680  20.11.2010 23:29:38
    msdmo.dll                                 6.06.7601.17514   Final Retail                      30720  20.11.2010 23:29:08
    msdvbnp.ax                                6.06.7601.17514   Final Retail                         59904  20.11.2010 23:29:38
    mskssrv.sys                               6.01.7600.16385   Final Retail                          8320  14.07.2009 1:45:08
    mspclock.sys                              6.01.7600.16385   Final Retail                          5888  14.07.2009 1:45:08
    mspqm.sys                                 6.01.7600.16385   Final Retail                          5504  14.07.2009 1:45:07
    mstee.sys                                 6.01.7600.16385   Final Retail                          6144  14.07.2009 1:45:08
    msvidctl.dll                              6.05.7601.17514   Final Retail                       2291712  20.11.2010 23:29:38
    msyuv.dll                                 6.01.7601.17514   Final Retail                      22528  20.11.2010 23:29:04
    pid.dll                                   6.01.7600.16385   Final Retail                      36352  14.07.2009 3:16:12
    psisdecd.dll                              6.06.7600.16385   Final Retail                        465408  14.07.2009 3:16:12
    psisrndr.ax                               6.06.7601.17514   Final Retail                         75776  20.11.2010 23:29:38
    qasf.dll                                  12.00.7601.17514  Final Retail                     206848  20.11.2010 23:29:08
    qcap.dll                                  6.06.7601.17514   Final Retail                        190976  20.11.2010 23:29:12
    qdv.dll                                   6.06.7601.17514   Final Retail                        283136  20.11.2010 23:29:12
    qdvd.dll                                  6.06.7601.17514   Final Retail                        514560  20.11.2010 23:29:06
    qedit.dll                                 6.06.7601.17514   Final Retail                        509440  20.11.2010 23:29:40
    qedwipes.dll                              6.06.7600.16385   Final Retail                     733184  14.07.2009 3:09:35
    quartz.dll                                6.06.7601.17514   Final Retail                       1328128  20.11.2010 23:29:07
    stream.sys                                6.01.7600.16385   Final Retail                         53632  14.07.2009 1:50:57
    swenum.sys                                6.01.7600.16385   Final Retail                         12240  14.07.2009 3:19:10
    vbisurf.ax                                6.01.7601.17514   Final Retail                      33792  20.11.2010 23:29:38
    vfwwdm32.dll                              6.01.7601.17514   Final Retail                         56832  20.11.2010 23:29:12
    wsock32.dll                               6.01.7600.16385   Final Retail                         15360  14.07.2009 3:16:20


--------[ DirectX -  ]---------------------------------------------------------------------------------------------

  [   ]

     DirectDraw:
        DirectDraw                           display
        DirectDraw                       
                                       nvd3dum.dll (8.15.11.8593 - nVIDIA ForceWare 185.93)
                                      NVIDIA GeForce 8600 GT (Microsoft Corporation - WDDM v1.1)

     Direct3D:
                                16, 32
        Z-                          16, 24, 32
      Multisample Anti-Aliasing Modes                   MSAA 2x, MSAA 4x, MSAA 8x, CSAA 8x, CSAA 8xQ, CSAA 16x, CSAA 16xQ
                               1 x 1
                              8192 x 8192
       Vertex-                             3.0
                                3.0

     Direct3D:
      Additive Texture Blending                         
      AGP Texturing                                     
      Anisotropic Filtering                             
      Automatic Mipmap Generation                       
      Bilinear Filtering                                
      Cubic Environment Mapping                         
      Cubic Filtering                                    
      Decal-Alpha Texture Blending                      
      Decal Texture Blending                            
      DirectX Texture Compression                        
      DirectX Volumetric Texture Compression             
      Dithering                                         
      Dot3 Texture Blending                             
      Dynamic Textures                                  
      Edge Anti-Aliasing                                
      Environmental Bump Mapping                        
      Environmental Bump Mapping + Luminance            
      Factor Alpha Blending                             
      Geometric Hidden-Surface Removal                   
      Guard Band                                        
      Hardware Scene Rasterization                      
      Hardware Transform & Lighting                     
      Legacy Depth Bias                                 
      Mipmap LOD Bias Adjustments                       
      Mipmapped Cube Textures                           
      Mipmapped Volume Textures                         
      Modulate-Alpha Texture Blending                   
      Modulate Texture Blending                         
      Non-Square Textures                               
      N-Patches                                          
      Perspective Texture Correction                    
      Point Sampling                                    
      Projective Textures                               
      Quintic Bezier Curves & B-Splines                  
      Range-Based Fog                                   
      Rectangular & Triangular Patches                   
      Rendering In Windowed Mode                        
      Scissor Test                                      
      Slope-Scale Based Depth Bias                      
      Specular Flat Shading                             
      Specular Gouraud Shading                          
      Specular Phong Shading                             
      Spherical Mapping                                 
      Stencil Buffers                                   
      Sub-Pixel Accuracy                                
      Subtractive Texture Blending                      
      Table Fog                                         
      Texture Alpha Blending                            
      Texture Clamping                                  
      Texture Mirroring                                 
      Texture Transparency                              
      Texture Wrapping                                  
      Triangle Culling                                   
      Trilinear Filtering                               
      Two-Sided Stencil Test                            
      Vertex Alpha Blending                             
      Vertex Fog                                        
      Vertex Tweening                                    
      Volume Textures                                   
      W-Based Fog                                       
      W-Buffering                                        
      Z-Based Fog                                       
      Z-Bias                                            
      Z-Test                                            

      FourCC:
      3x11                                              
      3x16                                              
      AI44                                              
      AIP8                                              
      ATOC                                              
      AV12                                              
      AYUV                                              
      NV12                                              
      NV24                                              
      NVDB                                              
      NVDP                                              
      NVMD                                              
      PLFF                                              
      SSAA                                              
      UYVY                                              
      YUY2                                              
      YV12                                              

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://driveragent.com?ref=59


--------[ DirectX -  ]----------------------------------------------------------------------------------------------

  [    ]

     DirectSound:
                                        
                                          
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    

  [   (S/PDIF) (2-    High Definition Audio) ]

     DirectSound:
                                        (S/PDIF) (2-    High Definition Audio)
                                          {0.0.0.00000000}.{51b051d8-68d4-4e67-842f-2715cdf29ee5}
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    


--------[ DirectX -  ]--------------------------------------------------------------------------------------------

  [ Microsoft MIDI Mapper [] ]

     DirectMusic:
                                      Microsoft MIDI Mapper []
                                          
                                          
                                           Windows Multimedia
       MIDI                                       16

     DirectMusic:
         GM                  
         Roland GS                 
      DirectSound                                        
        DLS L1                           
        DLS L2                           
        MIDI                                 
         DLS                    
                                         
                                               
                                           
                                       

  [ Microsoft GS Wavetable Synth [] ]

     DirectMusic:
                                      Microsoft GS Wavetable Synth []
                                          
                                          
                                           Windows Multimedia
       MIDI                                       16

     DirectMusic:
         GM                  
         Roland GS                 
      DirectSound                                        
        DLS L1                           
        DLS L2                           
        MIDI                                 
         DLS                    
                                         
                                               
                                           
                                       

  [ Microsoft Synthesizer ]

     DirectMusic:
                                      Microsoft Synthesizer
                                          
                                          
                                           User-Mode Synthesizer
                                             2
       MIDI                                       16000
                                                  1000
                                          

     DirectMusic:
         GM                  
         Roland GS                 
      DirectSound                                       
        DLS L1                          
        DLS L2                          
        MIDI                                 
         DLS                    
                                          
                                               
                                           
                                      


--------[ DirectX -  ]----------------------------------------------------------------------------------------------

  [  ]

     DirectInput:
                                      
                                           
                                        
                                                     3
      /                                    3

     DirectInput:
                                      
      Alias Device                                      
      Polled Device                                     
      Polled Data Format                                
      Attack Force Feedback                              
      Deadband Force Feedback                            
      Fade Force Feedback                                
      Force Feedback                                     
      Saturation Force Feedback                          
      +/- Force Feedback Coefficients                    
      +/- Force Feedback Saturation                      

  [  ]

     DirectInput:
                                      
                                           
                                        
      /                                    128

     DirectInput:
                                      
      Alias Device                                      
      Polled Device                                     
      Polled Data Format                                
      Attack Force Feedback                              
      Deadband Force Feedback                            
      Fade Force Feedback                                
      Force Feedback                                     
      Saturation Force Feedback                          
      +/- Force Feedback Coefficients                    
      +/- Force Feedback Saturation                      


--------[  Windows ]------------------------------------------------------------------------------------------

  [  ]

    DVD  CD-ROM :
      PIONEER DVD-RW  DVR-219L ATA Device               6.1.7601.17514

    IDE ATA/ATAPI :
      ATA Channel 0                                     6.1.7601.17514
      ATA Channel 0                                     6.1.7601.17514
      ATA Channel 1                                     6.1.7601.17514
      ATA Channel 1                                     6.1.7601.17514
         PCI IDE      6.1.7601.17514
         PCI IDE      6.1.7601.17514

    Unknown:
                                              

    :
      NVIDIA GeForce 8600 GT (Microsoft Corporation - WDDM v1.1)8.15.11.8593

     :
      ST3250410AS ATA Device                            6.1.7600.16385

      :
      Ancillary Function Driver for Winsock             
      Beep                                              
      CNG                                               
      Hardware Policy Driver                            
      HTTP                                              
      Kernel Mode Driver Frameworks service             
      KSecDD                                            
      KSecPkg                                           
      Lavalys EVEREST Kernel Driver                     
      LDDM Graphics Subsystem                           
      Link-Layer Topology Discovery Mapper I/O Driver   
      Link-Layer Topology Discovery Responder           
      msisadrv                                          
      NDProxy                                           
      NETBT                                             
      NSI proxy service driver.                         
      Null                                              
      Parvdm                                            
      PEAUTH                                            
      Performance Counters for Windows Driver           
      RDP Encoder Mirror Driver                         
      RDPCDD                                            
      Reflector Display Driver used to gain access to graphics data
      Security Driver                                   
      Security Processor Loader Driver                  
      System Attribute Cache                            
      TCP/IP Registry Compatibility                     
      User Mode Driver Frameworks Platform Driver       
      VgaSave                                           
      WFP Lightweight Filter                            
            
                              
                               
                                 
         Windows           
        NetIO Legacy TDI                
        TCP/IP                          
         IPv6 ARP               
          Bitlocker        
        (CLFS)                               
        QoS                           
        NDIS                            
                               

    ,    :
         High Definition Audio     6.1.7601.17514

    :
        PS/2                       6.1.7601.17514

    :
      ACPI    x86                        6.1.7600.16385

     USB:
       USB-                         6.1.7601.17514
       USB-                         6.1.7601.17514
       OpenHCD USB -           6.1.7601.17514
        PCI - USB - 6.1.7601.17514

      :
                       6.1.7600.16385

    :
        PnP                         6.1.7600.16385

        :
      Microsoft PS/2                                6.1.7600.16385

     (COM  LPT):
        (LPT1)                              6.1.7600.16385
        (COM1)                      6.1.7600.16385

    :
      AMD Athlon(tm) 64 X2 Dual Core Processor 4200+    6.1.7600.16385
      AMD Athlon(tm) 64 X2 Dual Core Processor 4200+    6.1.7600.16385

     :
      Teredo Tunneling Pseudo-Interface                 6.1.7600.16385
      WAN Miniport (IKEv2)                              6.1.7601.17514
       Microsoft ISATAP #2                       6.1.7600.16385
       Microsoft ISATAP #3                       6.1.7600.16385
       Microsoft ISATAP                          6.1.7600.16385
       WAN (IP)                                 6.1.7601.17514
       WAN (IPv6)                               6.1.7601.17514
       WAN (L2TP)                               6.1.7601.17514
       WAN (PPPoE)                              6.1.7601.17514
       WAN (PPTP)                               6.1.7601.17514
      - WAN (SSTP)                              6.1.7601.17514
       WAN ( )                    6.1.7601.17514
        NVIDIA nForce                  1.0.1.211

     :
      AMD Address Map                       6.1.7601.17514
      AMD DRAM  HyperTransport(tm) Trace Mode 6.1.7601.17514
      AMD HyperTransport(tm)                6.1.7601.17514
      AMD                             6.1.7601.17514
      CMOS                                         6.1.7601.17514
      Microsoft ACPI-                 6.1.7601.17514
      Microsoft System Management BIOS           6.1.7601.17514
      Remote Desktop Device Redirector Bus              6.1.7600.16385
      UMBus                    6.1.7601.17514
      UMBus                                6.1.7601.17514
                               6.1.7601.17514
                                       6.1.7601.17514
                               6.1.7601.17514
                                          6.1.7601.17514
                      6.1.7601.17514
                            6.1.7601.17514
          ()6.1.7601.17514
                               6.1.7600.16385
        ACPI                               6.1.7601.17514
       High Definition Audio (Microsoft)      6.1.7601.17514
                         6.1.7601.17514
                        6.1.7601.17514
                            6.1.7601.17514
         Plug and Play 6.1.7601.17514
       PCI Express standard Root                    6.1.7601.17514
       PCI Express standard Root                    6.1.7601.17514
       PCI Express standard Root                    6.1.7601.17514
       PCI Express standard Root                    6.1.7601.17514
                     6.1.7601.17514
                                   6.1.7601.17514
                                   6.1.7601.17514
                                   6.1.7601.17514
                                   6.1.7601.17514
                                          6.1.7601.17514
                                         6.1.7601.17514
       PCI- RAM                    6.1.7601.17514
       PCI- RAM                    6.1.7601.17514
        PCI - ISA                        6.1.7601.17514
        PCI - PCI                        6.1.7601.17514
         ACPI          6.1.7601.17514
       NVIDIA nForce PCI System Management          6.1.7601.17514
       PCI                                          6.1.7601.17514

        :
                           6.1.7600.16385

      :
                                        6.1.7601.17514
                                        6.1.7601.17514

  [ DVD  CD-ROM  / PIONEER DVD-RW  DVR-219L ATA Device ]

     :
                                        PIONEER DVD-RW  DVR-219L ATA Device
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          cdrom.inf
       ID                                     IDE\CdRomPIONEER_DVD-RW__DVR-219L________________1.01____
                                     Channel 1, Target 0, Lun 0

  [ IDE ATA/ATAPI  / ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          mshdc.inf
       ID                                     10de-0448
                                     Channel 0

     :
      IRQ                                               14
                                                    01F0-01F7
                                                    03F6-03F6

  [ IDE ATA/ATAPI  / ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          mshdc.inf
       ID                                     10de-045d
                                     Channel 0

  [ IDE ATA/ATAPI  / ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          mshdc.inf
       ID                                     10de-0448
                                     Channel 1

     :
      IRQ                                               15
                                                    0170-0177
                                                    0376-0376

  [ IDE ATA/ATAPI  / ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          mshdc.inf
       ID                                     10de-045d
                                     Channel 1

  [ IDE ATA/ATAPI  /    PCI IDE ]

     :
                                           PCI IDE
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          mshdc.inf
       ID                                     PCI\VEN_10DE&DEV_045D&SUBSYS_82491043&REV_A1
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,10,0)
      PCI-                                    nVIDIA MCP65 - SATA Controller

     :
      IRQ                                               21
                                                  DBFF2000-DBFF3FFF
                                                    0E00-0E03
                                                    0E80-0E87
                                                    0F00-0F03
                                                    0F80-0F87
                                                    C480-C48F

  [ IDE ATA/ATAPI  /    PCI IDE ]

     :
                                           PCI IDE
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          mshdc.inf
       ID                                     PCI\VEN_10DE&DEV_0448&SUBSYS_82491043&REV_A1
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,9,0)
      PCI-                                    nVIDIA MCP65 - Parallel ATA Controller

     :
                                                    FFA0-FFAF

  [ Unknown / Unknown ]

     :
                                        Unknown
       ID                                     ACPI\ATK0110
      PnP-                                    Asus ATK-110 ACPI Utility

  [  / NVIDIA GeForce 8600 GT (Microsoft Corporation - WDDM v1.1) ]

     :
                                        NVIDIA GeForce 8600 GT (Microsoft Corporation - WDDM v1.1)
                                            14.05.2009
                                          8.15.11.8593
                                       NVIDIA
      INF-                                          nv_lh.inf
       ID                                     PCI\VEN_10DE&DEV_0402&SUBSYS_00000000&REV_A1
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(4,0,0)
      PCI-                                    nVIDIA GeForce 8600 GT Video Adapter

     :
      IRQ                                               18
                                                  000A0000-000BFFFF
                                                  C0000000-CFFFFFFF
                                                  DC000000-DDFFFFFF
                                                  DF000000-DFFFFFFF
                                                    03B0-03BB
                                                    03C0-03DF
                                                    EC00-EC7F

  [   / ST3250410AS ATA Device ]

     :
                                        ST3250410AS ATA Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf
       ID                                     IDE\DiskST3250410AS_____________________________3.AAA___
                                     Channel 0, Target 0, Lun 0

  [    / Ancillary Function Driver for Winsock ]

     :
                                        Ancillary Function Driver for Winsock

  [    / Beep ]

     :
                                        Beep

  [    / CNG ]

     :
                                        CNG

  [    / Hardware Policy Driver ]

     :
                                        Hardware Policy Driver

  [    / HTTP ]

     :
                                        HTTP

  [    / Kernel Mode Driver Frameworks service ]

     :
                                        Kernel Mode Driver Frameworks service

  [    / KSecDD ]

     :
                                        KSecDD

  [    / KSecPkg ]

     :
                                        KSecPkg

  [    / Lavalys EVEREST Kernel Driver ]

     :
                                        Lavalys EVEREST Kernel Driver

  [    / LDDM Graphics Subsystem ]

     :
                                        LDDM Graphics Subsystem

  [    / Link-Layer Topology Discovery Mapper I/O Driver ]

     :
                                        Link-Layer Topology Discovery Mapper I/O Driver

  [    / Link-Layer Topology Discovery Responder ]

     :
                                        Link-Layer Topology Discovery Responder

  [    / msisadrv ]

     :
                                        msisadrv

  [    / NDProxy ]

     :
                                        NDProxy

  [    / NETBT ]

     :
                                        NETBT

  [    / NSI proxy service driver. ]

     :
                                        NSI proxy service driver.

  [    / Null ]

     :
                                        Null

  [    / Parvdm ]

     :
                                        Parvdm

  [    / PEAUTH ]

     :
                                        PEAUTH

  [    / Performance Counters for Windows Driver ]

     :
                                        Performance Counters for Windows Driver

  [    / RDP Encoder Mirror Driver ]

     :
                                        RDP Encoder Mirror Driver

  [    / RDPCDD ]

     :
                                        RDPCDD

  [    / Reflector Display Driver used to gain access to graphics data ]

     :
                                        Reflector Display Driver used to gain access to graphics data

  [    / Security Driver ]

     :
                                        Security Driver

  [    / Security Processor Loader Driver ]

     :
                                        Security Processor Loader Driver

  [    / System Attribute Cache ]

     :
                                        System Attribute Cache

  [    / TCP/IP Registry Compatibility ]

     :
                                        TCP/IP Registry Compatibility

  [    / User Mode Driver Frameworks Platform Driver ]

     :
                                        User Mode Driver Frameworks Platform Driver

  [    / VgaSave ]

     :
                                        VgaSave

  [    / WFP Lightweight Filter ]

     :
                                        WFP Lightweight Filter

  [    /        ]

     :
                                              

  [    /    ]

     :
                                          

  [    /    ]

     :
                                          

  [    /    ]

     :
                                          

  [    /    Windows ]

     :
                                           Windows

  [    /   NetIO Legacy TDI ]

     :
                                          NetIO Legacy TDI

  [    /   TCP/IP ]

     :
                                          TCP/IP

  [    /    IPv6 ARP ]

     :
                                           IPv6 ARP

  [    /     Bitlocker ]

     :
                                            Bitlocker

  [    /   (CLFS) ]

     :
                                          (CLFS)

  [    /   QoS ]

     :
                                          QoS

  [    /   NDIS ]

     :
                                          NDIS

  [    /    ]

     :
                                          

  [ ,     /    High Definition Audio ]

     :
                                           High Definition Audio
                                            19.11.2010
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          hdaudio.inf
       ID                                     HDAUDIO\FUNC_01&VEN_10EC&DEV_0883&SUBSYS_10438286&REV_1000
                                       High Definition Audio

  [  /   PS/2 ]

     :
                                          PS/2
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          keyboard.inf
       ID                                     ACPI\PNP0303
      PnP-                                    101/102-Key or MS Natural Keyboard

     :
      IRQ                                               01
                                                    0060-0060
                                                    0064-0064

  [  / ACPI    x86 ]

     :
                                        ACPI    x86
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          hal.inf
       ID                                     acpiapic

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB&VID10DE&PID0454&REV00A1

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB20&VID10DE&PID0455&REV00A1

  [  USB /  OpenHCD USB - ]

     :
                                         OpenHCD USB -
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_10DE&DEV_0454&SUBSYS_82491043&REV_A1
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,2,0)
      PCI-                                    nVIDIA MCP65 - OHCI USB 1.1 Controller

     :
      IRQ                                               22
                                                  DBFFF000-DBFFFFFF

  [  USB /   PCI - USB - ]

     :
                                          PCI - USB -
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_10DE&DEV_0455&SUBSYS_82491043&REV_A1
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,2,1)
      PCI-                                    nVIDIA MCP65 - EHCI USB 2.0 Controller

     :
      IRQ                                               21
                                                  DBFFEC00-DBFFECFF

  [    /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          fdc.inf
       ID                                     ACPI\PNP0700
      PnP-                                    Floppy Disk Controller

     :
      DMA                                               02
      IRQ                                               06
                                                    03F0-03F5
                                                    03F7-03F7

  [  /   PnP ]

     :
                                          PnP
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          monitor.inf
       ID                                     MONITOR\GSM4B31
                                                 LG L1918S

  [      / Microsoft PS/2  ]

     :
                                        Microsoft PS/2 
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          msmouse.inf
       ID                                     ACPI\PNP0F03
      PnP-                                    Microsoft PS/2 Port Mouse

     :
      IRQ                                               12

  [  (COM  LPT) /   (LPT1) ]

     :
                                          (LPT1)
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          msports.inf
       ID                                     ACPI\PNP0400
      PnP-                                    Parallel Port

     :
                                                    0378-037F

  [  (COM  LPT) /   (COM1) ]

     :
                                          (COM1)
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          msports.inf
       ID                                     ACPI\PNP0501
      PnP-                                    16550A-compatible UART Serial Port

     :
      IRQ                                               04
                                                    03F8-03FF

  [  / AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ ]

     :
                                        AMD Athlon(tm) 64 X2 Dual Core Processor 4200+
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          cpu.inf
       ID                                     ACPI\AuthenticAMD_-_x86_Family_15_Model_75

  [  / AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ ]

     :
                                        AMD Athlon(tm) 64 X2 Dual Core Processor 4200+
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          cpu.inf
       ID                                     ACPI\AuthenticAMD_-_x86_Family_15_Model_75

  [   / Teredo Tunneling Pseudo-Interface ]

     :
                                        Teredo Tunneling Pseudo-Interface
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          nettun.inf
       ID                                     *TEREDO

  [   / WAN Miniport (IKEv2) ]

     :
                                        WAN Miniport (IKEv2)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netavpna.inf
       ID                                     ms_agilevpnminiport

  [   /  Microsoft ISATAP #2 ]

     :
                                         Microsoft ISATAP #2
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          nettun.inf
       ID                                     *ISATAP

  [   /  Microsoft ISATAP #3 ]

     :
                                         Microsoft ISATAP #3
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          nettun.inf
       ID                                     *ISATAP

  [   /  Microsoft ISATAP ]

     :
                                         Microsoft ISATAP
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          nettun.inf
       ID                                     *ISATAP

  [   /  WAN (IP) ]

     :
                                        WAN Miniport (IP)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_ndiswanip

  [   /  WAN (IPv6) ]

     :
                                        WAN Miniport (IPv6)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_ndiswanipv6

  [   /  WAN (L2TP) ]

     :
                                        WAN Miniport (L2TP)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_l2tpminiport

  [   /  WAN (PPPoE) ]

     :
                                        WAN Miniport (PPPOE)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_pppoeminiport

  [   /  WAN (PPTP) ]

     :
                                        WAN Miniport (PPTP)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_pptpminiport

  [   / - WAN (SSTP) ]

     :
                                        WAN Miniport (SSTP)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netsstpa.inf
       ID                                     ms_sstpminiport

  [   /  WAN ( ) ]

     :
                                        WAN Miniport (Network Monitor)
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_ndiswanbh

  [   /   NVIDIA nForce ]

     :
                                          NVIDIA nForce
                                            17.10.2008
                                          1.0.1.211
                                       Microsoft
      INF-                                          netnvm32.inf
       ID                                     PCI\VEN_10DE&DEV_0450&SUBSYS_82491043&REV_A1
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,6,0)
      PCI-                                    nVIDIA MCP65 - LAN Controller

     :
      IRQ                                               20
                                                  DBFFD000-DBFFDFFF

  [   / AMD Address Map  ]

     :
                                        AMD Address Map 
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1101&SUBSYS_00000000&REV_00
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,24,1)
      PCI-                                    AMD Hammer - Address Map

  [   / AMD DRAM  HyperTransport(tm) Trace Mode  ]

     :
                                        AMD DRAM  HyperTransport(tm) Trace Mode 
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1102&SUBSYS_00000000&REV_00
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,24,2)
      PCI-                                    AMD Hammer - DRAM Controller

  [   / AMD HyperTransport(tm)  ]

     :
                                        AMD HyperTransport(tm) 
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1100&SUBSYS_00000000&REV_00
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,24,0)
      PCI-                                    AMD Hammer - HyperTransport Technology Configuration

  [   / AMD   ]

     :
                                        AMD  
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1103&SUBSYS_00000000&REV_00
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,24,3)
      PCI-                                    AMD Hammer - Miscellaneous Control

  [   / CMOS   ]

     :
                                        CMOS  
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0B00
      PnP-                                    Real-Time Clock

     :
      IRQ                                               08
                                                    0070-0071

  [   / Microsoft ACPI-  ]

     :
                                        Microsoft ACPI- 
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          acpi.inf
       ID                                     ACPI_HAL\PNP0C08
      PnP-                                    ACPI Driver/BIOS

     :
      IRQ                                               100
      IRQ                                               101
      IRQ                                               102
      IRQ                                               103
      IRQ                                               104
      IRQ                                               105
      IRQ                                               106
      IRQ                                               107
      IRQ                                               108
      IRQ                                               109
      IRQ                                               110
      IRQ                                               111
      IRQ                                               112
      IRQ                                               113
      IRQ                                               114
      IRQ                                               115
      IRQ                                               116
      IRQ                                               117
      IRQ                                               118
      IRQ                                               119
      IRQ                                               120
      IRQ                                               121
      IRQ                                               122
      IRQ                                               123
      IRQ                                               124
      IRQ                                               125
      IRQ                                               126
      IRQ                                               127
      IRQ                                               128
      IRQ                                               129
      IRQ                                               130
      IRQ                                               131
      IRQ                                               132
      IRQ                                               133
      IRQ                                               134
      IRQ                                               135
      IRQ                                               136
      IRQ                                               137
      IRQ                                               138
      IRQ                                               139
      IRQ                                               140
      IRQ                                               141
      IRQ                                               142
      IRQ                                               143
      IRQ                                               144
      IRQ                                               145
      IRQ                                               146
      IRQ                                               147
      IRQ                                               148
      IRQ                                               149
      IRQ                                               150
      IRQ                                               151
      IRQ                                               152
      IRQ                                               153
      IRQ                                               154
      IRQ                                               155
      IRQ                                               156
      IRQ                                               157
      IRQ                                               158
      IRQ                                               159
      IRQ                                               160
      IRQ                                               161
      IRQ                                               162
      IRQ                                               163
      IRQ                                               164
      IRQ                                               165
      IRQ                                               166
      IRQ                                               167
      IRQ                                               168
      IRQ                                               169
      IRQ                                               170
      IRQ                                               171
      IRQ                                               172
      IRQ                                               173
      IRQ                                               174
      IRQ                                               175
      IRQ                                               176
      IRQ                                               177
      IRQ                                               178
      IRQ                                               179
      IRQ                                               180
      IRQ                                               181
      IRQ                                               182
      IRQ                                               183
      IRQ                                               184
      IRQ                                               185
      IRQ                                               186
      IRQ                                               187
      IRQ                                               188
      IRQ                                               189
      IRQ                                               190
      IRQ                                               81
      IRQ                                               82
      IRQ                                               83
      IRQ                                               84
      IRQ                                               85
      IRQ                                               86
      IRQ                                               87
      IRQ                                               88
      IRQ                                               89
      IRQ                                               90
      IRQ                                               91
      IRQ                                               92
      IRQ                                               93
      IRQ                                               94
      IRQ                                               95
      IRQ                                               96
      IRQ                                               97
      IRQ                                               98
      IRQ                                               99

  [   / Microsoft System Management BIOS  ]

     :
                                        Microsoft System Management BIOS 
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ROOT\mssmbios

  [   / Remote Desktop Device Redirector Bus ]

     :
                                        Remote Desktop Device Redirector Bus
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          rdpbus.inf
       ID                                     ROOT\RDPBUS

  [   / UMBus    ]

     :
                                        UMBus   
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          umbus.inf
       ID                                     root\umbus

  [   / UMBus  ]

     :
                                        UMBus 
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          umbus.inf
       ID                                     UMB\UMBUS

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C04
      PnP-                                    Numeric Data Processor

     :
      IRQ                                               13
                                                    00F0-00FF

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0800
      PnP-                                    PC Speaker

     :
                                                    0061-0061

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0103
      PnP-                                    High Precision Event Timer

     :
                                                  FED00000-FED00FFF

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ROOT\VOLMGR

  [   /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ROOT\RDP_KBD

  [   /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ROOT\RDP_MOU

  [   /     () ]

     :
                                            ()
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ROOT\vdrvroot

  [   /      ]

     :
                                            
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          blbdrive.inf
       ID                                     ROOT\BLBDRIVE

  [   /   ACPI ]

     :
                                          ACPI
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C0C
      PnP-                                    Power Button

  [   /  High Definition Audio (Microsoft) ]

     :
                                         High Definition Audio (Microsoft)
                                            19.11.2010
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          hdaudbus.inf
       ID                                     PCI\VEN_10DE&DEV_044A&SUBSYS_82861043&REV_A1
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,7,0)
      PCI-                                    nVIDIA MCP65 - High Definition Audio Controller

     :
      IRQ                                               23
                                                  DBFF4000-DBFF7FFF

  [   /      ]

     :
                                            
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0200
      PnP-                                    DMA Controller

     :
      DMA                                               04
                                                    0000-000F
                                                    0081-0083
                                                    0087-0087
                                                    0089-008B
                                                    008F-008F
                                                    00C0-00DF

  [   /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     LPTENUM\MicrosoftRawPort958A
                                     LPT1

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          compositebus.inf
       ID                                     ROOT\CompositeBus

  [   /    Plug and Play ]

     :
                                           Plug and Play
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     root\swenum

  [   /  PCI Express standard Root ]

     :
                                         PCI Express standard Root
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_10DE&DEV_0459&SUBSYS_000010DE&REV_A1
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,14,0)
      PCI-                                    nVIDIA MCP65 - PCI Express Root Port (x8)

     :
      IRQ                                               196607

  [   /  PCI Express standard Root ]

     :
                                         PCI Express standard Root
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_10DE&DEV_045A&SUBSYS_000010DE&REV_A1
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,12,0)
      PCI-                                    nVIDIA MCP65 - PCI Express Root Port (x2)

     :
      IRQ                                               196607

  [   /  PCI Express standard Root ]

     :
                                         PCI Express standard Root
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_10DE&DEV_045B&SUBSYS_000010DE&REV_A1
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,11,0)
      PCI-                                    nVIDIA MCP65 - PCI Express Root Port (x2)

     :
      IRQ                                               196607

  [   /  PCI Express standard Root ]

     :
                                         PCI Express standard Root
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_10DE&DEV_0458&SUBSYS_000010DE&REV_A1
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,13,0)
      PCI-                                    nVIDIA MCP65 - PCI Express Root Port (x16)

     :
      IRQ                                               196607
                                                  000A0000-000BFFFF
                                                  C0000000-CFFFFFFF
                                                  DC000000-DFFFFFFF
                                                    03B0-03BB
                                                    03C0-03DF
                                                    E000-EFFF

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0000
      PnP-                                    Programmable Interrupt Controller

     :
                                                    0020-0021
                                                    00A0-00A1

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C02
      PnP-                                    Motherboard Resources

     :
                                                  E0000000-EFFFFFFF

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C02
      PnP-                                    Motherboard Resources

     :
                                                  FEC00000-FEC00FFF
                                                  FEE00000-FEE00FFF

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C02
      PnP-                                    Motherboard Resources

     :
                                                  000D0000-000D3FFF
                                                  000D4000-000D7FFF
                                                  000DE000-000DFFFF
                                                  FEE01000-FEEFFFFF
                                                    0010-001F
                                                    0022-003F
                                                    0044-005F
                                                    0062-0063
                                                    0065-006F
                                                    0072-007F
                                                    0080-0080
                                                    0084-0086
                                                    0088-0088
                                                    008C-008E
                                                    0090-009F
                                                    00A2-00BF
                                                    00E0-00EF
                                                    04D0-04D1
                                                    0500-057F
                                                    0580-05FF
                                                    0800-080F
                                                    0800-087F
                                                    0880-08FF
                                                    0900-097F
                                                    0980-09FF
                                                    0A30-0A37
                                                    0D00-0D7F
                                                    0D80-0DFF
                                                    1100-117F
                                                    1180-11FF

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C02
      PnP-                                    Motherboard Resources

     :
                                                    0230-023F
                                                    0290-029F
                                                    0A00-0A0F
                                                    0A10-0A1F

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C01
      PnP-                                    System Board Extension

     :
                                                  00000000-0009FFFF
                                                  000C0000-000CFFFF
                                                  000E0000-000FFFFF
                                                  00100000-7FFFFFFF
                                                  FEC00000-FFFFFFFF

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0100
      PnP-                                    System Timer

     :
      IRQ                                               00
                                                    0040-0043

  [   /  PCI- RAM ]

     :
                                         PCI- RAM
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_10DE&DEV_0444&SUBSYS_82491043&REV_A1
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,0,0)
      PCI-                                    nVIDIA MCP65 - Host Bridge (HyperTransport)

  [   /  PCI- RAM ]

     :
                                         PCI- RAM
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_10DE&DEV_0445&SUBSYS_82491043&REV_A1
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,1,2)
      PCI-                                    nVIDIA MCP65 - Shape/Trim

  [   /   PCI - ISA ]

     :
                                          PCI - ISA
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_10DE&DEV_0441&SUBSYS_82491043&REV_A2
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,1,0)
      PCI-                                    nVIDIA nForce 520 (MCP65S) - LPC Bridge

  [   /   PCI - PCI ]

     :
                                          PCI - PCI
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_10DE&DEV_0449&SUBSYS_CB8410DE&REV_A1
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,8,0)
      PCI-                                    nVIDIA MCP65 - PCI-PCI Bridge

  [   /    ACPI ]

     :
                                           ACPI
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\FixedButton

  [   /  NVIDIA nForce PCI System Management ]

     :
                                         NVIDIA nForce PCI System Management
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_10DE&DEV_0446&SUBSYS_82491043&REV_A1
                                     @system32\drivers\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,1,1)
      PCI-                                    nVIDIA MCP65 - SMBus Controller

     :
      IRQ                                               10
                                                    0600-063F
                                                    0700-073F
                                                    DC00-DC3F

  [   /  PCI ]

     :
                                         PCI
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0A03
      PnP-                                    PCI Bus

     :
                                                  000A0000-000BFFFF
                                                  000D0000-000DFFFF
                                                  80000000-FEBFFFFF
                                                    0000-0CF7
                                                    0D00-FFFF

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
       ID                                     STORAGE\VolumeSnapshot

  [    /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          volume.inf
       ID                                     STORAGE\Volume

  [    /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7601.17514
                                       Microsoft
      INF-                                          volume.inf
       ID                                     STORAGE\Volume


--------[   ]---------------------------------------------------------------------------------------

     PCI:
       0,  24,  1                  AMD Hammer - Address Map
       0,  24,  2                  AMD Hammer - DRAM Controller
       0,  24,  0                  AMD Hammer - HyperTransport Technology Configuration
       0,  24,  3                  AMD Hammer - Miscellaneous Control
       4,  0,  0                   nVIDIA GeForce 8600 GT Video Adapter
       0,  2,  1                   nVIDIA MCP65 - EHCI USB 2.0 Controller
       0,  7,  0                   nVIDIA MCP65 - High Definition Audio Controller
       0,  0,  0                   nVIDIA MCP65 - Host Bridge (HyperTransport)
       0,  6,  0                   nVIDIA MCP65 - LAN Controller
       0,  2,  0                   nVIDIA MCP65 - OHCI USB 1.1 Controller
       0,  9,  0                   nVIDIA MCP65 - Parallel ATA Controller
       0,  13,  0                  nVIDIA MCP65 - PCI Express Root Port (x16)
       0,  11,  0                  nVIDIA MCP65 - PCI Express Root Port (x2)
       0,  12,  0                  nVIDIA MCP65 - PCI Express Root Port (x2)
       0,  14,  0                  nVIDIA MCP65 - PCI Express Root Port (x8)
       0,  8,  0                   nVIDIA MCP65 - PCI-PCI Bridge
       0,  10,  0                  nVIDIA MCP65 - SATA Controller
       0,  1,  2                   nVIDIA MCP65 - Shape/Trim
       0,  1,  1                   nVIDIA MCP65 - SMBus Controller
       0,  1,  0                   nVIDIA nForce 520 (MCP65S) - LPC Bridge

     PnP:
      PNP0303                                           101/102-Key or MS Natural Keyboard
      PNP0501                                           16550A-compatible UART Serial Port
      PNP0C08                                           ACPI Driver/BIOS
      AUTHENTICAMD_-_X86_FAMILY_15_MODEL_75_-_AMD_ATHLON(TM)_64_X2_DUAL_CORE_PROCESSOR_4200+AMD Athlon(tm) 64 X2 Dual Core Processor 4200+
      AUTHENTICAMD_-_X86_FAMILY_15_MODEL_75_-_AMD_ATHLON(TM)_64_X2_DUAL_CORE_PROCESSOR_4200+AMD Athlon(tm) 64 X2 Dual Core Processor 4200+
      ATK0110                                           Asus ATK-110 ACPI Utility
      PNP0200                                           DMA Controller
      PNP0700                                           Floppy Disk Controller
      PNP0103                                           High Precision Event Timer
      PNP0F03                                           Microsoft PS/2 Port Mouse
      PNP0C02                                           Motherboard Resources
      PNP0C02                                           Motherboard Resources
      PNP0C02                                           Motherboard Resources
      PNP0C02                                           Motherboard Resources
      PNP0C04                                           Numeric Data Processor
      PNP0400                                           Parallel Port
      PNP0800                                           PC Speaker
      PNP0A03                                           PCI Bus
      PNP0C0C                                           Power Button
      PNP0000                                           Programmable Interrupt Controller
      PNP0B00                                           Real-Time Clock
      PNP0C01                                           System Board Extension
      PNP0100                                           System Timer
      TEREDO                                            Teredo Tunneling Pseudo-Interface
      ISATAP                                             Microsoft ISATAP #2
      ISATAP                                             Microsoft ISATAP #3
      ISATAP                                             Microsoft ISATAP
      FIXEDBUTTON                                          ACPI

     LPT PnP:
      MICROSOFTRAWPORT                                     

    :
      COM1                                                (COM1)
      LPT1                                                (LPT1)


--------[  PCI ]----------------------------------------------------------------------------------------------

  [ AMD Hammer - Address Map ]

     :
                                      AMD Hammer - Address Map
                                                 PCI
       /  /                        0 / 24 / 1
      ID                                      1022-1101
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD Hammer - DRAM Controller ]

     :
                                      AMD Hammer - DRAM Controller
                                                 PCI
       /  /                        0 / 24 / 2
      ID                                      1022-1102
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD Hammer - HyperTransport Technology Configuration ]

     :
                                      AMD Hammer - HyperTransport Technology Configuration
                                                 PCI
       /  /                        0 / 24 / 0
      ID                                      1022-1100
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

    HyperTransport LDT0:
       HyperTransport                             1.02
                                                 
                                             
      .  /                    16  / 16 
        /          16  / 16 
                                1000 
                                     1000 
       /                     0 / 0
      Isochronous Flow Control Mode                      
      CRC Error Detected                                
      CRC Test Mode                                      
      Extended CTL Required                             
      Extended Register Set                              
      HyperTransport Stop Mode                          
      Link Failure Detected                             

  [ AMD Hammer - Miscellaneous Control ]

     :
                                      AMD Hammer - Miscellaneous Control
                                                 PCI
       /  /                        0 / 24 / 3
      ID                                      1022-1103
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ nVIDIA GeForce 8600 GT Video Adapter ]

     :
                                      nVIDIA GeForce 8600 GT Video Adapter
                                                 PCI Express 1.0 x16
       /  /                        4 / 0 / 0
      ID                                      10DE-0402
                               0000-0000
                                         0300 (VGA Display Controller)
                                                  A1
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ nVIDIA MCP65 - EHCI USB 2.0 Controller ]

     :
                                      nVIDIA MCP65 - EHCI USB 2.0 Controller
                                                 PCI
       /  /                        0 / 2 / 1
      ID                                      10DE-0455
                               1043-8249
                                         0C03 (USB Controller)
                                                  A1
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ nVIDIA MCP65 - High Definition Audio Controller ]

     :
                                      nVIDIA MCP65 - High Definition Audio Controller
                                                 PCI
       /  /                        0 / 7 / 0
      ID                                      10DE-044A
                               1043-8286
                                         0403 (High Definition Audio)
                                                  A1
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ nVIDIA MCP65 - Host Bridge (HyperTransport) ]

     :
                                      nVIDIA MCP65 - Host Bridge (HyperTransport)
                                                 PCI
       /  /                        0 / 0 / 0
      ID                                      10DE-0444
                               1043-8249
                                         0500 (RAM Controller)
                                                  A1
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ nVIDIA MCP65 - LAN Controller ]

     :
                                      nVIDIA MCP65 - LAN Controller
                                                 PCI
       /  /                        0 / 6 / 0
      ID                                      10DE-0450
                               1043-8249
                                         0200 (Ethernet Controller)
                                                  A1
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ nVIDIA MCP65 - OHCI USB 1.1 Controller ]

     :
                                      nVIDIA MCP65 - OHCI USB 1.1 Controller
                                                 PCI
       /  /                        0 / 2 / 0
      ID                                      10DE-0454
                               1043-8249
                                         0C03 (USB Controller)
                                                  A1
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ nVIDIA MCP65 - Parallel ATA Controller ]

     :
                                      nVIDIA MCP65 - Parallel ATA Controller
                                                 PCI
       /  /                        0 / 9 / 0
      ID                                      10DE-0448
                               1043-8249
                                         0101 (IDE Controller)
                                                  A1
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ nVIDIA MCP65 - PCI Express Root Port (x16) ]

     :
                                      nVIDIA MCP65 - PCI Express Root Port (x16)
                                                 PCI
       /  /                        0 / 13 / 0
      ID                                      10DE-0458
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  A1
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ nVIDIA MCP65 - PCI Express Root Port (x2) ]

     :
                                      nVIDIA MCP65 - PCI Express Root Port (x2)
                                                 PCI
       /  /                        0 / 11 / 0
      ID                                      10DE-045B
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  A1
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ nVIDIA MCP65 - PCI Express Root Port (x2) ]

     :
                                      nVIDIA MCP65 - PCI Express Root Port (x2)
                                                 PCI
       /  /                        0 / 12 / 0
      ID                                      10DE-045A
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  A1
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ nVIDIA MCP65 - PCI Express Root Port (x8) ]

     :
                                      nVIDIA MCP65 - PCI Express Root Port (x8)
                                                 PCI
       /  /                        0 / 14 / 0
      ID                                      10DE-0459
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  A1
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ nVIDIA MCP65 - PCI-PCI Bridge ]

     :
                                      nVIDIA MCP65 - PCI-PCI Bridge
                                                 PCI
       /  /                        0 / 8 / 0
      ID                                      10DE-0449
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  A1
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ nVIDIA MCP65 - SATA Controller ]

     :
                                      nVIDIA MCP65 - SATA Controller
                                                 PCI
       /  /                        0 / 10 / 0
      ID                                      10DE-045D
                               1043-8249
                                         0101 (IDE Controller)
                                                  A1
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ nVIDIA MCP65 - Shape/Trim ]

     :
                                      nVIDIA MCP65 - Shape/Trim
                                                 PCI
       /  /                        0 / 1 / 2
      ID                                      10DE-0445
                               1043-8249
                                         0500 (RAM Controller)
                                                  A1
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ nVIDIA MCP65 - SMBus Controller ]

     :
                                      nVIDIA MCP65 - SMBus Controller
                                                 PCI
       /  /                        0 / 1 / 1
      ID                                      10DE-0446
                               1043-8249
                                         0C05 (SMBus Controller)
                                                  A1
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ nVIDIA nForce 520 (MCP65S) - LPC Bridge ]

     :
                                      nVIDIA nForce 520 (MCP65S) - LPC Bridge
                                                 PCI
       /  /                        0 / 1 / 0
      ID                                      10DE-0441
                               1043-8249
                                         0601 (PCI/ISA Bridge)
                                                  A2
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     


--------[   ]-------------------------------------------------------------------------------------------

    DMA 02                                  
    DMA 04                                   
    IRQ 00                                
    IRQ 01                                 PS/2
    IRQ 04                                 (COM1)
    IRQ 06                                  
    IRQ 08                               CMOS  
    IRQ 10                                         NVIDIA nForce PCI System Management
    IRQ 100                              Microsoft ACPI- 
    IRQ 101                              Microsoft ACPI- 
    IRQ 102                              Microsoft ACPI- 
    IRQ 103                              Microsoft ACPI- 
    IRQ 104                              Microsoft ACPI- 
    IRQ 105                              Microsoft ACPI- 
    IRQ 106                              Microsoft ACPI- 
    IRQ 107                              Microsoft ACPI- 
    IRQ 108                              Microsoft ACPI- 
    IRQ 109                              Microsoft ACPI- 
    IRQ 110                              Microsoft ACPI- 
    IRQ 111                              Microsoft ACPI- 
    IRQ 112                              Microsoft ACPI- 
    IRQ 113                              Microsoft ACPI- 
    IRQ 114                              Microsoft ACPI- 
    IRQ 115                              Microsoft ACPI- 
    IRQ 116                              Microsoft ACPI- 
    IRQ 117                              Microsoft ACPI- 
    IRQ 118                              Microsoft ACPI- 
    IRQ 119                              Microsoft ACPI- 
    IRQ 12                               Microsoft PS/2 
    IRQ 120                              Microsoft ACPI- 
    IRQ 121                              Microsoft ACPI- 
    IRQ 122                              Microsoft ACPI- 
    IRQ 123                              Microsoft ACPI- 
    IRQ 124                              Microsoft ACPI- 
    IRQ 125                              Microsoft ACPI- 
    IRQ 126                              Microsoft ACPI- 
    IRQ 127                              Microsoft ACPI- 
    IRQ 128                              Microsoft ACPI- 
    IRQ 129                              Microsoft ACPI- 
    IRQ 13                                
    IRQ 130                              Microsoft ACPI- 
    IRQ 131                              Microsoft ACPI- 
    IRQ 132                              Microsoft ACPI- 
    IRQ 133                              Microsoft ACPI- 
    IRQ 134                              Microsoft ACPI- 
    IRQ 135                              Microsoft ACPI- 
    IRQ 136                              Microsoft ACPI- 
    IRQ 137                              Microsoft ACPI- 
    IRQ 138                              Microsoft ACPI- 
    IRQ 139                              Microsoft ACPI- 
    IRQ 14                               ATA Channel 0
    IRQ 140                              Microsoft ACPI- 
    IRQ 141                              Microsoft ACPI- 
    IRQ 142                              Microsoft ACPI- 
    IRQ 143                              Microsoft ACPI- 
    IRQ 144                              Microsoft ACPI- 
    IRQ 145                              Microsoft ACPI- 
    IRQ 146                              Microsoft ACPI- 
    IRQ 147                              Microsoft ACPI- 
    IRQ 148                              Microsoft ACPI- 
    IRQ 149                              Microsoft ACPI- 
    IRQ 15                               ATA Channel 1
    IRQ 150                              Microsoft ACPI- 
    IRQ 151                              Microsoft ACPI- 
    IRQ 152                              Microsoft ACPI- 
    IRQ 153                              Microsoft ACPI- 
    IRQ 154                              Microsoft ACPI- 
    IRQ 155                              Microsoft ACPI- 
    IRQ 156                              Microsoft ACPI- 
    IRQ 157                              Microsoft ACPI- 
    IRQ 158                              Microsoft ACPI- 
    IRQ 159                              Microsoft ACPI- 
    IRQ 160                              Microsoft ACPI- 
    IRQ 161                              Microsoft ACPI- 
    IRQ 162                              Microsoft ACPI- 
    IRQ 163                              Microsoft ACPI- 
    IRQ 164                              Microsoft ACPI- 
    IRQ 165                              Microsoft ACPI- 
    IRQ 166                              Microsoft ACPI- 
    IRQ 167                              Microsoft ACPI- 
    IRQ 168                              Microsoft ACPI- 
    IRQ 169                              Microsoft ACPI- 
    IRQ 170                              Microsoft ACPI- 
    IRQ 171                              Microsoft ACPI- 
    IRQ 172                              Microsoft ACPI- 
    IRQ 173                              Microsoft ACPI- 
    IRQ 174                              Microsoft ACPI- 
    IRQ 175                              Microsoft ACPI- 
    IRQ 176                              Microsoft ACPI- 
    IRQ 177                              Microsoft ACPI- 
    IRQ 178                              Microsoft ACPI- 
    IRQ 179                              Microsoft ACPI- 
    IRQ 18                                        NVIDIA GeForce 8600 GT (Microsoft Corporation - WDDM v1.1)
    IRQ 180                              Microsoft ACPI- 
    IRQ 181                              Microsoft ACPI- 
    IRQ 182                              Microsoft ACPI- 
    IRQ 183                              Microsoft ACPI- 
    IRQ 184                              Microsoft ACPI- 
    IRQ 185                              Microsoft ACPI- 
    IRQ 186                              Microsoft ACPI- 
    IRQ 187                              Microsoft ACPI- 
    IRQ 188                              Microsoft ACPI- 
    IRQ 189                              Microsoft ACPI- 
    IRQ 190                              Microsoft ACPI- 
    IRQ 196607                            PCI Express standard Root
    IRQ 196607                            PCI Express standard Root
    IRQ 196607                            PCI Express standard Root
    IRQ 196607                            PCI Express standard Root
    IRQ 20                                          NVIDIA nForce
    IRQ 21                                          PCI - USB -
    IRQ 21                                           PCI IDE
    IRQ 22                                         OpenHCD USB -
    IRQ 23                                         High Definition Audio (Microsoft)
    IRQ 81                               Microsoft ACPI- 
    IRQ 82                               Microsoft ACPI- 
    IRQ 83                               Microsoft ACPI- 
    IRQ 84                               Microsoft ACPI- 
    IRQ 85                               Microsoft ACPI- 
    IRQ 86                               Microsoft ACPI- 
    IRQ 87                               Microsoft ACPI- 
    IRQ 88                               Microsoft ACPI- 
    IRQ 89                               Microsoft ACPI- 
    IRQ 90                               Microsoft ACPI- 
    IRQ 91                               Microsoft ACPI- 
    IRQ 92                               Microsoft ACPI- 
    IRQ 93                               Microsoft ACPI- 
    IRQ 94                               Microsoft ACPI- 
    IRQ 95                               Microsoft ACPI- 
    IRQ 96                               Microsoft ACPI- 
    IRQ 97                               Microsoft ACPI- 
    IRQ 98                               Microsoft ACPI- 
    IRQ 99                               Microsoft ACPI- 
     00000000-0009FFFF              
     000A0000-000BFFFF                       PCI
     000A0000-000BFFFF                      NVIDIA GeForce 8600 GT (Microsoft Corporation - WDDM v1.1)
     000A0000-000BFFFF                PCI Express standard Root
     000C0000-000CFFFF              
     000D0000-000D3FFF                        
     000D0000-000DFFFF                       PCI
     000D4000-000D7FFF                        
     000DE000-000DFFFF                        
     000E0000-000FFFFF              
     00100000-7FFFFFFF              
     80000000-FEBFFFFF                       PCI
     C0000000-CFFFFFFF              PCI Express standard Root
     C0000000-CFFFFFFF             NVIDIA GeForce 8600 GT (Microsoft Corporation - WDDM v1.1)
     DBFF2000-DBFF3FFF                PCI IDE
     DBFF4000-DBFF7FFF              High Definition Audio (Microsoft)
     DBFFD000-DBFFDFFF               NVIDIA nForce
     DBFFEC00-DBFFECFF               PCI - USB -
     DBFFF000-DBFFFFFF              OpenHCD USB -
     DC000000-DDFFFFFF             NVIDIA GeForce 8600 GT (Microsoft Corporation - WDDM v1.1)
     DC000000-DFFFFFFF              PCI Express standard Root
     DF000000-DFFFFFFF             NVIDIA GeForce 8600 GT (Microsoft Corporation - WDDM v1.1)
     E0000000-EFFFFFFF               
     FEC00000-FEC00FFF               
     FEC00000-FFFFFFFF              
     FED00000-FED00FFF               
     FEE00000-FEE00FFF               
     FEE01000-FEEFFFFF               
     0000-000F                           
     0000-0CF7                                 PCI
     0010-001F                         
     0020-0021                         
     0022-003F                         
     0040-0043                        
     0044-005F                         
     0060-0060                         PS/2
     0061-0061                        
     0062-0063                         
     0064-0064                         PS/2
     0065-006F                         
     0070-0071                       CMOS  
     0072-007F                         
     0080-0080                         
     0081-0083                           
     0084-0086                         
     0087-0087                           
     0088-0088                         
     0089-008B                           
     008C-008E                         
     008F-008F                           
     0090-009F                         
     00A0-00A1                         
     00A2-00BF                         
     00C0-00DF                           
     00E0-00EF                         
     00F0-00FF                        
     0170-0177                       ATA Channel 1
     01F0-01F7                       ATA Channel 0
     0230-023F                         
     0290-029F                         
     0376-0376                       ATA Channel 1
     0378-037F                         (LPT1)
     03B0-03BB                                NVIDIA GeForce 8600 GT (Microsoft Corporation - WDDM v1.1)
     03B0-03BB                          PCI Express standard Root
     03C0-03DF                                NVIDIA GeForce 8600 GT (Microsoft Corporation - WDDM v1.1)
     03C0-03DF                          PCI Express standard Root
     03F0-03F5                          
     03F6-03F6                       ATA Channel 0
     03F7-03F7                          
     03F8-03FF                         (COM1)
     04D0-04D1                         
     0500-057F                         
     0580-05FF                         
     0600-063F                        NVIDIA nForce PCI System Management
     0700-073F                        NVIDIA nForce PCI System Management
     0800-080F                         
     0800-087F                         
     0880-08FF                         
     0900-097F                         
     0980-09FF                         
     0A00-0A0F                         
     0A10-0A1F                         
     0A30-0A37                         
     0D00-0D7F                         
     0D00-FFFF                                 PCI
     0D80-0DFF                         
     0E00-0E03                          PCI IDE
     0E80-0E87                          PCI IDE
     0F00-0F03                          PCI IDE
     0F80-0F87                          PCI IDE
     1100-117F                         
     1180-11FF                         
     C480-C48F                          PCI IDE
     DC00-DC3F                        NVIDIA nForce PCI System Management
     E000-EFFF                        PCI Express standard Root
     EC00-EC7F                       NVIDIA GeForce 8600 GT (Microsoft Corporation - WDDM v1.1)
     FFA0-FFAF                          PCI IDE


--------[  ]--------------------------------------------------------------------------------------------------------

  [   PS/2 ]

     :
                                        PS/2
                                           Japanese keyboard
                                     Russian
        ANSI                             1251 - @%SystemRoot%\system32\mlang.dll,-4611
        OEM                              866 - @%SystemRoot%\system32\mlang.dll,-4645
                                         1
                                         31

  [ Microsoft PS/2  ]

     :
                                            Microsoft PS/2 
                                         3
                                              
                                         1
                                     500 msec
       X / Y                                       6 / 10
                                 3

     :
                               
      ''                                
                
                                            
                   
                                              
      Sonar                                             

     :
                                                   Microsoft Corporation
                                     http://www.microsoft.com/products
                                       http://www.microsoft.com/downloads
                                     http://driveragent.com?ref=59


--------[  ]----------------------------------------------------------------------------------------------------

  [ Fax ]

     :
                                             Fax
                                      
                                  
                                            SHRFAX:
                                         Microsoft Shared Fax Driver (v4.00)
                                           Fax
                                         winprint
                                     
                                             3:00 - 3:00
                                               1
                                 0
                                                  

     :
                                            Letter, 8.5 x 11 in
                                              
                                          200 x 200 dpi Mono

  [ Microsoft XPS Document Writer ( ) ]

     :
                                             Microsoft XPS Document Writer
                                      
                                  
                                            XPSPort:
                                         Microsoft XPS Document Writer (v6.00)
                                           Microsoft XPS Document Writer
                                         winprint
                                     
                                             
                                               1
                                 0
                                                  

     :
                                            A4, 210 x 297 mm
                                              
                                          600 x 600 dpi Color


--------[   ]-------------------------------------------------------------------------------------

    EVEREST Ultimate Edition                                                                 5.00.1650  
    WinRAR 4.01 (32-bit)                                                                        4.01.0  


--------[  ]----------------------------------------------------------------------------------------------------

    Microsoft Internet Explorer 8.0.7601.17514                              MHFPT-8C8M2-V9488-FGM44-2C9T3
    Microsoft Windows 7 Ultimate                                            MHFPT-8C8M2-V9488-FGM44-2C9T3


--------[   ]-------------------------------------------------------------------------------------------------

    386               Virtual Device Driver                                            
    3G2               3GPP2 Audio/Video                                                video/3gpp2
    3GP               3GPP Audio/Video                                                 video/3gpp
    3GP2              3GPP2 Audio/Video                                                video/3gpp2
    3GPP              3GPP Audio/Video                                                 video/3gpp
    7Z                WinRAR archive                                                   
    AAC               ADTS Audio                                                       audio/vnd.dlna.adts
    ACE               WinRAR archive                                                   
    ADT               ADTS Audio                                                       audio/vnd.dlna.adts
    ADTS              ADTS Audio                                                       audio/vnd.dlna.adts
    AIF               AIFF Format Sound                                                audio/aiff
    AIFC              AIFF Format Sound                                                audio/aiff
    AIFF              AIFF Format Sound                                                audio/aiff
    ANI               Animated Cursor                                                  
    APPLICATION       Application Manifest                                             application/x-ms-application
    APPREF-MS         Application Reference                                            
    ARJ               WinRAR archive                                                   
    ASA               ASA File                                                         
    ASF               Windows Media Audio/Video file                                   video/x-ms-asf
    ASP               ASP File                                                         
    ASX               Windows Media Audio/Video playlist                               video/x-ms-asf
    AU                AU Format Sound                                                  audio/basic
    AVI               Video Clip                                                       video/avi
    BAT               Windows Batch File                                               
    BLG               Performance Monitor File                                         
    BMP               Bitmap Image                                                     image/bmp
    BZ                WinRAR archive                                                   
    BZ2               WinRAR archive                                                   
    C2R               C2R File                                                         
    CAB               WinRAR archive                                                   
    CAMP              WCS Viewing Condition Profile                                    
    CAT               Security Catalog                                                 application/vnd.ms-pki.seccat
    CDA               CD Audio Track                                                   
    CDMP              WCS Device Profile                                               
    CDX               CDX File                                                         
    CER               Security Certificate                                             application/x-x509-ca-cert
    CHESSTITANSSAVE-MS  .ChessTitansSave-ms                                              
    CHK               Recovered File Fragments                                         
    CHM               Compiled HTML Help file                                          
    CMD               Windows Command Script                                           
    COM               MS-DOS Application                                               
    COMFYCAKESSAVE-MS  .ComfyCakesSave-ms                                               
    COMPOSITEFONT     Composite Font File                                              
    CONTACT           Contact File                                                     text/x-ms-contact
    CPL               Control Panel Item                                               
    CRD               Information Card                                                 
    CRDS              Information Card Store                                           
    CRL               Certificate Revocation List                                      application/pkix-crl
    CRT               Security Certificate                                             application/x-x509-ca-cert
    CSS               Cascading Style Sheet Document                                   text/css
    CUR               Cursor                                                           
    DB                Data Base File                                                   
    DER               Security Certificate                                             application/x-x509-ca-cert
    DESKLINK          Desktop Shortcut                                                 
    DIAGCAB           Diagnostic Cabinet                                               
    DIAGCFG           Diagnostic Configuration                                         
    DIAGPKG           Diagnostic Document                                              
    DIB               Bitmap Image                                                     image/bmp
    DLL               Application Extension                                            application/x-msdownload
    DOCX              OOXML Text Document                                              
    DRV               Device Driver                                                    
    DSN               Microsoft OLE DB Provider for ODBC Drivers                       
    DVR               Microsoft Recorded TV Show                                       
    DVR-MS            Microsoft Recorded TV Show                                       
    DWFX              XPS Document                                                     model/vnd.dwfx+xps
    EASMX             XPS Document                                                     model/vnd.easmx+xps
    EDRWX             XPS Document                                                     model/vnd.edrwx+xps
    EMF               EMF File                                                         
    EPRTX             XPS Document                                                     model/vnd.eprtx+xps
    EVT               EVT File                                                         
    EVTX              EVTX File                                                        
    EXE               Application                                                      application/x-msdownload
    FON               Font file                                                        
    FREECELLSAVE-MS   .FreeCellSave-ms                                                 
    GADGET            Windows Gadget                                                   
    GIF               GIF Image                                                        image/gif
    GMMP              WCS Gamut Mapping Profile                                        
    GROUP             Contact Group File                                               text/x-ms-group
    GRP               Microsoft Program Group                                          
    GZ                WinRAR archive                                                   
    H1C               Windows Help Collection Definition File                          
    H1D               Windows Help Validator File                                      
    H1F               Windows Help Include File                                        
    H1H               Windows Help Merged Hierarchy                                    
    H1K               Windows Help Index File                                          
    H1Q               Windows Help Merged Query Index                                  
    H1S               Compiled Windows Help file                                       
    H1T               Windows Help Table of Contents File                              
    H1V               Windows Help Virtual Topic Definition File                       
    H1W               Windows Help Merged Keyword Index                                
    HEARTSSAVE-MS     .HeartsSave-ms                                                   
    HLP               Help File                                                        
    HTA               HTML Application                                                 application/hta
    HTM               HTML Document                                                    text/html
    HTML              HTML Document                                                    text/html
    ICC               ICC Profile                                                      
    ICL               Icon Library                                                     
    ICM               ICC Profile                                                      
    ICO               Icon                                                             image/x-icon
    IMG               Disc Image File                                                  
    INF               Setup Information                                                
    INI               Configuration Settings                                           
    ISO               Disc Image File                                                  
    JAR               WinRAR archive                                                   
    JFIF              JPEG Image                                                       image/jpeg
    JNT               Journal Document                                                 
    JOB               Task Scheduler Task Object                                       
    JOD               Microsoft.Jet.OLEDB.4.0                                          
    JPE               JPEG Image                                                       image/jpeg
    JPEG              JPEG Image                                                       image/jpeg
    JPG               JPEG Image                                                       image/jpeg
    JS                JScript Script File                                              
    JSE               JScript Encoded File                                             
    JTP               Journal Template                                                 
    JTX               XPS Document                                                     application/x-jtx+xps
    LABEL             Property List                                                    
    LHA               WinRAR archive                                                   
    LIBRARY-MS        Library Folder                                                   application/windows-library+xml
    LNK               Shortcut                                                         
    LOG               Text Document                                                    
    LZH               WinRAR archive                                                   
    M1V               Movie Clip                                                       video/mpeg
    M2T               AVCHD Video                                                      video/vnd.dlna.mpeg-tts
    M2TS              AVCHD Video                                                      video/vnd.dlna.mpeg-tts
    M2V               Movie Clip                                                       video/mpeg
    M3U               M3U file                                                         audio/x-mpegurl
    M4A               MPEG-4 Audio                                                     audio/mp4
    M4V               MP4 Video                                                        video/mp4
    MAHJONGTITANSSAVE-MS  .MahjongTitansSave-ms                                            
    MAPIMAIL          Mail Service                                                     
    MCL               MCL File                                                         
    MHT               MHTML Document                                                   message/rfc822
    MHTML             MHTML Document                                                   message/rfc822
    MID               MIDI Sequence                                                    audio/mid
    MIDI              MIDI Sequence                                                    audio/mid
    MIG               Migration Store                                                  
    MINESWEEPERSAVE-MS  .MinesweeperSave-ms                                              
    MLC               Language Pack File_                                              
    MOD               Movie Clip                                                       video/mpeg
    MOV               QuickTime Movie                                                  video/quicktime
    MP2               MP3 Format Sound                                                 audio/mpeg
    MP2V              Movie Clip                                                       video/mpeg
    MP3               MP3 Format Sound                                                 audio/mpeg
    MP4               MP4 Video                                                        video/mp4
    MP4V              MP4 Video                                                        video/mp4
    MPA               Movie Clip                                                       video/mpeg
    MPE               Movie Clip                                                       video/mpeg
    MPEG              Movie Clip                                                       video/mpeg
    MPG               Movie Clip                                                       video/mpeg
    MPV2              Movie Clip                                                       video/mpeg
    MSC               Microsoft Common Console Document                                
    MSDVD             MSDVD File                                                       
    MSI               Windows Installer Package                                        
    MSP               Windows Installer Patch                                          
    MSRCINCIDENT      Windows Remote Assistance Invitation                             
    MSSTYLES          Windows Visual Style File                                        
    MSU               Microsoft Update Standalone Package                              
    MTS               AVCHD Video                                                      video/vnd.dlna.mpeg-tts
    MYDOCS            MyDocs Drop Target                                               
    NFO               MSInfo Configuration File                                        
    OCX               ActiveX control                                                  
    ODT               ODT File                                                         
    OSDX              OpenSearch Description File                                      application/opensearchdescription+xml
    OTF               OpenType Font file                                               
    P10               Certificate Request                                              application/pkcs10
    P12               Personal Information Exchange                                    application/x-pkcs12
    P7B               PKCS #7 Certificates                                             application/x-pkcs7-certificates
    P7C               Digital ID File                                                  application/pkcs7-mime
    P7M               PKCS #7 MIME Message                                             application/pkcs7-mime
    P7R               Certificate Request Response                                     application/x-pkcs7-certreqresp
    P7S               PKCS #7 Signature                                                application/pkcs7-signature
    PBK               Dial-Up Phonebook                                                
    PERFMONCFG        Performance Monitor Configuration                                
    PFM               Type 1 Font file                                                 
    PFX               Personal Information Exchange                                    application/x-pkcs12
    PIF               Shortcut to MS-DOS Program                                       
    PKO               Public Key Security Object                                       application/vnd.ms-pki.pko
    PNF               Precompiled Setup Information                                    
    PNG               PNG Image                                                        image/png
    PRF               PICS Rules File                                                  application/pics-rules
    PRINTEREXPORT     Printer Migration File                                           
    PS1               PS1 File                                                         
    PS1XML            PS1XML File                                                      
    PSC1              PSC1 File                                                        application/PowerShell
    PSD1              PSD1 File                                                        
    PSM1              PSM1 File                                                        
    PURBLEPAIRSSAVE-MS  .PurblePairsSave-ms                                              
    PURBLESHOPSAVE-MS  .PurbleShopSave-ms                                               
    QDS               Directory Query                                                  
    R00               WinRAR archive                                                   
    R01               WinRAR archive                                                   
    R02               WinRAR archive                                                   
    R03               WinRAR archive                                                   
    R04               WinRAR archive                                                   
    R05               WinRAR archive                                                   
    R06               WinRAR archive                                                   
    R07               WinRAR archive                                                   
    R08               WinRAR archive                                                   
    R09               WinRAR archive                                                   
    R10               WinRAR archive                                                   
    R11               WinRAR archive                                                   
    R12               WinRAR archive                                                   
    R13               WinRAR archive                                                   
    R14               WinRAR archive                                                   
    R15               WinRAR archive                                                   
    R16               WinRAR archive                                                   
    R17               WinRAR archive                                                   
    R18               WinRAR archive                                                   
    R19               WinRAR archive                                                   
    R20               WinRAR archive                                                   
    R21               WinRAR archive                                                   
    R22               WinRAR archive                                                   
    R23               WinRAR archive                                                   
    R24               WinRAR archive                                                   
    R25               WinRAR archive                                                   
    R26               WinRAR archive                                                   
    R27               WinRAR archive                                                   
    R28               WinRAR archive                                                   
    R29               WinRAR archive                                                   
    RAR               WinRAR archive                                                   
    RAT               Rating System File                                               application/rat-file
    RDP               Remote Desktop Connection                                        
    REG               Registration Entries                                             
    RESMONCFG         Resource Monitor Configuration                                   
    REV               RAR recovery volume                                              
    RLE               RLE File                                                         
    RLL               Application Extension                                            
    RMI               MIDI Sequence                                                    audio/mid
    RTF               Rich Text Document                                               
    SCF               Windows Explorer Command                                         
    SCP               Text Document                                                    
    SCR               Screen saver                                                     
    SCT               Windows Script Component                                         text/scriptlet
    SEARCHCONNECTOR-MS  Search Connector Folder                                          application/windows-search-connector+xml
    SEARCH-MS         Saved Search                                                     
    SFCACHE           ReadyBoost Cache File                                            
    SLUPKG-MS         XrML Digital License Package                                     application/x-ms-license
    SND               AU Format Sound                                                  audio/basic
    SOLITAIRESAVE-MS  .SolitaireSave-ms                                                
    SPC               PKCS #7 Certificates                                             application/x-pkcs7-certificates
    SPIDERSOLITAIRESAVE-MS  .SpiderSolitaireSave-ms                                          
    SST               Microsoft Serialized Certificate Store                           application/vnd.ms-pki.certstore
    STL               Certificate Trust List                                           application/vnd.ms-pki.stl
    SYS               System file                                                      
    TAR               WinRAR archive                                                   
    TAZ               WinRAR archive                                                   
    TBZ               WinRAR archive                                                   
    TBZ2              WinRAR archive                                                   
    TGZ               WinRAR archive                                                   
    THEME             Windows Theme File                                               
    THEMEPACK         Windows Theme Pack                                               
    TIF               TIF File                                                         image/tiff
    TIFF              TIFF File                                                        image/tiff
    TS                MPEG-2 TS Video                                                  video/vnd.dlna.mpeg-tts
    TTC               TrueType Collection Font file                                    
    TTF               TrueType Font file                                               
    TTS               MPEG-2 TS Video                                                  video/vnd.dlna.mpeg-tts
    TXT               Text Document                                                    text/plain
    UDL               Microsoft Data Link                                              
    URL               URL File                                                         
    UU                WinRAR archive                                                   
    UUE               WinRAR archive                                                   
    VBE               VBScript Encoded File                                            
    VBS               VBScript Script File                                             
    VCF               vCard File                                                       text/x-vcard
    VXD               Virtual Device Driver                                            
    WAB               Address Book File                                                
    WAV               Wave Sound                                                       audio/wav
    WAX               Windows Media Audio shortcut                                     audio/x-ms-wax
    WBCAT             Windows Backup Catalog File                                      
    WCX               Workspace Configuration File                                     
    WDP               Windows Media Photo                                              image/vnd.ms-photo
    WEBPNP            Web Point And Print File                                         
    WM                Windows Media Audio/Video file                                   video/x-ms-wm
    WMA               Windows Media Audio file                                         audio/x-ms-wma
    WMD               Windows Media Player Download Package                            application/x-ms-wmd
    WMDB              Windows Media Library                                            
    WMF               WMF File                                                         
    WMS               Windows Media Player Skin File                                   
    WMV               Windows Media Audio/Video file                                   video/x-ms-wmv
    WMX               Windows Media Audio/Video playlist                               video/x-ms-wmx
    WMZ               Windows Media Player Skin Package                                application/x-ms-wmz
    WPL               Windows Media playlist                                           application/vnd.ms-wpl
    WSC               Windows Script Component                                         text/scriptlet
    WSF               Windows Script File                                              
    WSH               Windows Script Host Settings File                                
    WTV               Windows Recorded TV Show                                         
    WTX               Text Document                                                    
    WVX               Windows Media Audio/Video playlist                               video/x-ms-wvx
    XAML              Windows Markup File                                              application/xaml+xml
    XBAP              XAML Browser Application                                         application/x-ms-xbap
    XML               XML Document                                                     text/xml
    XPS               XPS Document                                                     application/vnd.ms-xpsdocument
    XRM-MS            XrML Digital License                                             text/xml
    XSL               XSL Stylesheet                                                   text/xml
    XXE               WinRAR archive                                                   
    Z                 WinRAR archive                                                   
    ZFSENDTOTARGET    Compressed (zipped) Folder SendTo Target                         
    ZIP               WinRAR ZIP archive                                               


--------[ Sidebar Gadgets ]---------------------------------------------------------------------------------------------

  [ Calendar ]

    Gadget Properties:
                                                     Calendar
                                                Browse the days of the calendar.
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Calendar.Gadget\en-US\gadget.xml

  [ Clock ]

    Gadget Properties:
                                                     Clock
                                                Watch the clock in your own time zone or any city in the world.
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Clock.Gadget\en-US\gadget.xml

  [ CPU Meter ]

    Gadget Properties:
                                                     CPU Meter
                                                See the current computer CPU and system memory (RAM).
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               CPU.Gadget\en-US\gadget.xml

  [ Currency ]

    Gadget Properties:
                                                     Currency
                                                Convert from one currency to another.
                                                  1.0.0.0
                                                   Microsoft Corporation
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Currency.Gadget\en-US\gadget.xml

  [ Feed Headlines ]

    Gadget Properties:
                                                     Feed Headlines
                                                Track the latest news, sports, and entertainment headlines.
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               RSSFeeds.Gadget\en-US\gadget.xml

  [ Picture Puzzle ]

    Gadget Properties:
                                                     Picture Puzzle
                                                Move the pieces of the puzzle and try to put them in order.
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               PicturePuzzle.Gadget\en-US\gadget.xml

  [ Slide Show ]

    Gadget Properties:
                                                     Slide Show
                                                Show a continuous slide show of your pictures.
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               SlideShow.Gadget\en-US\gadget.xml

  [ Weather ]

    Gadget Properties:
                                                     Weather
                                                See what the weather looks like around the world.
                                                  1.1.0.0
                                                   Microsoft Corporation
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Weather.Gadget\en-US\gadget.xml

  [ Windows Media Center ]

    Gadget Properties:
                                                     Windows Media Center
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               MediaCenter.Gadget\ru-RU\gadget.xml

  [ Windows Media Center ]

    Gadget Properties:
                                                     Windows Media Center
                                                Play your latest TV recordings, new Internet TV clips, and favorite music and pictures.
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               MediaCenter.Gadget\en-US\gadget.xml

  [  ]

    Gadget Properties:
                                                     
                                                     .
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               PicturePuzzle.Gadget\ru-RU\gadget.xml

  [   - ]

    Gadget Properties:
                                                       -
                                                   ,     .
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               RSSFeeds.Gadget\ru-RU\gadget.xml

  [   ]

    Gadget Properties:
                                                      
                                                      (RAM).
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               CPU.Gadget\ru-RU\gadget.xml

  [  ]

    Gadget Properties:
                                                     
                                                  .
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Calendar.Gadget\ru-RU\gadget.xml

  [   ]

    Gadget Properties:
                                                      
                                                     .
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               SlideShow.Gadget\ru-RU\gadget.xml

  [  ]

    Gadget Properties:
                                                     
                                                          .
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Clock.Gadget\ru-RU\gadget.xml


--------[  Windows ]----------------------------------------------------------------------------------------

      :
                                              Microsoft Windows 7 Ultimate
                                       Service Pack 1
      Winlogon Shell                                    explorer.exe
          (UAC)  
                                   

       (DEP, NX, EDB):
                                        
                                        
       ( )                       
       ( )                        


--------[  Windows ]------------------------------------------------------------------------------------------

    (Automatic Update)                                                                Download:Notify, Install:Notify  


--------[  ]--------------------------------------------------------------------------------------------------

     Windows                              6.1.7600.16385  


--------[   ]--------------------------------------------------------------------------------------------

    Microsoft Windows Defender                6.1.7600.16385(win7_rtm.090713-1255)


--------[   ]--------------------------------------------------------------------------------------

     :
                                      ()
                            (UTC+02:00) 
                               
                                    

    :
       (.)                                      
       (.)                                      Russian
       (ISO 639)                                    ru

    /:
       (.)                                    
       (.)                                    Russia
       (ISO 3166)                                 RU
                                               7

     :
        (.)                          
        (.)                          Russian Ruble
         (.)                   .
         (ISO 4217)                RUB
                                      123456789,00.
                         -123456789,00.

    :
                                           H:mm:ss
                                       dd.MM.yyyy
                                        d MMMM yyyy '.'
                                       123456789,00
                          -123456789,00
                                            first; second; third
                                               0123456789

     :
                                       / 
                                           / 
                                              / 
                                           / 
                                            / 
                                            / 
                                        / 

    :
                                             / 
                                            / 
                                              / 
                                             / 
                                                / 
                                               / 
                                               / 
                                            / 
                                           / 
                                            / 
                                             / 
                                            / 

    :
                                            Gregorian (localized)
                                 A4
                                        


--------[  ]---------------------------------------------------------------------------------------------------

    ALLUSERSPROFILE           C:\ProgramData
    APPDATA                   C:\Users\user\AppData\Roaming
    CommonProgramFiles        C:\Program Files\Common Files
    COMPUTERNAME              USER-PC
    ComSpec                   C:\Windows\system32\cmd.exe
    FP_NO_HOST_CHECK          NO
    HOMEDRIVE                 C:
    HOMEPATH                  \Users\user
    LOCALAPPDATA              C:\Users\user\AppData\Local
    LOGONSERVER               \\USER-PC
    NUMBER_OF_PROCESSORS      2
    OS                        Windows_NT
    Path                      C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\
    PATHEXT                   .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    PROCESSOR_ARCHITECTURE    x86
    PROCESSOR_IDENTIFIER      x86 Family 15 Model 75 Stepping 2, AuthenticAMD
    PROCESSOR_LEVEL           15
    PROCESSOR_REVISION        4b02
    ProgramData               C:\ProgramData
    ProgramFiles              C:\Program Files
    PSModulePath              C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
    PUBLIC                    C:\Users\Public
    SystemDrive               C:
    SystemRoot                C:\Windows
    TEMP                      C:\Users\user\AppData\Local\Temp
    TMP                       C:\Users\user\AppData\Local\Temp
    USERDOMAIN                user-PC
    USERNAME                  user
    USERPROFILE               C:\Users\user
    windir                    C:\Windows
    windows_tracing_flags     3
    windows_tracing_logfile   C:\BVTBin\Tests\installpackage\csilogfile.log


--------[   ]-------------------------------------------------------------------------------------------

    Windows CardSpace                                  -    .
                                         -, DVD  ,      ,  ,   ,  .
                                 
                            .      .
     Windows                           ,       .
                                                Windows.
                                .
                                     ,       .
                .
                                  .
                           Windows.
                                   ,         .
     Windows                                 
                                                .
                         ,      .
                                      , ,       .
                                            , ,  ,   ,     .
        ''''                ''''   , ,       .
                             
                                    .
                                 ,       .
           RemoteApp          RemoteApp
                                  Windows    .
                                .
                          ,      ,     ,  ,      .
                                 
                             .
                                .
                                               , ,  .
               .   ,   , ,    .
                                           .
                                 ,   .
                                .
                              ,    
                          ,    .
      Windows                       ,    ,   .
                                       .
                                  ( ).
                     .
             ,            .
      BitLocker                       BitLocker.
                                           ,    .
                                                .
                                          .
                      ,  ,  ,   .


--------[  ]-----------------------------------------------------------------------------------------------------

    C:            0         0      ?  ?
    D:            0         0      ?  ?


--------[   ]---------------------------------------------------------------------------------------------

  [ autoexec.bat ]

    REM Dummy file for NTVDM

  [ config.sys ]

    FILES=40

  [ autoexec.nt ]

    @echo off
    
    REM AUTOEXEC.BAT is not used to initialize the MS-DOS environment.
    REM AUTOEXEC.NT is used to initialize the MS-DOS environment unless a
    REM different startup file is specified in an application's PIF.
    
    REM Install CD ROM extensions
    lh %SystemRoot%\system32\mscdexnt.exe
    
    REM Install network redirector (load before dosx.exe)
    lh %SystemRoot%\system32\redir
    
    REM Install DPMI support
    lh %SystemRoot%\system32\dosx
    
    REM The following line enables Sound Blaster 2.0 support on NTVDM.
    REM The command for setting the BLASTER environment is as follows:
    REM    SET BLASTER=A220 I5 D1 P330
    REM    where:
    REM        A    specifies the sound blaster's base I/O port
    REM        I    specifies the interrupt request line
    REM        D    specifies the 8-bit DMA channel
    REM        P    specifies the MPU-401 base I/O port
    REM        T    specifies the type of sound blaster card
    REM                 1 - Sound Blaster 1.5
    REM                 2 - Sound Blaster Pro I
    REM                 3 - Sound Blaster 2.0
    REM                 4 - Sound Blaster Pro II
    REM                 6 - SOund Blaster 16/AWE 32/32/64
    REM
    REM    The default value is A220 I5 D1 T3 and P330.  If any of the switches is
    REM    left unspecified, the default value will be used. (NOTE, since all the
    REM    ports are virtualized, the information provided here does not have to
    REM    match the real hardware setting.)  NTVDM supports Sound Blaster 2.0 only.
    REM    The T switch must be set to 3, if specified.
    SET BLASTER=A220 I5 D1 P330 T3
    
    REM To disable the sound blaster 2.0 support on NTVDM, specify an invalid
    REM SB base I/O port address.  For example:
    REM    SET BLASTER=A0

  [ config.nt ]

    REM Windows MS-DOS Startup File
    REM
    REM CONFIG.SYS vs CONFIG.NT
    REM CONFIG.SYS is not used to initialize the MS-DOS environment.
    REM CONFIG.NT is used to initialize the MS-DOS environment unless a
    REM different startup file is specified in an application's PIF.
    REM
    REM ECHOCONFIG
    REM By default, no information is displayed when the MS-DOS environment
    REM is initialized. To display CONFIG.NT/AUTOEXEC.NT information, add
    REM the command echoconfig to CONFIG.NT or other startup file.
    REM
    REM NTCMDPROMPT
    REM When you return to the command prompt from a TSR or while running an
    REM MS-DOS-based application, Windows runs COMMAND.COM. This allows the
    REM TSR to remain active. To run CMD.EXE, the Windows command prompt,
    REM rather than COMMAND.COM, add the command ntcmdprompt to CONFIG.NT or
    REM other startup file.
    REM
    REM DOSONLY
    REM By default, you can start any type of application when running
    REM COMMAND.COM. If you start an application other than an MS-DOS-based
    REM application, any running TSR may be disrupted. To ensure that only
    REM MS-DOS-based applications can be started, add the command dosonly to
    REM CONFIG.NT or other startup file.
    REM
    REM EMM
    REM You can use EMM command line to configure EMM(Expanded Memory Manager).
    REM The syntax is:
    REM
    REM EMM = [A=AltRegSets] [B=BaseSegment] [RAM]
    REM
    REM     AltRegSets
    REM         specifies the total Alternative Mapping Register Sets you
    REM         want the system to support. 1 <= AltRegSets <= 255. The
    REM         default value is 8.
    REM     BaseSegment
    REM         specifies the starting segment address in the Dos conventional
    REM         memory you want the system to allocate for EMM page frames.
    REM         The value must be given in Hexdecimal.
    REM         0x1000 <= BaseSegment <= 0x4000. The value is rounded down to
    REM         16KB boundary. The default value is 0x4000
    REM     RAM
    REM         specifies that the system should only allocate 64Kb address
    REM         space from the Upper Memory Block(UMB) area for EMM page frames
    REM         and leave the rests(if available) to be used by DOS to support
    REM         loadhigh and devicehigh commands. The system, by default, would
    REM         allocate all possible and available UMB for page frames.
    REM
    REM     The EMM size is determined by pif file(either the one associated
    REM     with your application or _default.pif). If the size from PIF file
    REM     is zero, EMM will be disabled and the EMM line will be ignored.
    REM
    dos=high, umb
    device=%SystemRoot%\system32\himem.sys
    files=40

  [ system.ini ]

    ; for 16-bit app support
    [386Enh]
    woafont=dosapp.fon
    EGA80WOA.FON=EGA80WOA.FON
    EGA40WOA.FON=EGA40WOA.FON
    CGA80WOA.FON=CGA80WOA.FON
    CGA40WOA.FON=CGA40WOA.FON
    
    [drivers]
    wave=mmdrv.dll
    timer=timer.drv
    
    [mci]

  [ win.ini ]

    ; for 16-bit app support
    [fonts]
    [extensions]
    [mci extensions]
    [files]
    [Mail]
    MAPI=1
    [MCI Extensions.BAK]
    3g2=MPEGVideo
    3gp=MPEGVideo
    3gp2=MPEGVideo
    3gpp=MPEGVideo
    aac=MPEGVideo
    adt=MPEGVideo
    adts=MPEGVideo
    m2t=MPEGVideo
    m2ts=MPEGVideo
    m2v=MPEGVideo
    m4a=MPEGVideo
    m4v=MPEGVideo
    mod=MPEGVideo
    mov=MPEGVideo
    mp4=MPEGVideo
    mp4v=MPEGVideo
    mts=MPEGVideo
    ts=MPEGVideo
    tts=MPEGVideo

  [ hosts ]

    

  [ lmhosts.sam ]

    
    
    
    


--------[   ]---------------------------------------------------------------------------------------------

    Administrative Tools         C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    AppData                      C:\Users\user\AppData\Roaming
    Cache                        C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files
    CD Burning                   C:\Users\user\AppData\Local\Microsoft\Windows\Burn\Burn
    Common Administrative Tools  C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    Common AppData               C:\ProgramData
    Common Desktop               C:\Users\Public\Desktop
    Common Documents             C:\Users\Public\Documents
    Common Favorites             C:\Users\user\Favorites
    Common Files                 C:\Program Files\Common Files
    Common Music                 C:\Users\Public\Music
    Common Pictures              C:\Users\Public\Pictures
    Common Programs              C:\ProgramData\Microsoft\Windows\Start Menu\Programs
    Common Start Menu            C:\ProgramData\Microsoft\Windows\Start Menu
    Common Startup               C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
    Common Templates             C:\ProgramData\Microsoft\Windows\Templates
    Common Video                 C:\Users\Public\Videos
    Cookies                      C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies
    Desktop                      C:\Users\user\Desktop
    Device                       C:\Windows\inf
    Favorites                    C:\Users\user\Favorites
    Fonts                        C:\Windows\Fonts
    History                      C:\Users\user\AppData\Local\Microsoft\Windows\History
    Local AppData                C:\Users\user\AppData\Local
    My Documents                 C:\Users\user\Documents
    My Music                     C:\Users\user\Music
    My Pictures                  C:\Users\user\Pictures
    My Video                     C:\Users\user\Videos
    NetHood                      C:\Users\user\AppData\Roaming\Microsoft\Windows\Network Shortcuts
    PrintHood                    C:\Users\user\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
    Profile                      C:\Users\user
    Program Files                C:\Program Files
    Programs                     C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
    Recent                       C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent
    Resources                    C:\Windows\resources
    SendTo                       C:\Users\user\AppData\Roaming\Microsoft\Windows\SendTo
    Start Menu                   C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu
    Startup                      C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
    System                       C:\Windows\system32
    Temp                         C:\Users\user\AppData\Local\Temp\
    Templates                    C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates
    Windows                      C:\Windows


--------[   ]-------------------------------------------------------------------------------------------

                     2002-01-02 01:27:56                                  EventSystem                     
                     2002-01-02 01:27:56                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-02 01:27:57                                  Winlogon                        4101:  Windows .  
                     2002-01-02 01:27:57                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-02 01:27:58                                  Desktop Window Manager          9007:       ,   WDDM    
       Unknown                 2002-01-02 01:27:58                                  WinMgmt                         
       Unknown                 2002-01-02 01:28:25                                  WinMgmt                         
             1          2002-01-02 01:28:27                                  ESENT                           102: Windows (1980) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-02 01:28:27                                  ESENT                           300: Windows (1980) Windows:     .  
             3          2002-01-02 01:28:27                                  ESENT                           301: Windows (1980) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-02 01:28:27                                  ESENT                           302: Windows (1980) Windows:    .  
             1          2002-01-02 01:28:28                                  Windows Search Service          1003:  Windows Search .   
                     2002-01-02 01:28:56                                  Windows Error Reporting         1001:   ,  0   : PnPDriverNotFound  :     CAB: 0     :  P1: x86  P2: ACPI\ATK0110  P3:   P4:   P5:   P6:   P7:   P8:   P9:   P10:      :  C:\Users\user\AppData\Local\Temp\DMI58B9.tmp.log.xml        :  C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x86_93856eefc23cb6f60c4f9525ca72dec1a9d7155_cab_05355946     :     : 0   : 52bd0fa0-ff0f-11d5-a8d6-ce1c13e0201f   : 6  
                         2002-01-02 01:29:28                                  WinMgmt                         
                     2002-01-02 01:30:01                                  Software Protection Platform Service  900:      .    
                     2002-01-02 01:30:03                                  SecurityCenter                  1:     Windows .  
                     2002-01-02 01:30:03                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-02 01:30:05                                  Software Protection Platform Service  1033:   ,       override-only.   =(IIS-W3SVC-MaxConcurrentRequests) (Microsoft.Windows.Smc-Enabled) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (nfs-admincmdtools-enabled) (nfs-adminmmc-enabled) (nfs-clientcmdtools-enabled) (nfs-clientcore-enabled) (sua-EnableSUA)    =55c92734-d682-4d71-983e-d6ec3f16059f   SKU=ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8  
                     2002-01-02 01:30:05                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 30 0)( 5 0xC004F009 30 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-02 01:30:05                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                     2002-01-02 01:30:14                                  Desktop Window Manager          9009:         (0x40010004)  
                     2002-01-02 01:30:14                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-02 01:30:16                           Microsoft-Windows-User Profiles Service  1532:    .        
                     2002-01-02 01:30:52                                  EventSystem                     
                     2002-01-02 01:30:52                           Microsoft-Windows-User Profiles Service  1531:     .        
       Unknown                 2002-01-02 01:30:53                                  WinMgmt                         
                       2002-01-02 01:30:54                                  Winlogon                        4105: Windows    .  
                     2002-01-02 01:30:58                                  Software Protection Platform Service  900:      .    
                     2002-01-02 01:30:58                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-02 01:30:58                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 30 0)( 5 0xC004F009 30 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-02 01:30:58                                  WinMgmt                         
       Unknown                 2002-01-02 01:30:58                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                     2002-01-02 01:31:11                                  Winlogon                        4104:   Windows   .  
                     2002-01-02 01:31:11                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
             1          2002-01-02 01:31:18                                  ESENT                           102: Windows (296) Windows:   (6.01.7601.0000)    (0).  
             1          2002-01-02 01:31:18                                  Windows Search Service          1003:  Windows Search .   
             3          2002-01-02 01:31:18                                  ESENT                           300: Windows (296) Windows:     .  
             3          2002-01-02 01:31:18                                  ESENT                           301: Windows (296) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-02 01:31:18                                  ESENT                           302: Windows (296) Windows:    .  
                     2002-01-02 01:32:06                                  Desktop Window Manager          9009:         (0x40010004)  
                     2002-01-02 01:32:06                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-02 01:32:07                           Microsoft-Windows-User Profiles Service  1532:    .        
                     2002-01-02 01:32:42                                  EventSystem                     
                     2002-01-02 01:32:42                           Microsoft-Windows-User Profiles Service  1531:     .        
       Unknown                 2002-01-02 01:32:43                                  WinMgmt                         
                       2002-01-02 01:32:43                                  Winlogon                        4105: Windows    .  
                     2002-01-02 01:32:44                                  Software Protection Platform Service  900:      .    
       Unknown                 2002-01-02 01:32:44                                  WinMgmt                         
                     2002-01-02 01:32:45                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-02 01:32:45                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 30 0)( 5 0xC004F009 30 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-02 01:32:45                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                         2002-01-02 01:34:26                                  WinMgmt                         
                     2002-01-02 01:34:34                                  Winlogon                        4104:   Windows   .  
                     2002-01-02 01:36:45                                  EventSystem                     
                     2002-01-02 01:36:45                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-02 01:36:46                                  WinMgmt                         
       Unknown                 2002-01-02 01:36:46                                  WinMgmt                         
                       2002-01-02 01:36:46                                  Winlogon                        4105: Windows    .  
                     2002-01-02 01:36:48                                  Software Protection Platform Service  900:      .    
                     2002-01-02 01:36:48                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-02 01:36:48                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 30 0)( 5 0xC004F009 30 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-02 01:36:48                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
       Unknown                 2002-01-02 01:36:56                                  WinMgmt                         
                     2002-01-02 01:37:14                                  Windows Error Reporting         1001:   ,  0   : PnPDeviceProblemCode  :     CAB: 0     :  P1: x86  P2: USB\UNKNOWN  P3: {36fc9e60-c465-11cf-8056-444553540000}  P4: 0000002B  P5: unknown  P6: unknown  P7: unknown  P8:   P9:   P10:      :  C:\Users\user\AppData\Local\Temp\DMIB4AE.tmp.log.xml  C:\Windows\inf\usb.inf        :  C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x86_a796cc5babf24d790d38cfc7dd844dad2e847e4_cab_0634b52b     :     : 0   : 7b9752e0-ff10-11d5-9dcf-001bfc896f8c   : 6  
                         2002-01-02 01:38:28                                  WinMgmt                         
                     2002-01-02 01:38:46                                  Winlogon                        4104:   Windows   .  
                     2002-01-02 01:38:46                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-02 01:38:53                                  SecurityCenter                  1:     Windows .  
             1          2002-01-02 01:38:56                                  ESENT                           102: Windows (1676) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-02 01:38:57                                  ESENT                           300: Windows (1676) Windows:     .  
             3          2002-01-02 01:38:57                                  ESENT                           301: Windows (1676) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-02 01:38:57                                  ESENT                           302: Windows (1676) Windows:    .  
             1          2002-01-02 01:38:58                                  Windows Search Service          1003:  Windows Search .   
                     2002-01-02 01:40:54                           Microsoft-Windows-LoadPerf      1001:     WmiApRpl (WmiApRpl)  .        Last Counter  Last Help.  
                     2002-01-02 01:40:54                           Microsoft-Windows-LoadPerf      1000: C    WmiApRpl (WmiApRpl)  .         ,   .  
       Unknown                 2002-01-02 01:49:15                                  .NET Runtime Optimization Service  1130: .NET Runtime Optimization Service (2.0.50727.5420) - Installed from repository: Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets  
                     2002-01-02 01:53:54                                  Windows Error Reporting         1001:   ,  0   : MpTelemetry  :     CAB: 0     :  P1: 8024001f  P2: EndSearch  P3: Search  P4: 6.1.7601.17514  P5: MpSigDwn.dll  P6: 6.1.7600.16385  P7: Windows Defender  P8:   P9:   P10:      :  C:\Windows\Temp\MPTelemetrySubmit\client_manifest.txt        :  C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_8024001f_73aea48bd74c52b523f34668a59a345e9e5b5_cab_0c4bf5b3     :     : 0   : cf60ee20-ff12-11d5-9dcf-001bfc896f8c   : 6  
                     2002-01-02 01:53:59                                  Windows Error Reporting         1001:   ,  0   : WindowsUpdateFailure  :     CAB: 0     :  P1: 7.5.7601.17514  P2: 8024001f  P3: 00000000-0000-0000-0000-000000000000  P4: Scan  P5: 101  P6: Unmanaged  P7:   P8:   P9:   P10:      :        :       :     : 0   : d25ae4a0-ff12-11d5-9dcf-001bfc896f8c   : 0  
                     2002-01-02 01:53:59                                  Windows Error Reporting         1001:   ,  0   : WindowsUpdateFailure  :     CAB: 0     :  P1: 7.5.7601.17514  P2: 8024001f  P3: 00000000-0000-0000-0000-000000000000  P4: Scan  P5: 101  P6: Unmanaged  P7:   P8:   P9:   P10:      :        :  C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_7.5.7601.17514_78efc842cf92e79bab1c4f2fb5bd805f263a65_cab_0d880943     :     : 0   : d25ae4a0-ff12-11d5-9dcf-001bfc896f8c   : 6  
                     2002-01-02 01:58:28                                  Desktop Window Manager          9010:  (   Windows)          
                     2002-01-02 01:58:28                                  Desktop Window Manager          9013:       ,          
                     2002-01-02 01:58:54                                  Windows Error Reporting         1001:   ,  0   : MpTelemetry  :     CAB: 0     :  P1: 8024001f  P2: EndSearch  P3: Search  P4: 6.1.7601.17514  P5: MpSigDwn.dll  P6: 6.1.7600.16385  P7: Windows Defender  P8:   P9:   P10:      :        :  C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_8024001f_73aea48bd74c52b523f34668a59a345e9e5b5_0f0c8b8c     :     : 0   : 8280a4a0-ff13-11d5-9dcf-001bfc896f8c   : 6  
                     2002-01-02 01:58:59                                  Windows Error Reporting         1001:   ,  0   : WindowsUpdateFailure  :     CAB: 0     :  P1: 7.5.7601.17514  P2: 8024001f  P3: 00000000-0000-0000-0000-000000000000  P4: Scan  P5: 101  P6: Unmanaged  P7:   P8:   P9:   P10:      :        :       :     : 0   : 857962a0-ff13-11d5-9dcf-001bfc896f8c   : 0  
                     2002-01-02 01:58:59                                  Windows Error Reporting         1001:   ,  0   : WindowsUpdateFailure  :     CAB: 0     :  P1: 7.5.7601.17514  P2: 8024001f  P3: 00000000-0000-0000-0000-000000000000  P4: Scan  P5: 101  P6: Unmanaged  P7:   P8:   P9:   P10:      :        :  C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_7.5.7601.17514_78efc842cf92e79bab1c4f2fb5bd805f263a65_0fdc9f0c     :     : 0   : 857962a0-ff13-11d5-9dcf-001bfc896f8c   : 6  
                     2002-01-02 02:01:03                                  EventSystem                     
                     2002-01-02 02:01:03                           Microsoft-Windows-User Profiles Service  1531:     .        
       Unknown                 2002-01-02 02:01:06                                  WinMgmt                         
                       2002-01-02 02:01:06                                  Winlogon                        4105: Windows    .  
                     2002-01-02 02:01:08                                  Software Protection Platform Service  900:      .    
                     2002-01-02 02:01:08                                  WinMgmt                         
                     2002-01-02 02:01:13                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-02 02:01:13                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 30 0)( 5 0xC004F009 30 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-02 02:01:13                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
       Unknown                 2002-01-02 02:01:16                                  WinMgmt                         
                     2002-01-02 02:01:22                                  Winlogon                        4104:   Windows   .  
                     2002-01-02 02:01:22                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
             1          2002-01-02 02:01:30                                  ESENT                           102: Windows (420) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-02 02:01:30                                  ESENT                           300: Windows (420) Windows:     .  
             3          2002-01-02 02:01:30                                  ESENT                           301: Windows (420) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00002.log.  
             3          2002-01-02 02:01:30                                  ESENT                           301: Windows (420) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00003.log.  
             3          2002-01-02 02:01:30                                  ESENT                           301: Windows (420) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-02 02:01:30                                  ESENT                           302: Windows (420) Windows:    .  
             1          2002-01-02 02:01:31                                  Windows Search Service          1003:  Windows Search .   
                         2002-01-02 02:02:49                                  WinMgmt                         
                     2002-01-02 02:03:08                                  SecurityCenter                  1:     Windows .  
                     2002-01-04 20:54:53                                  EventSystem                     
                     2002-01-04 20:54:53                           Microsoft-Windows-User Profiles Service  1531:     .        
                       2002-01-04 20:54:53                                  Winlogon                        4105: Windows    .  
                     2002-01-04 20:54:54                                  Software Protection Platform Service  900:      .    
                     2002-01-04 20:54:54                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-04 20:54:54                                  WinMgmt                         
                     2002-01-04 20:54:54                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 30 0)( 5 0xC004F009 30 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-04 20:54:54                                  WinMgmt                         
       Unknown                 2002-01-04 20:54:54                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
       Unknown                 2002-01-04 20:55:02                                  WinMgmt                         
                         2002-01-04 20:55:10                                  Winlogon                        4103:    Windows.  0x00000000.  
                     2002-01-04 20:55:10                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-04 20:55:11                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-04 20:55:12                           Microsoft-Windows-User Profiles Service  1532:    .        
                     2002-01-04 20:56:07                                  EventSystem                     
                     2002-01-04 20:56:07                           Microsoft-Windows-User Profiles Service  1531:     .        
       Unknown                 2002-01-04 20:56:09                                  WinMgmt                         
                       2002-01-04 20:56:10                                  Winlogon                        4105: Windows    .  
                     2002-01-04 20:56:15                                  Software Protection Platform Service  900:      .    
       Unknown                 2002-01-04 20:56:15                                  WinMgmt                         
                     2002-01-04 20:56:16                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-04 20:56:16                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 30 0)( 5 0xC004F009 30 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-04 20:56:16                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                         2002-01-04 20:56:22                                  Winlogon                        4103:    Windows.  0x00000000.  
                     2002-01-04 20:56:22                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-04 20:56:23                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-04 20:56:24                           Microsoft-Windows-User Profiles Service  1532:    .        
                     2002-01-04 21:11:04                                  EventSystem                     
                     2002-01-04 21:11:04                           Microsoft-Windows-User Profiles Service  1531:     .        
       Unknown                 2002-01-04 21:11:06                                  WinMgmt                         
                       2002-01-04 21:11:06                                  Winlogon                        4105: Windows    .  
                     2002-01-04 21:11:08                                  Software Protection Platform Service  900:      .    
                     2002-01-04 21:11:10                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-04 21:11:10                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 30 0)( 5 0xC004F009 30 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-04 21:11:10                                  WinMgmt                         
       Unknown                 2002-01-04 21:11:10                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                     2002-01-04 21:11:11                                  Windows Error Reporting         1001:   ,  0   : StartupRepairOnline  :     CAB: 0     :  P1: 6.1.7600.16385  P2: 6.1.7600.16385  P3: System manufacturer  P4: 21346706  P5: 0  P6: AutoFailover  P7: 1  P8: 0xa  P9:   P10:      :        :  C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_6.1.7600.16385_202590426dcbc09d49982c2ac383c6b76b27cc9_cab_010055cc     :     : 0   : cfe024c0-0146-11d6-82ad-001bfc896f8c   : 6  
                     2002-01-04 21:11:13                                  Windows Error Reporting         1001:   ,  0   : PnPDeviceProblemCode  :     CAB: 0     :  P1: x86  P2: ACPI\PNP0F03  P3: {4d36e96f-e325-11ce-bfc1-08002be10318}  P4: 0000000A  P5: i8042prt.sys  P6: 6.1.7600.16385  P7: 07-13-2009  P8:   P9:   P10:      :  C:\Users\user\AppData\Local\Temp\DMI5E64.tmp.log.xml  C:\Windows\inf\msmouse.inf        :  C:\Users\user\AppData\Local\Microsoft\Windows\WER\ReportQueue\NonCritical_x86_18e50c447db71a4a0fc9d369f130d07e50e2b4_cab_04405ec2     :     : 0   : d1453300-0146-11d6-82ad-001bfc896f8c   : 6  
                         2002-01-04 21:11:19                                  Winlogon                        4103:    Windows.  0x00000000.  
                     2002-01-04 21:11:19                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-04 21:11:20                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-04 21:11:20                           Microsoft-Windows-User Profiles Service  1532:    .        
                     2002-01-04 21:12:02                                  EventSystem                     
                     2002-01-04 21:12:02                           Microsoft-Windows-User Profiles Service  1531:     .        
       Unknown                 2002-01-04 21:12:04                                  WinMgmt                         
                       2002-01-04 21:12:04                                  Winlogon                        4105: Windows    .  
                     2002-01-04 21:12:10                                  Software Protection Platform Service  900:      .    
                     2002-01-04 21:12:10                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
       Unknown                 2002-01-04 21:12:10                                  WinMgmt                         
                     2002-01-04 21:15:39                                  EventSystem                     
                     2002-01-04 21:15:39                           Microsoft-Windows-User Profiles Service  1531:     .        
       Unknown                 2002-01-04 21:15:46                                  WinMgmt                         
                       2002-01-04 21:15:47                                  Winlogon                        4105: Windows    .  
                     2002-01-04 21:15:50                                  Software Protection Platform Service  900:      .    
       Unknown                 2002-01-04 21:15:54                                  WinMgmt                         
                     2002-01-04 21:15:55                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-04 21:29:42                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-04 21:29:43                                  EventSystem                     
       Unknown                 2002-01-04 21:29:49                                  WinMgmt                         
                       2002-01-04 21:29:50                                  Winlogon                        4105: Windows    .  
                     2002-01-04 21:29:53                                  Software Protection Platform Service  900:      .    
                     2002-01-04 21:29:57                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-04 21:29:57                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 30 0)( 5 0xC004F009 30 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-04 21:29:57                                  WinMgmt                         
       Unknown                 2002-01-04 21:29:57                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                     2002-01-04 21:30:02                                  Winlogon                        4104:   Windows   .  
                     2002-01-04 21:30:02                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
             1          2002-01-04 21:30:13                                  ESENT                           102: Windows (1724) Windows:   (6.01.7601.0000)    (0).  
             1          2002-01-04 21:30:13                                  Windows Search Service          1003:  Windows Search .   
             3          2002-01-04 21:30:13                                  ESENT                           300: Windows (1724) Windows:     .  
             3          2002-01-04 21:30:13                                  ESENT                           301: Windows (1724) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-04 21:30:13                                  ESENT                           302: Windows (1724) Windows:    .  
                     2002-01-04 21:30:14                                  Windows Error Reporting         1001:   ,  0   : BlueScreen  :     CAB: 0     :  P1:   P2:   P3:   P4:   P5:   P6:   P7:   P8:   P9:   P10:      :  C:\Windows\Minidump\010402-21481-01.dmp  C:\Users\user\AppData\Local\Temp\WER-47580-0.sysdata.xml        :  C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_0548df08     :     : 0   : 010402-21481-01   : 2  
               3          2002-01-04 21:30:14                                  Windows Search Service          3036:     <csc://{S-1-5-21-3990141723-738477068-3967223031-1000}/> .  :  "",  "SystemIndex"  :  URL-       .       , ,         .  (HRESULT : 0x80040d0d) (0x80040d0d)   
                         2002-01-04 21:31:17                                  WinMgmt                         
                     2002-01-04 21:31:52                                  SecurityCenter                  1:     Windows .  
                     2002-01-04 21:33:56                           Microsoft-Windows-LoadPerf      1001:     WmiApRpl (WmiApRpl)  .        Last Counter  Last Help.  
                     2002-01-04 21:33:56                           Microsoft-Windows-LoadPerf      1000: C    WmiApRpl (WmiApRpl)  .         ,   .  
                     2002-01-04 21:35:20                                  Desktop Window Manager          9009:         (0x40010004)  
                     2002-01-04 21:35:20                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-04 21:35:21                           Microsoft-Windows-User Profiles Service  1532:    .        
                     2002-01-04 21:37:41                                  EventSystem                     
                     2002-01-04 21:37:41                           Microsoft-Windows-User Profiles Service  1531:     .        
       Unknown                 2002-01-04 21:37:42                                  WinMgmt                         
                       2002-01-04 21:37:42                                  Winlogon                        4105: Windows    .  
                     2002-01-04 21:37:43                                  Software Protection Platform Service  900:      .    
                     2002-01-04 21:37:43                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-04 21:37:43                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 30 0)( 5 0xC004F009 30 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-04 21:37:43                                  WinMgmt                         
       Unknown                 2002-01-04 21:37:43                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                     2002-01-04 21:37:50                                  Winlogon                        4104:   Windows   .  
                     2002-01-04 21:37:50                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
             1          2002-01-04 21:37:57                                  ESENT                           102: Windows (1736) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-04 21:37:57                                  ESENT                           300: Windows (1736) Windows:     .  
             3          2002-01-04 21:37:57                                  ESENT                           301: Windows (1736) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-04 21:37:57                                  ESENT                           302: Windows (1736) Windows:    .  
             1          2002-01-04 21:37:58                                  Windows Search Service          1003:  Windows Search .   
                     2002-01-04 21:39:17                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 1 [(0 )(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 30 0)( 5 0xC004F009 30 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F009)])] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
                         2002-01-04 21:39:26                                  WinMgmt                         
                     2002-01-04 21:39:34                                  Software Protection Platform Service  1004:       .   =Windows(R) 7 UL-OEM License (Public)   =9b3ea632-503c-40fb-8fa1-bf71e2c952a2  
                     2002-01-04 21:39:34                                  Software Protection Platform Service  1004:       .   =Windows(R) 7 UL-OEM License (Private)   =5f4702d6-eeaa-4b81-8a57-4f2cdac5f801  
                     2002-01-04 21:39:44                                  SecurityCenter                  1:     Windows .  
                     2002-01-04 21:40:12                                  Software Protection Platform Service  1016:      .   ACID=7cfd4696-69a9-4af7-af36-ff3d12b6b6c8  PKeyId=9fe345b3-d1b9-9d2d-f76d-069544c771e4  
                       2002-01-04 21:40:12                                  Software Protection Platform Service  1015: HRESULT ().  hr=0xC004F022,  hr=0x80049E00  
                     2002-01-04 21:40:13                                  Software Protection Platform Service  1033:   ,       override-only.   =(IIS-W3SVC-MaxConcurrentRequests) (Microsoft.Windows.Smc-Enabled) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (nfs-admincmdtools-enabled) (nfs-adminmmc-enabled) (nfs-clientcmdtools-enabled) (nfs-clientcore-enabled) (sua-EnableSUA)    =55c92734-d682-4d71-983e-d6ec3f16059f   SKU=7cfd4696-69a9-4af7-af36-ff3d12b6b6c8  
                     2002-01-04 21:40:13                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 0 [(0 [0xC004F063, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 30 0)( 5 0xC004F009 30 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F063)])] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
                     2002-01-04 21:40:13                                  Software Protection Platform Service  1004:       .   =OEM Certificate   =eb201f5b-460a-4fd7-b903-7bcf11f2ce30  
                     2002-01-04 21:40:14                                  Software Protection Platform Service  1033:   ,       override-only.   =(IIS-W3SVC-MaxConcurrentRequests) (Microsoft.Windows.Smc-Enabled) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (nfs-admincmdtools-enabled) (nfs-adminmmc-enabled) (nfs-clientcmdtools-enabled) (nfs-clientcore-enabled) (sua-EnableSUA)    =55c92734-d682-4d71-983e-d6ec3f16059f   SKU=7cfd4696-69a9-4af7-af36-ff3d12b6b6c8  
                     2002-01-04 21:40:14                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 0 [(0 [0xC004E003, 0, 0], [( 1 0xC004F057 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)( 1 0xC004F057 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 [0x00000000, 0, 0], [( 5 0xC004F009 30 0)( 5 0xC004F009 30 0)( 1 0x00000000 0 0 msft:rm/algorithm/flags/1.0 0x00000000 0)(?)(?)( 9 0x00000000 0xC004F057)])] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
                     2002-01-04 21:40:40                                  Desktop Window Manager          9009:         (0x40010004)  
                     2002-01-04 21:40:40                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-04 21:40:42                           Microsoft-Windows-User Profiles Service  1532:    .        
                     2002-01-04 21:42:13                                  EventSystem                     
                     2002-01-04 21:42:13                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-04 21:42:14                                  Software Protection Platform Service  900:      .    
       Unknown                 2002-01-04 21:42:14                                  WinMgmt                         
       Unknown                 2002-01-04 21:42:14                                  WinMgmt                         
                       2002-01-04 21:42:14                                  Winlogon                        4105: Windows    .  
                     2002-01-04 21:42:15                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-04 21:42:16                                  Software Protection Platform Service  1033:   ,       override-only.   =(IIS-W3SVC-MaxConcurrentRequests) (Microsoft.Windows.Smc-Enabled) (Telnet-Client-EnableTelnetClient) (Telnet-Server-EnableTelnetServer) (TiffIFilterLicensing-EnableTiffIFilter) (nfs-admincmdtools-enabled) (nfs-adminmmc-enabled) (nfs-clientcmdtools-enabled) (nfs-clientcore-enabled) (sua-EnableSUA)    =55c92734-d682-4d71-983e-d6ec3f16059f   SKU=7cfd4696-69a9-4af7-af36-ff3d12b6b6c8  
                     2002-01-04 21:42:16                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 0 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
                     2002-01-04 21:42:16                                  Winlogon                        4101:  Windows .  
                     2002-01-04 21:42:16                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
       Unknown                 2002-01-04 21:42:16                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                     2002-01-04 21:42:30                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
                     2002-01-04 21:43:10                                  Desktop Window Manager          9009:         (0x40010004)  
                     2002-01-04 21:43:10                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-04 21:43:10                           Microsoft-Windows-User Profiles Service  1532:    .        
                     2002-01-04 21:48:40                                  EventSystem                     
                     2002-01-04 21:48:40                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-04 21:48:41                                  Winlogon                        4101:  Windows .  
                     2002-01-04 21:48:41                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
       Unknown                 2002-01-04 21:48:42                                  WinMgmt                         
       Unknown                 2002-01-04 21:48:47                                  WinMgmt                         
                     2002-01-04 21:48:57                                  Windows Error Reporting         1001:   ,  0   : BlueScreen  :     CAB: 0     :  P1:   P2:   P3:   P4:   P5:   P6:   P7:   P8:   P9:   P10:      :  C:\Windows\Minidump\010402-15709-01.dmp  C:\Users\user\AppData\Local\Temp\WER-22573-0.sysdata.xml        :  C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_07a482d5     :     : 0   : 010402-15709-01   : 2  
             1          2002-01-04 21:48:57                                  ESENT                           102: Windows (1364) Windows:   (6.01.7601.0000)    (0).  
             1          2002-01-04 21:48:57                                  Windows Search Service          1003:  Windows Search .   
             3          2002-01-04 21:48:57                                  ESENT                           300: Windows (1364) Windows:     .  
             3          2002-01-04 21:48:57                                  ESENT                           301: Windows (1364) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-04 21:48:57                                  ESENT                           302: Windows (1364) Windows:    .  
                     2002-01-04 21:49:01                                  Software Protection Platform Service  900:      .    
                     2002-01-04 21:49:01                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-04 21:49:01                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-04 21:49:01                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                     2002-01-04 22:06:01                                  EventSystem                     
                     2002-01-04 22:06:02                                  Winlogon                        4101:  Windows .  
                     2002-01-04 22:06:02                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-04 22:08:27                                  EventSystem                     
                     2002-01-04 22:08:27                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-04 22:08:28                                  Winlogon                        4101:  Windows .  
                     2002-01-04 22:08:28                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-04 22:08:29                                  WinMgmt                         
       Unknown                 2002-01-04 22:08:29                                  WinMgmt                         
       Unknown                 2002-01-04 22:08:39                                  WinMgmt                         
             1          2002-01-04 22:08:47                                  ESENT                           102: Windows (1796) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-04 22:08:47                                  ESENT                           300: Windows (1796) Windows:     .  
             3          2002-01-04 22:08:47                                  ESENT                           301: Windows (1796) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-04 22:08:47                                  ESENT                           302: Windows (1796) Windows:    .  
             1          2002-01-04 22:08:48                                  Windows Search Service          1003:  Windows Search .   
               3          2002-01-04 22:08:48                                  Windows Search Service          3036:     <csc://{S-1-5-21-3990141723-738477068-3967223031-1000}/> .  :  "",  "SystemIndex"  :  URL-       .       , ,         .  (HRESULT : 0x80040d0d) (0x80040d0d)   
                     2002-01-04 22:17:51                                  EventSystem                     
                     2002-01-04 22:17:51                           Microsoft-Windows-User Profiles Service  1531:     .        
       Unknown                 2002-01-04 22:17:57                                  WinMgmt                         
                     2002-01-04 22:17:58                                  Winlogon                        4101:  Windows .  
                     2002-01-04 22:17:58                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-04 22:18:01                                  WinMgmt                         
             1          2002-01-04 22:18:15                                  ESENT                           102: Windows (1808) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-04 22:18:15                                  ESENT                           300: Windows (1808) Windows:     .  
             3          2002-01-04 22:18:15                                  ESENT                           301: Windows (1808) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-04 22:18:15                                  ESENT                           302: Windows (1808) Windows:    .  
             1          2002-01-04 22:18:16                                  Windows Search Service          1003:  Windows Search .   
               3          2002-01-04 22:18:17                                  Windows Search Service          3036:     <csc://{S-1-5-21-3990141723-738477068-3967223031-1000}/> .  :  "",  "SystemIndex"  :  URL-       .       , ,         .  (HRESULT : 0x80040d0d) (0x80040d0d)   
                     2002-01-04 22:19:42                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-04 22:19:43                                  EventSystem                     
                     2002-01-04 22:19:48                                  Winlogon                        4101:  Windows .  
                     2002-01-04 22:19:48                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
       Unknown                 2002-01-04 22:19:50                                  WinMgmt                         
                     2002-01-04 22:19:52                                  WinMgmt                         
             1          2002-01-04 22:20:10                                  ESENT                           102: Windows (1772) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-04 22:20:11                                  ESENT                           300: Windows (1772) Windows:     .  
             3          2002-01-04 22:20:11                                  ESENT                           301: Windows (1772) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-04 22:20:12                                  ESENT                           302: Windows (1772) Windows:    .  
             1          2002-01-04 22:20:13                                  Windows Search Service          1003:  Windows Search .   
               3          2002-01-04 22:20:15                                  Windows Search Service          3036:     <csc://{S-1-5-21-3990141723-738477068-3967223031-1000}/> .  :  "",  "SystemIndex"  :  URL-       .       , ,         .  (HRESULT : 0x80040d0d) (0x80040d0d)   
                     2002-01-04 22:20:17                                  Windows Error Reporting         1001:   ,  0   : BlueScreen  :     CAB: 0     :  P1:   P2:   P3:   P4:   P5:   P6:   P7:   P8:   P9:   P10:      :  C:\Windows\Minidump\010402-19780-01.dmp  C:\Users\user\AppData\Local\Temp\WER-37003-0.sysdata.xml        :  C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_0100e8d7     :     : 0   : 010402-19780-01   : 2  
       Unknown                 2002-01-04 22:20:20                                  WinMgmt                         
                     2002-01-04 22:20:26                                  Software Protection Platform Service  900:      .    
                     2002-01-04 22:20:26                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-04 22:20:27                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-04 22:20:27                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                     2002-01-04 22:23:30                                  EventSystem                     
                     2002-01-04 22:23:30                           Microsoft-Windows-User Profiles Service  1531:     .        
       Unknown                 2002-01-04 22:23:36                                  WinMgmt                         
                     2002-01-04 22:23:37                                  Winlogon                        4101:  Windows .  
                     2002-01-04 22:23:38                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-04 22:23:41                                  WinMgmt                         
             1          2002-01-04 22:23:54                                  ESENT                           102: Windows (1824) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-04 22:23:54                                  ESENT                           300: Windows (1824) Windows:     .  
             3          2002-01-04 22:23:54                                  ESENT                           301: Windows (1824) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-04 22:23:55                                  ESENT                           302: Windows (1824) Windows:    .  
             1          2002-01-04 22:23:56                                  Windows Search Service          1003:  Windows Search .   
               3          2002-01-04 22:23:57                                  Windows Search Service          3036:     <csc://{S-1-5-21-3990141723-738477068-3967223031-1000}/> .  :  "",  "SystemIndex"  :  URL-       .       , ,         .  (HRESULT : 0x80040d0d) (0x80040d0d)   
                     2002-01-04 22:24:04                                  Software Protection Platform Service  900:      .    
       Unknown                 2002-01-04 22:24:04                                  WinMgmt                         
                     2002-01-04 22:24:05                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-04 22:24:05                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-04 22:24:05                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                         2002-01-04 22:25:07                                  WinMgmt                         
                     2002-01-04 22:25:40                                  SecurityCenter                  1:     Windows .  
                     2002-01-04 22:27:50                           Microsoft-Windows-LoadPerf      1001:     WmiApRpl (WmiApRpl)  .        Last Counter  Last Help.  
                     2002-01-04 22:27:50                           Microsoft-Windows-LoadPerf      1000: C    WmiApRpl (WmiApRpl)  .         ,   .  
                     2002-01-04 22:27:56                                  VSS                             8224:  VSS  - - .    
       Unknown                 2002-01-04 22:29:05                                  Software Protection Platform Service  903:     .    
                     2002-01-04 23:11:45                                  EventSystem                     
                     2002-01-04 23:11:45                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-04 23:11:50                                  Winlogon                        4101:  Windows .  
                     2002-01-04 23:11:50                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
       Unknown                 2002-01-04 23:11:51                                  WinMgmt                         
                     2002-01-04 23:11:55                                  WinMgmt                         
             1          2002-01-04 23:12:09                                  ESENT                           102: Windows (1464) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-04 23:12:09                                  ESENT                           300: Windows (1464) Windows:     .  
             3          2002-01-04 23:12:09                                  ESENT                           301: Windows (1464) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-04 23:12:10                                  ESENT                           302: Windows (1464) Windows:    .  
             1          2002-01-04 23:12:11                                  Windows Search Service          1003:  Windows Search .   
                     2002-01-04 23:13:20                                  EventSystem                     
                     2002-01-04 23:13:20                           Microsoft-Windows-User Profiles Service  1531:     .        
       Unknown                 2002-01-04 23:13:26                                  WinMgmt                         
                     2002-01-04 23:13:28                                  Winlogon                        4101:  Windows .  
                     2002-01-04 23:13:28                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-04 23:13:29                                  WinMgmt                         
                     2002-01-04 23:13:47                                  Windows Error Reporting         1001:   ,  0   : BlueScreen  :     CAB: 0     :  P1:   P2:   P3:   P4:   P5:   P6:   P7:   P8:   P9:   P10:      :  C:\Windows\Minidump\010402-20248-01.dmp  C:\Users\user\AppData\Local\Temp\WER-37736-0.sysdata.xml        :  C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_00e8ca50     :     : 0   : 010402-20248-01   : 2  
             1          2002-01-04 23:13:47                                  ESENT                           102: Windows (632) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-04 23:13:47                                  ESENT                           300: Windows (632) Windows:     .  
             3          2002-01-04 23:13:47                                  ESENT                           301: Windows (632) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-04 23:13:47                                  ESENT                           302: Windows (632) Windows:    .  
             1          2002-01-04 23:13:48                                  Windows Search Service          1003:  Windows Search .   
               3          2002-01-04 23:13:48                                  Windows Search Service          3036:     <csc://{S-1-5-21-3990141723-738477068-3967223031-1000}/> .  :  "",  "SystemIndex"  :  URL-       .       , ,         .  (HRESULT : 0x80040d0d) (0x80040d0d)   
       Unknown                 2002-01-04 23:13:50                                  WinMgmt                         
                     2002-01-04 23:13:51                                  Software Protection Platform Service  900:      .    
                     2002-01-04 23:13:51                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-04 23:13:52                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-04 23:13:52                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                         2002-01-04 23:14:55                                  WinMgmt                         
                     2002-01-04 23:15:29                                  SecurityCenter                  1:     Windows .  
                     2002-01-04 23:17:27                                  VSS                             8224:  VSS  - - .    
                     2002-01-04 23:17:33                           Microsoft-Windows-LoadPerf      1001:     WmiApRpl (WmiApRpl)  .        Last Counter  Last Help.  
                     2002-01-04 23:17:33                           Microsoft-Windows-LoadPerf      1000: C    WmiApRpl (WmiApRpl)  .         ,   .  
       Unknown                 2002-01-04 23:18:52                                  Software Protection Platform Service  903:     .    
                     2002-01-04 23:19:12                                  Software Protection Platform Service  900:      .    
                     2002-01-04 23:19:13                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-04 23:19:13                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-04 23:19:13                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                     2002-01-04 23:20:07                           Microsoft-Windows-LoadPerf      1001:     WmiApRpl (WmiApRpl)  .        Last Counter  Last Help.  
                     2002-01-04 23:20:07                           Microsoft-Windows-LoadPerf      1000: C    WmiApRpl (WmiApRpl)  .         ,   .  
                     2002-01-04 23:20:25                                  Desktop Window Manager          9009:         (0x40010004)  
                     2002-01-04 23:20:25                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                       2002-01-04 23:20:26                           Microsoft-Windows-User Profiles Service  1530:  Windows ,        .    .   ,    ,    .        -    1 user registry handles leaked from \Registry\User\S-1-5-21-3990141723-738477068-3967223031-1000_Classes: Process 1636 (\Device\HarddiskVolume1\Windows\System32\WUDFHost.exe) has opened key \REGISTRY\USER\S-1-5-21-3990141723-738477068-3967223031-1000_CLASSES   
                     2002-01-04 23:20:27                           Microsoft-Windows-User Profiles Service  1532:    .        
                     2002-01-04 23:57:58                                  EventSystem                     
                     2002-01-04 23:57:58                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-04 23:58:00                                  Winlogon                        4101:  Windows .  
                     2002-01-04 23:58:00                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
       Unknown                 2002-01-04 23:58:00                                  WinMgmt                         
       Unknown                 2002-01-04 23:58:01                                  WinMgmt                         
             1          2002-01-04 23:58:07                                  ESENT                           102: Windows (1092) Windows:   (6.01.7601.0000)    (0).  
             1          2002-01-04 23:58:07                                  Windows Search Service          1003:  Windows Search .   
             3          2002-01-04 23:58:07                                  ESENT                           300: Windows (1092) Windows:     .  
             3          2002-01-04 23:58:07                                  ESENT                           301: Windows (1092) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00004.log.  
             3          2002-01-04 23:58:07                                  ESENT                           301: Windows (1092) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-04 23:58:07                                  ESENT                           302: Windows (1092) Windows:    .  
                     2002-01-04 23:59:23                                  Desktop Window Manager          9009:         (0x40010004)  
                     2002-01-04 23:59:23                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-04 23:59:24                           Microsoft-Windows-User Profiles Service  1532:    .        
                     2002-01-05 00:00:14                                  EventSystem                     
                     2002-01-05 00:00:14                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-05 00:00:16                                  Winlogon                        4101:  Windows .  
                     2002-01-05 00:00:16                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
       Unknown                 2002-01-05 00:00:19                                  WinMgmt                         
       Unknown                 2002-01-05 00:00:22                                  WinMgmt                         
             1          2002-01-05 00:00:26                                  ESENT                           102: Windows (1660) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-05 00:00:26                                  ESENT                           300: Windows (1660) Windows:     .  
             3          2002-01-05 00:00:26                                  ESENT                           301: Windows (1660) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-05 00:00:26                                  ESENT                           302: Windows (1660) Windows:    .  
             1          2002-01-05 00:00:27                                  Windows Search Service          1003:  Windows Search .   
                         2002-01-05 00:01:56                                  WinMgmt                         
                     2002-01-05 00:02:23                                  Software Protection Platform Service  900:      .    
                     2002-01-05 00:02:24                                  SecurityCenter                  1:     Windows .  
                     2002-01-05 00:02:25                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-05 00:02:25                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-05 00:02:25                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                     2002-01-05 00:04:34                           Microsoft-Windows-LoadPerf      1001:     WmiApRpl (WmiApRpl)  .        Last Counter  Last Help.  
                     2002-01-05 00:04:36                           Microsoft-Windows-LoadPerf      1000: C    WmiApRpl (WmiApRpl)  .         ,   .  
                     2002-01-05 00:06:50                                  Desktop Window Manager          9009:         (0x40010004)  
                     2002-01-05 00:06:51                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-05 00:06:54                           Microsoft-Windows-User Profiles Service  1532:    .        
                     2002-01-05 00:07:41                                  EventSystem                     
                     2002-01-05 00:07:41                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-05 00:07:43                                  Winlogon                        4101:  Windows .  
                     2002-01-05 00:07:43                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
       Unknown                 2002-01-05 00:07:46                                  WinMgmt                         
       Unknown                 2002-01-05 00:07:49                                  WinMgmt                         
             1          2002-01-05 00:07:54                                  ESENT                           102: Windows (1844) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-05 00:07:55                                  ESENT                           300: Windows (1844) Windows:     .  
             3          2002-01-05 00:07:55                                  ESENT                           301: Windows (1844) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-05 00:07:55                                  ESENT                           302: Windows (1844) Windows:    .  
             1          2002-01-05 00:07:56                                  Windows Search Service          1003:  Windows Search .   
                         2002-01-05 00:09:22                                  WinMgmt                         
                     2002-01-05 00:09:49                                  Software Protection Platform Service  900:      .    
                     2002-01-05 00:09:51                                  SecurityCenter                  1:     Windows .  
                     2002-01-05 00:09:51                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-05 00:09:51                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-05 00:09:51                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                     2002-01-05 00:11:54                           Microsoft-Windows-LoadPerf      1001:     WmiApRpl (WmiApRpl)  .        Last Counter  Last Help.  
                     2002-01-05 00:11:56                           Microsoft-Windows-LoadPerf      1000: C    WmiApRpl (WmiApRpl)  .         ,   .  
       Unknown                 2002-01-05 00:14:52                                  Software Protection Platform Service  903:     .    
                     2002-01-05 00:14:56                                  Desktop Window Manager          9009:         (0x40010004)  
                     2002-01-05 00:14:56                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-05 00:15:00                           Microsoft-Windows-User Profiles Service  1532:    .        
                     2002-01-05 00:15:53                                  EventSystem                     
                     2002-01-05 00:15:53                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-05 00:15:54                                  Winlogon                        4101:  Windows .  
                     2002-01-05 00:15:54                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
       Unknown                 2002-01-05 00:15:57                                  WinMgmt                         
       Unknown                 2002-01-05 00:15:59                                  WinMgmt                         
             1          2002-01-05 00:16:04                                  ESENT                           102: Windows (1568) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-05 00:16:04                                  ESENT                           300: Windows (1568) Windows:     .  
             3          2002-01-05 00:16:04                                  ESENT                           301: Windows (1568) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-05 00:16:04                                  ESENT                           302: Windows (1568) Windows:    .  
             1          2002-01-05 00:16:05                                  Windows Search Service          1003:  Windows Search .   
                         2002-01-05 00:17:33                                  WinMgmt                         
                     2002-01-05 00:18:00                                  Software Protection Platform Service  900:      .    
                     2002-01-05 00:18:02                                  SecurityCenter                  1:     Windows .  
                     2002-01-05 00:18:02                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-05 00:18:02                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-05 00:18:02                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                     2002-01-05 00:20:05                           Microsoft-Windows-LoadPerf      1001:     WmiApRpl (WmiApRpl)  .        Last Counter  Last Help.  
                     2002-01-05 00:20:07                           Microsoft-Windows-LoadPerf      1000: C    WmiApRpl (WmiApRpl)  .         ,   .  
       Unknown                 2002-01-05 00:23:02                                  Software Protection Platform Service  903:     .    
                     2002-01-05 00:25:40                                  Desktop Window Manager          9009:         (0x40010004)  
                     2002-01-05 00:25:41                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-05 00:25:44                           Microsoft-Windows-User Profiles Service  1532:    .        
                     2002-01-05 01:48:25                                  EventSystem                     
                     2002-01-05 01:48:25                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-05 01:48:27                                  Winlogon                        4101:  Windows .  
                     2002-01-05 01:48:27                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
       Unknown                 2002-01-05 01:48:31                                  WinMgmt                         
       Unknown                 2002-01-05 01:48:33                                  WinMgmt                         
             1          2002-01-05 01:48:38                                  ESENT                           102: Windows (1588) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-05 01:48:38                                  ESENT                           300: Windows (1588) Windows:     .  
             3          2002-01-05 01:48:38                                  ESENT                           301: Windows (1588) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-05 01:48:39                                  ESENT                           302: Windows (1588) Windows:    .  
             1          2002-01-05 01:48:41                                  Windows Search Service          1003:  Windows Search .   
                         2002-01-05 01:50:07                                  WinMgmt                         
                     2002-01-05 01:50:34                                  Software Protection Platform Service  900:      .    
                     2002-01-05 01:50:36                                  SecurityCenter                  1:     Windows .  
                     2002-01-05 01:50:36                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-05 01:50:36                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-05 01:50:36                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                     2002-01-05 01:52:52  user                            MsiInstaller                    1040:    Windows: C:\Users\user\AppData\Roaming\Microsoft\DirectX Redist (June 2010)\install\6C22E1B\DirectX Redist 9.29.1962 (June 2010).msi.   : 2396.  
                     2002-01-05 01:53:19                           Microsoft-Windows-LoadPerf      1001:     WmiApRpl (WmiApRpl)  .        Last Counter  Last Help.  
                     2002-01-05 01:53:24                           Microsoft-Windows-LoadPerf      1000: C    WmiApRpl (WmiApRpl)  .         ,   .  
                     2002-01-05 01:54:13                                  Windows Error Reporting         1001:   ,  0   : PCA2  :     CAB: 0     :  P1: SETUP.EXE  P2: 1.3.1.3  P3: unknown  P4: ?  P5: unknown  P6: 1  P7: 200  P8:   P9:   P10:      :  C:\Users\user\AppData\Local\Temp\{678ac54c-981a-458a-b360-81543e99f933}\appcompat.txt        :  C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_SETUP.EXE_c8a338d8c1b292735ca1b6cb47fafbdbd18e9f86_cab_0da1974f     :     : 0   : 4b1b6830-016e-11d6-8607-001bfc896f8c   : 6  
                     2002-01-05 01:54:21                                  System Restore                  8194:     ( = C:\Windows\system32\msiexec.exe /V;  = Installed DirectX Redist (June 2010)).  
                     2002-01-05 01:54:27  user                            Microsoft-Windows-RestartManager  10000:   0 - 2002-01-04T23:54:27.815400000Z.  
                     2002-01-05 01:54:45  user                            Microsoft-Windows-RestartManager  10001:   0,  2002-01-04T23:54:27.815400000Z.  
                     2002-01-05 01:54:45                           MsiInstaller                    1042:    Windows: C:\Users\user\AppData\Roaming\Microsoft\DirectX Redist (June 2010)\install\6C22E1B\DirectX Redist 9.29.1962 (June 2010).msi.   : 2396.  
                     2002-01-05 01:54:47  user                            MsiInstaller                    11707: : DirectX Redist (June 2010) --   .  
                     2002-01-05 01:54:47  user                            MsiInstaller                    1033:  Windows   . : DirectX Redist (June 2010). : 9.29.1962. : 1049. : Microsoft.    : 0.  
                     2002-01-05 01:55:13                                  Desktop Window Manager          9009:         (0x40010004)  
                     2002-01-05 01:55:13                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-05 01:55:16                           Microsoft-Windows-User Profiles Service  1532:    .        
                     2002-01-05 19:34:35                                  EventSystem                     
                     2002-01-05 19:34:35                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-05 19:34:36                                  Winlogon                        4101:  Windows .  
                     2002-01-05 19:34:36                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
       Unknown                 2002-01-05 19:34:40                                  WinMgmt                         
       Unknown                 2002-01-05 19:34:42                                  WinMgmt                         
             1          2002-01-05 19:34:47                                  ESENT                           102: Windows (1768) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-05 19:34:48                                  ESENT                           300: Windows (1768) Windows:     .  
             3          2002-01-05 19:34:48                                  ESENT                           301: Windows (1768) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-05 19:34:48                                  ESENT                           302: Windows (1768) Windows:    .  
             1          2002-01-05 19:34:50                                  Windows Search Service          1003:  Windows Search .   
                         2002-01-05 19:36:15                                  WinMgmt                         
                     2002-01-05 19:36:43                                  Software Protection Platform Service  900:      .    
                     2002-01-05 19:36:45                                  SecurityCenter                  1:     Windows .  
                     2002-01-05 19:36:45                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-05 19:36:45                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-05 19:36:45                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                     2002-01-05 19:38:48                           Microsoft-Windows-LoadPerf      1001:     WmiApRpl (WmiApRpl)  .        Last Counter  Last Help.  
                     2002-01-05 19:38:50                           Microsoft-Windows-LoadPerf      1000: C    WmiApRpl (WmiApRpl)  .         ,   .  
       Unknown                 2002-01-05 19:41:45                                  Software Protection Platform Service  903:     .    
                     2002-01-05 19:51:47                                  Windows Error Reporting         1001:   ,  0   : MpTelemetry  :     CAB: 0     :  P1: 8024001f  P2: EndSearch  P3: Search  P4: 6.1.7601.17514  P5: MpSigDwn.dll  P6: 6.1.7600.16385  P7: Windows Defender  P8:   P9:   P10:      :        :  C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_8024001f_73aea48bd74c52b523f34668a59a345e9e5b5_07001083     :     : 0   : e2975e80-0204-11d6-a8fc-001bfc896f8c   : 6  
                     2002-01-05 19:51:51                                  Windows Error Reporting         1001:   ,  0   : WindowsUpdateFailure  :     CAB: 0     :  P1: 7.5.7601.17514  P2: 8024001f  P3: 00000000-0000-0000-0000-000000000000  P4: Scan  P5: 101  P6: Unmanaged  P7:   P8:   P9:   P10:      :        :       :     : 0   : e589f260-0204-11d6-a8fc-001bfc896f8c   : 0  
                     2002-01-05 19:51:52                                  Windows Error Reporting         1001:   ,  0   : WindowsUpdateFailure  :     CAB: 0     :  P1: 7.5.7601.17514  P2: 8024001f  P3: 00000000-0000-0000-0000-000000000000  P4: Scan  P5: 101  P6: Unmanaged  P7:   P8:   P9:   P10:      :        :  C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_7.5.7601.17514_78efc842cf92e79bab1c4f2fb5bd805f263a65_0674249f     :     : 0   : e589f260-0204-11d6-a8fc-001bfc896f8c   : 6  
                     2002-01-05 19:56:48                                  Windows Error Reporting         1001:   ,  0   : MpTelemetry  :     CAB: 0     :  P1: 8024001f  P2: EndSearch  P3: Search  P4: 6.1.7601.17514  P5: MpSigDwn.dll  P6: 6.1.7600.16385  P7: Windows Defender  P8:   P9:   P10:      :        :  C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_8024001f_73aea48bd74c52b523f34668a59a345e9e5b5_01fcabe8     :     : 0   : 96884f80-0205-11d6-a8fc-001bfc896f8c   : 6  
                     2002-01-05 19:56:53                                  Windows Error Reporting         1001:   ,  0   : WindowsUpdateFailure  :     CAB: 0     :  P1: 7.5.7601.17514  P2: 8024001f  P3: 00000000-0000-0000-0000-000000000000  P4: Scan  P5: 101  P6: Unmanaged  P7:   P8:   P9:   P10:      :        :       :     : 0   : 99715de0-0205-11d6-a8fc-001bfc896f8c   : 0  
                     2002-01-05 19:56:54                                  Windows Error Reporting         1001:   ,  0   : WindowsUpdateFailure  :     CAB: 0     :  P1: 7.5.7601.17514  P2: 8024001f  P3: 00000000-0000-0000-0000-000000000000  P4: Scan  P5: 101  P6: Unmanaged  P7:   P8:   P9:   P10:      :        :  C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_7.5.7601.17514_78efc842cf92e79bab1c4f2fb5bd805f263a65_07b8c042     :     : 0   : 99715de0-0205-11d6-a8fc-001bfc896f8c   : 6  
                     2002-01-05 20:04:36                                  Desktop Window Manager          9009:         (0x40010004)  
                     2002-01-05 20:04:36                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-05 20:04:40                           Microsoft-Windows-User Profiles Service  1532:    .        
                     2002-01-05 21:45:01                                  EventSystem                     
                     2002-01-05 21:45:02                           Microsoft-Windows-User Profiles Service  1531:     .        
       Unknown                 2002-01-05 21:45:06                                  WinMgmt                         
                     2002-01-05 21:45:07                                  Winlogon                        4101:  Windows .  
                     2002-01-05 21:45:08                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
       Unknown                 2002-01-05 21:45:10                                  WinMgmt                         
             1          2002-01-05 21:45:21                                  ESENT                           102: Windows (1940) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-05 21:45:21                                  ESENT                           300: Windows (1940) Windows:     .  
             3          2002-01-05 21:45:21                                  ESENT                           301: Windows (1940) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-05 21:45:21                                  ESENT                           302: Windows (1940) Windows:    .  
             1          2002-01-05 21:45:22                                  Windows Search Service          1003:  Windows Search .   
                     2002-01-05 21:47:03                                  EventSystem                     
                     2002-01-05 21:47:04                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-05 21:47:08                                  Winlogon                        4101:  Windows .  
                     2002-01-05 21:47:08                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
       Unknown                 2002-01-05 21:47:10                                  WinMgmt                         
                     2002-01-05 21:47:11                                  WinMgmt                         
             1          2002-01-05 21:47:20                                  ESENT                           102: Windows (1688) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-05 21:47:21                                  ESENT                           300: Windows (1688) Windows:     .  
             3          2002-01-05 21:47:21                                  ESENT                           301: Windows (1688) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-05 21:47:21                                  ESENT                           302: Windows (1688) Windows:    .  
             1          2002-01-05 21:47:22                                  Windows Search Service          1003:  Windows Search .   
               3          2002-01-05 21:47:24                                  Windows Search Service          3036:     <csc://{S-1-5-21-3990141723-738477068-3967223031-1000}/> .  :  "",  "SystemIndex"  :  URL-       .       , ,         .  (HRESULT : 0x80040d0d) (0x80040d0d)   
       Unknown                 2002-01-05 21:47:28                                  WinMgmt                         
                     2002-01-05 21:47:48                                  Desktop Window Manager          9009:         (0x40010004)  
                     2002-01-05 21:47:48                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-05 21:47:51                           Microsoft-Windows-User Profiles Service  1532:    .        
                     2002-01-05 21:48:53                                  EventSystem                     
                     2002-01-05 21:48:53                           Microsoft-Windows-User Profiles Service  1531:     .        
       Unknown                 2002-01-05 21:48:57                                  WinMgmt                         
                     2002-01-05 21:48:58                                  Winlogon                        4101:  Windows .  
                     2002-01-05 21:48:58                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
       Unknown                 2002-01-05 21:49:02                                  WinMgmt                         
             1          2002-01-05 21:49:08                                  ESENT                           102: Windows (1716) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-05 21:49:09                                  ESENT                           300: Windows (1716) Windows:     .  
             3          2002-01-05 21:49:09                                  ESENT                           301: Windows (1716) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-05 21:49:09                                  ESENT                           302: Windows (1716) Windows:    .  
             1          2002-01-05 21:49:10                                  Windows Search Service          1003:  Windows Search .   
                     2002-01-05 21:50:30                                  EventSystem                     
                     2002-01-05 21:50:31                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-05 21:50:35                                  Winlogon                        4101:  Windows .  
                     2002-01-05 21:50:35                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
       Unknown                 2002-01-05 21:50:37                                  WinMgmt                         
                     2002-01-05 21:50:38                                  WinMgmt                         
             1          2002-01-05 21:50:49                                  ESENT                           102: Windows (1652) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-05 21:50:49                                  ESENT                           300: Windows (1652) Windows:     .  
             3          2002-01-05 21:50:49                                  ESENT                           301: Windows (1652) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-05 21:50:49                                  ESENT                           302: Windows (1652) Windows:    .  
             1          2002-01-05 21:50:51                                  Windows Search Service          1003:  Windows Search .   
               3          2002-01-05 21:50:52                                  Windows Search Service          3036:     <csc://{S-1-5-21-3990141723-738477068-3967223031-1000}/> .  :  "",  "SystemIndex"  :  URL-       .       , ,         .  (HRESULT : 0x80040d0d) (0x80040d0d)   
       Unknown                 2002-01-05 21:50:59                                  WinMgmt                         
                         2002-01-05 21:52:08                                  WinMgmt                         
                     2002-01-05 21:52:43                                  Software Protection Platform Service  900:      .    
                     2002-01-05 21:52:48                                  SecurityCenter                  1:     Windows .  
                     2002-01-05 21:52:50                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-05 21:52:51                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-05 21:52:51                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                     2002-01-05 21:54:53                           Microsoft-Windows-LoadPerf      1001:     WmiApRpl (WmiApRpl)  .        Last Counter  Last Help.  
                     2002-01-05 21:54:57                           Microsoft-Windows-LoadPerf      1000: C    WmiApRpl (WmiApRpl)  .         ,   .  
       Unknown                 2002-01-05 21:57:51                                  Software Protection Platform Service  903:     .    
                     2002-01-05 22:07:54                                  Windows Error Reporting         1001:   ,  0   : MpTelemetry  :     CAB: 0     :  P1: 8024001f  P2: EndSearch  P3: Search  P4: 6.1.7601.17514  P5: MpSigDwn.dll  P6: 6.1.7600.16385  P7: Windows Defender  P8:   P9:   P10:      :        :  C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_8024001f_73aea48bd74c52b523f34668a59a345e9e5b5_08184402     :     : 0   : e689eb30-0217-11d6-9e1b-001bfc896f8c   : 6  
                     2002-01-05 22:07:58                                  Windows Error Reporting         1001:   ,  0   : WindowsUpdateFailure  :     CAB: 0     :  P1: 7.5.7601.17514  P2: 8024001f  P3: 00000000-0000-0000-0000-000000000000  P4: Scan  P5: 101  P6: Unmanaged  P7:   P8:   P9:   P10:      :        :       :     : 0   : e95dcbb0-0217-11d6-9e1b-001bfc896f8c   : 0  
                     2002-01-05 22:07:59                                  Windows Error Reporting         1001:   ,  0   : WindowsUpdateFailure  :     CAB: 0     :  P1: 7.5.7601.17514  P2: 8024001f  P3: 00000000-0000-0000-0000-000000000000  P4: Scan  P5: 101  P6: Unmanaged  P7:   P8:   P9:   P10:      :        :  C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_7.5.7601.17514_78efc842cf92e79bab1c4f2fb5bd805f263a65_08e4588b     :     : 0   : e95dcbb0-0217-11d6-9e1b-001bfc896f8c   : 6  
                     2002-01-05 22:12:58                                  Windows Error Reporting         1001:   ,  0   : MpTelemetry  :     CAB: 0     :  P1: 8024001f  P2: EndSearch  P3: Search  P4: 6.1.7601.17514  P5: MpSigDwn.dll  P6: 6.1.7600.16385  P7: Windows Defender  P8:   P9:   P10:      :        :  C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_8024001f_73aea48bd74c52b523f34668a59a345e9e5b5_0194e697     :     : 0   : 9b9d5b60-0218-11d6-9e1b-001bfc896f8c   : 6  
                     2002-01-05 22:13:02                                  Windows Error Reporting         1001:   ,  0   : WindowsUpdateFailure  :     CAB: 0     :  P1: 7.5.7601.17514  P2: 8024001f  P3: 00000000-0000-0000-0000-000000000000  P4: Scan  P5: 101  P6: Unmanaged  P7:   P8:   P9:   P10:      :        :       :     : 0   : 9e87aa10-0218-11d6-9e1b-001bfc896f8c   : 0  
                     2002-01-05 22:13:03                                  Windows Error Reporting         1001:   ,  0   : WindowsUpdateFailure  :     CAB: 0     :  P1: 7.5.7601.17514  P2: 8024001f  P3: 00000000-0000-0000-0000-000000000000  P4: Scan  P5: 101  P6: Unmanaged  P7:   P8:   P9:   P10:      :        :  C:\ProgramData\Microsoft\Windows\WER\ReportQueue\NonCritical_7.5.7601.17514_78efc842cf92e79bab1c4f2fb5bd805f263a65_0278fbcc     :     : 0   : 9e87aa10-0218-11d6-9e1b-001bfc896f8c   : 6  
                     2002-01-05 22:32:02                                  Desktop Window Manager          9009:         (0x40010004)  
                     2002-01-05 22:32:02                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-05 22:32:08                           Microsoft-Windows-User Profiles Service  1532:    .        
                     2002-01-06 00:50:37                                  EventSystem                     
                     2002-01-06 00:50:37                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-06 00:50:40                                  Winlogon                        4101:  Windows .  
                     2002-01-06 00:50:40                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-06 00:50:42                                  WinMgmt                         
       Unknown                 2002-01-06 00:50:42                                  WinMgmt                         
             1          2002-01-06 00:50:52                                  ESENT                           102: Windows (1792) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-06 00:50:52                                  ESENT                           300: Windows (1792) Windows:     .  
             3          2002-01-06 00:50:53                                  ESENT                           301: Windows (1792) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-06 00:50:53                                  ESENT                           302: Windows (1792) Windows:    .  
             1          2002-01-06 00:50:55                                  Windows Search Service          1003:  Windows Search .   
       Unknown                 2002-01-06 00:50:59                                  WinMgmt                         
                         2002-01-06 00:52:12                                  WinMgmt                         
                     2002-01-06 00:52:45                                  Software Protection Platform Service  900:      .    
                     2002-01-06 00:52:49                                  SecurityCenter                  1:     Windows .  
                     2002-01-06 00:52:50                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-06 00:52:51                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-06 00:52:51                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                     2002-01-06 00:53:19                                  Windows Error Reporting         1001:   ,  0   : BlueScreen  :     CAB: 0     :  P1:   P2:   P3:   P4:   P5:   P6:   P7:   P8:   P9:   P10:      :  C:\Windows\Minidump\010602-22854-01.dmp  C:\Users\user\AppData\Local\Temp\WER-32167-0.sysdata.xml        :  C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_0162db50     :     : 0   : 010602-22854-01   : 2  
                     2002-01-06 00:55:48                           Microsoft-Windows-LoadPerf      1001:     WmiApRpl (WmiApRpl)  .        Last Counter  Last Help.  
                     2002-01-06 00:55:51                           Microsoft-Windows-LoadPerf      1000: C    WmiApRpl (WmiApRpl)  .         ,   .  
                     2002-01-06 00:58:18                                  EventSystem                     
                     2002-01-06 00:58:18                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-06 00:58:21                                  Winlogon                        4101:  Windows .  
                     2002-01-06 00:58:21                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-06 00:58:23                                  WinMgmt                         
       Unknown                 2002-01-06 00:58:23                                  WinMgmt                         
             1          2002-01-06 00:58:34                                  ESENT                           102: Windows (648) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-06 00:58:35                                  ESENT                           300: Windows (648) Windows:     .  
             3          2002-01-06 00:58:35                                  ESENT                           301: Windows (648) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-06 00:58:35                                  ESENT                           302: Windows (648) Windows:    .  
             1          2002-01-06 00:58:37                                  Windows Search Service          1003:  Windows Search .   
               3          2002-01-06 00:58:39                                  Windows Search Service          3036:     <csc://{S-1-5-21-3990141723-738477068-3967223031-1000}/> .  :  "",  "SystemIndex"  :  URL-       .       , ,         .  (HRESULT : 0x80040d0d) (0x80040d0d)   
       Unknown                 2002-01-06 00:58:47                                  WinMgmt                         
                     2002-01-06 00:58:55                                  Windows Error Reporting         1001:   ,  0   : BlueScreen  :     CAB: 0     :  P1:   P2:   P3:   P4:   P5:   P6:   P7:   P8:   P9:   P10:      :  C:\Windows\Minidump\010602-16754-01.dmp  C:\Users\user\AppData\Local\Temp\WER-26566-0.sysdata.xml        :  C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_0224db50     :     : 0   : 010602-16754-01   : 2  
                     2002-01-06 01:01:12                                  EventSystem                     
                     2002-01-06 01:01:12                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-06 01:01:14                                  Winlogon                        4101:  Windows .  
                     2002-01-06 01:01:14                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
       Unknown                 2002-01-06 01:01:16                                  WinMgmt                         
                     2002-01-06 01:01:17                                  WinMgmt                         
             1          2002-01-06 01:01:26                                  ESENT                           102: Windows (2028) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-06 01:01:27                                  ESENT                           300: Windows (2028) Windows:     .  
             3          2002-01-06 01:01:27                                  ESENT                           301: Windows (2028) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-06 01:01:27                                  ESENT                           302: Windows (2028) Windows:    .  
             1          2002-01-06 01:01:29                                  Windows Search Service          1003:  Windows Search .   
               3          2002-01-06 01:01:30                                  Windows Search Service          3036:     <csc://{S-1-5-21-3990141723-738477068-3967223031-1000}/> .  :  "",  "SystemIndex"  :  URL-       .       , ,         .  (HRESULT : 0x80040d0d) (0x80040d0d)   
       Unknown                 2002-01-06 01:01:36                                  WinMgmt                         
                         2002-01-06 01:02:51                                  WinMgmt                         
                     2002-01-06 01:04:43                                  EventSystem                     
                     2002-01-06 01:04:43                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-06 01:04:45                                  Winlogon                        4101:  Windows .  
                     2002-01-06 01:04:45                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
       Unknown                 2002-01-06 01:04:47                                  WinMgmt                         
                     2002-01-06 01:04:48                                  WinMgmt                         
             1          2002-01-06 01:04:58                                  ESENT                           102: Windows (1808) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-06 01:04:58                                  ESENT                           300: Windows (1808) Windows:     .  
             3          2002-01-06 01:04:58                                  ESENT                           301: Windows (1808) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-06 01:04:58                                  ESENT                           302: Windows (1808) Windows:    .  
             1          2002-01-06 01:05:00                                  Windows Search Service          1003:  Windows Search .   
       Unknown                 2002-01-06 01:05:08                                  WinMgmt                         
                     2002-01-06 01:05:26                                  Windows Error Reporting         1001:   ,  0   : BlueScreen  :     CAB: 0     :  P1:   P2:   P3:   P4:   P5:   P6:   P7:   P8:   P9:   P10:      :  C:\Windows\Minidump\010602-17440-01.dmp  C:\Users\user\AppData\Local\Temp\WER-26520-0.sysdata.xml        :  C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_01c4f814     :     : 0   : 010602-17440-01   : 2  
                         2002-01-06 01:06:23                                  WinMgmt                         
                     2002-01-06 01:06:49                                  Software Protection Platform Service  900:      .    
                     2002-01-06 01:06:51                                  SecurityCenter                  1:     Windows .  
                     2002-01-06 01:06:51                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-06 01:06:52                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-06 01:06:52                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                     2002-01-06 01:09:12                           Microsoft-Windows-LoadPerf      1001:     WmiApRpl (WmiApRpl)  .        Last Counter  Last Help.  
                     2002-01-06 01:09:15                           Microsoft-Windows-LoadPerf      1000: C    WmiApRpl (WmiApRpl)  .         ,   .  
       Unknown                 2002-01-06 01:11:52                                  Software Protection Platform Service  903:     .    
                     2002-01-06 01:15:04                                  EventSystem                     
                     2002-01-06 01:15:04                           Microsoft-Windows-User Profiles Service  1531:     .        
       Unknown                 2002-01-06 01:15:11                                  WinMgmt                         
                     2002-01-06 01:15:13                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-06 01:15:14                                  WinMgmt                         
                     2002-01-06 01:17:28                                  EventSystem                     
                     2002-01-06 01:17:28                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-06 01:17:35                                  Winlogon                        4101:  Windows .  
                     2002-01-06 01:17:35                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
       Unknown                 2002-01-06 01:17:35                                  WinMgmt                         
       Unknown                 2002-01-06 01:17:40                                  WinMgmt                         
             1          2002-01-06 01:17:54                                  ESENT                           102: Windows (444) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-06 01:17:54                                  ESENT                           300: Windows (444) Windows:     .  
             3          2002-01-06 01:17:55                                  ESENT                           301: Windows (444) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS00005.log.  
             3          2002-01-06 01:17:55                                  ESENT                           301: Windows (444) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-06 01:17:55                                  ESENT                           302: Windows (444) Windows:    .  
             1          2002-01-06 01:17:56                                  Windows Search Service          1003:  Windows Search .   
                     2002-01-06 01:19:18                                  EventSystem                     
                     2002-01-06 01:19:18                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-06 01:19:25                                  Winlogon                        4101:  Windows .  
       Unknown                 2002-01-06 01:19:25                                  WinMgmt                         
                     2002-01-06 01:19:26                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-06 01:19:28                                  WinMgmt                         
             1          2002-01-06 01:19:47                                  ESENT                           102: Windows (912) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-06 01:19:48                                  ESENT                           300: Windows (912) Windows:     .  
             3          2002-01-06 01:19:48                                  ESENT                           301: Windows (912) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-06 01:19:48                                  ESENT                           302: Windows (912) Windows:    .  
             1          2002-01-06 01:19:49                                  Windows Search Service          1003:  Windows Search .   
               3          2002-01-06 01:19:51                                  Windows Search Service          3036:     <csc://{S-1-5-21-3990141723-738477068-3967223031-1000}/> .  :  "",  "SystemIndex"  :  URL-       .       , ,         .  (HRESULT : 0x80040d0d) (0x80040d0d)   
       Unknown                 2002-01-06 01:19:55                                  WinMgmt                         
                         2002-01-06 01:20:53                                  WinMgmt                         
                     2002-01-06 01:21:30                                  Software Protection Platform Service  900:      .    
                     2002-01-06 01:21:32                                  SecurityCenter                  1:     Windows .  
                     2002-01-06 01:21:33                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-06 01:21:33                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-06 01:21:33                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                     2002-01-06 01:25:09                                  EventSystem                     
                     2002-01-06 01:25:09                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-06 01:25:15                                  Winlogon                        4101:  Windows .  
                     2002-01-06 01:25:15                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
       Unknown                 2002-01-06 01:25:17                                  WinMgmt                         
                     2002-01-06 01:25:21                                  WinMgmt                         
             1          2002-01-06 01:25:39                                  ESENT                           102: Windows (1996) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-06 01:25:39                                  ESENT                           300: Windows (1996) Windows:     .  
                     2002-01-06 14:35:45                                  EventSystem                     
                     2002-01-06 14:35:45                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-06 14:35:50                                  Winlogon                        4101:  Windows .  
                     2002-01-06 14:35:51                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
       Unknown                 2002-01-06 14:35:53                                  WinMgmt                         
                     2002-01-06 14:35:57                                  WinMgmt                         
             1          2002-01-06 14:36:12                                  ESENT                           102: Windows (1592) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-06 14:36:12                                  ESENT                           300: Windows (1592) Windows:     .  
             3          2002-01-06 14:36:12                                  ESENT                           301: Windows (1592) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-06 14:36:12                                  ESENT                           302: Windows (1592) Windows:    .  
             1          2002-01-06 14:36:13                                  Windows Search Service          1003:  Windows Search .   
                     2002-01-06 14:36:16                                  Desktop Window Manager          9009:         (0x40010004)  
                     2002-01-06 14:36:16                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-06 14:36:20                           Microsoft-Windows-User Profiles Service  1532:    .        
                     2002-01-06 14:38:42                                  EventSystem                     
                     2002-01-06 14:38:42                           Microsoft-Windows-User Profiles Service  1531:     .        
       Unknown                 2002-01-06 14:38:49                                  WinMgmt                         
                     2002-01-06 14:38:50                                  Winlogon                        4101:  Windows .  
                     2002-01-06 14:38:50                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
       Unknown                 2002-01-06 14:38:55                                  WinMgmt                         
             1          2002-01-06 14:39:12                                  ESENT                           102: Windows (700) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-06 14:39:12                                  ESENT                           300: Windows (700) Windows:     .  
             3          2002-01-06 14:39:12                                  ESENT                           301: Windows (700) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-06 14:39:12                                  ESENT                           302: Windows (700) Windows:    .  
             1          2002-01-06 14:39:13                                  Windows Search Service          1003:  Windows Search .   
                     2002-01-06 14:40:13                                  Windows Error Reporting         1001:   ,  0   : BlueScreen  :     CAB: 0     :  P1:   P2:   P3:   P4:   P5:   P6:   P7:   P8:   P9:   P10:      :  C:\Windows\Minidump\010602-24117-01.dmp  C:\Users\user\AppData\Local\Temp\WER-42525-0.sysdata.xml        :  C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_0235d068     :     : 0   : 010602-24117-01   : 2  
                         2002-01-06 14:40:14                                  WinMgmt                         
                     2002-01-06 14:40:21                                  Desktop Window Manager          9009:         (0x40010004)  
                     2002-01-06 14:40:21                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
                     2002-01-06 14:40:22                           Microsoft-Windows-User Profiles Service  1532:    .        
                     2002-01-06 14:41:08                                  EventSystem                     
                     2002-01-06 14:41:08                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-06 14:41:10                                  Winlogon                        4101:  Windows .  
                     2002-01-06 14:41:10                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
       Unknown                 2002-01-06 14:41:12                                  WinMgmt                         
       Unknown                 2002-01-06 14:41:15                                  WinMgmt                         
             1          2002-01-06 14:41:22                                  ESENT                           102: Windows (1420) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-06 14:41:22                                  ESENT                           300: Windows (1420) Windows:     .  
             3          2002-01-06 14:41:22                                  ESENT                           301: Windows (1420) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-06 14:41:23                                  ESENT                           302: Windows (1420) Windows:    .  
             1          2002-01-06 14:41:24                                  Windows Search Service          1003:  Windows Search .   
                         2002-01-06 14:42:50                                  WinMgmt                         
                     2002-01-06 14:43:16                                  Software Protection Platform Service  900:      .    
                     2002-01-06 14:43:18                                  SecurityCenter                  1:     Windows .  
                     2002-01-06 14:43:18                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-06 14:43:18                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-06 14:43:19                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                         2002-01-06 14:46:51                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2002-01-06 14:46:51                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2002-01-06 14:46:51                           Microsoft-Windows-LoadPerf      3011:        WmiApRpl (WmiApRpl)  .    (DWORD)      .  
                     2002-01-06 14:46:54                           Microsoft-Windows-LoadPerf      1000: C    WmiApRpl (WmiApRpl)  .         ,   .  
                     2002-01-06 14:49:38                           Microsoft-Windows-User Profiles Service  1531:     .        
                     2002-01-06 14:49:39                                  EventSystem                     
                     2002-01-06 14:49:40                                  Winlogon                        4101:  Windows .  
                     2002-01-06 14:49:40                                  Wlclntfy                        6000:     -    winlogon <SessionEnv>.  
       Unknown                 2002-01-06 14:49:44                                  WinMgmt                         
                     2002-01-06 14:49:45                                  WinMgmt                         
       Unknown                 2002-01-06 14:49:53                                  WinMgmt                         
             1          2002-01-06 14:49:56                                  ESENT                           102: Windows (996) Windows:   (6.01.7601.0000)    (0).  
             3          2002-01-06 14:49:57                                  ESENT                           300: Windows (996) Windows:     .  
             3          2002-01-06 14:49:57                                  ESENT                           301: Windows (996) Windows:      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.  
             3          2002-01-06 14:49:57                                  ESENT                           302: Windows (996) Windows:    .  
             1          2002-01-06 14:49:58                                  Windows Search Service          1003:  Windows Search .   
                     2002-01-06 14:50:07                                  Windows Error Reporting         1001:   ,  0   : BlueScreen  :     CAB: 0     :  P1:   P2:   P3:   P4:   P5:   P6:   P7:   P8:   P9:   P10:      :  C:\Windows\Minidump\010602-17222-01.dmp  C:\Users\user\AppData\Local\Temp\WER-28797-0.sysdata.xml        :  C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Kernel_0_0_cab_04c4ba39     :     : 0   : 010602-17222-01   : 2  
                         2002-01-06 14:51:19                                  WinMgmt                         
                     2002-01-06 14:51:46                                  Software Protection Platform Service  900:      .    
                     2002-01-06 14:51:48                                  SecurityCenter                  1:     Windows .  
                     2002-01-06 14:51:49                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-06 14:51:49                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-06 14:51:49                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
                         2002-01-06 14:53:51                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2002-01-06 14:53:51                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2002-01-06 14:53:51                           Microsoft-Windows-LoadPerf      3011:        WmiApRpl (WmiApRpl)  .    (DWORD)      .  
                     2002-01-06 14:53:54                           Microsoft-Windows-LoadPerf      1000: C    WmiApRpl (WmiApRpl)  .         ,   .  
       Unknown                 2002-01-06 14:56:49                                  Software Protection Platform Service  903:     .    
                     2002-01-06 14:58:24                                  Software Protection Platform Service  900:      .    
                     2002-01-06 14:58:24                                  Software Protection Platform Service  1066:    .  C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000 C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000   
                     2002-01-06 14:58:24                                  Software Protection Platform Service  1003:        .   =55c92734-d682-4d71-983e-d6ec3f16059f   = 1: 022a1afb-b893-4190-92c3-8f69a49839fb, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 2: 436cef53-8387-4692-bb4a-9492cd82260e, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 3: 57a232fe-0931-48fe-9389-e4586967c661, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 4: 7cfd4696-69a9-4af7-af36-ff3d12b6b6c8, 1, 1 [(0 [0x00000000, 1, 0], [(?)(?)( 1 0x00000000 0 0 msft:rm/algorithm/bios/4.0 0x00000000 0)(?)(?)(?)])(1 )(2 )] 5: 8ec16e01-e86f-415f-b333-1819f4145294, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 6: a0cde89c-3304-4157-b61c-c8ad785d1fad, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 7: ac96e1a8-6cc4-4310-a4ff-332ce77fb5b8, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 8: b2c4b9f6-3ee6-4a2a-a361-64ad3b61ded5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 9: bba42084-cacd-4ad4-b606-9f3d6c93b2c5, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 10: c619d61c-c2f2-40c3-ab3f-c5924314b0f3, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 11: cfb3e52c-d707-4861-af51-11b27ee6169c, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 12: 4a8149bb-7d61-49f4-8822-82c7bf88d64b, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )] 13: afd5f68f-b70f-4000-a21d-28dbc8be8b07, 1, 0 [(0 [0xC004F014, 0, 0], [(?)(?)(?)(?)(?)(?)])(1 )(2 )]    
       Unknown                 2002-01-06 14:58:24                                  Software Protection Platform Service  902:     .  6.1.7601.17514  
      Audit Success   12288      2002-01-02 01:27:50                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-02 01:27:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:27:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x198    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 01:27:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-02 01:27:50                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x783d  
      Audit Success   12544      2002-01-02 01:27:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x198    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:27:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x198    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:27:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x198    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:27:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x198    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 01:27:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-02 01:27:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-02 01:27:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-02 01:27:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-02 01:27:56                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1d0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-02 01:27:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x10d02   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d0    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:27:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x10d33   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d0    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 01:27:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x10d02    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-02 01:27:57                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2002-01-02 01:27:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x198    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 01:27:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-02 01:27:58                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-02 01:27:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x172b0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:28:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x198    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 01:28:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-02 01:30:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x198    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 01:30:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2002-01-02 01:30:14                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x10d33      ,   .  ,  ,  .        .  
      Audit Success   103        2002-01-02 01:30:16                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2002-01-02 01:30:51                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-02 01:30:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:30:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:30:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 01:30:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-02 01:30:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-02 01:30:51                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7af5  
      Audit Success   12544      2002-01-02 01:30:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:30:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:30:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:30:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 01:30:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-02 01:30:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-02 01:30:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-02 01:30:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-02 01:30:53                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2002-01-02 01:30:53                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-02 01:30:53                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x214    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-02 01:30:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13973   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x214    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:30:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x139e3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x214    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 01:30:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13973    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-02 01:30:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x17df2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:31:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 01:31:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2002-01-02 01:32:06                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x139e3      ,   .  ,  ,  .        .  
      Audit Success   103        2002-01-02 01:32:07                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2002-01-02 01:32:41                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-02 01:32:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:32:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 01:32:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-02 01:32:41                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7ac6  
      Audit Success   12544      2002-01-02 01:32:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:32:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:32:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:32:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:32:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 01:32:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-02 01:32:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-02 01:32:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-02 01:32:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-02 01:32:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-02 01:32:43                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2002-01-02 01:32:43                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-02 01:32:43                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x214    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-02 01:32:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13c9b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x214    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:32:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13cfc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x214    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:32:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x17d9c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 01:32:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13c9b    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2002-01-02 01:36:44                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-02 01:36:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:36:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:36:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:36:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:36:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:36:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 01:36:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-02 01:36:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-02 01:36:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-02 01:36:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-02 01:36:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-02 01:36:44                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x8005  
      Audit Success   12544      2002-01-02 01:36:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:36:45                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x210    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-02 01:36:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x132c3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:36:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13355   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 01:36:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-02 01:36:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x132c3    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-02 01:36:46                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2002-01-02 01:36:46                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-02 01:36:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x18c95   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 01:36:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 01:36:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-02 01:38:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 01:38:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-02 01:38:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 01:38:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2002-01-02 02:01:02                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-02 02:01:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 02:01:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ac    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 02:01:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ac    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 02:01:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ac    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 02:01:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ac    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 02:01:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-02 02:01:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-02 02:01:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-02 02:01:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-02 02:01:02                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7a40  
      Audit Success   12544      2002-01-02 02:01:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ac    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 02:01:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ac    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 02:01:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-02 02:01:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-02 02:01:04                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2002-01-02 02:01:04                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x210    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-02 02:01:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13cb0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 02:01:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13d28   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 02:01:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13cb0    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-02 02:01:06                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-02 02:01:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x17b09   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-02 02:01:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ac    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 02:01:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-02 02:01:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ac    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 02:01:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-02 02:03:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ac    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-02 02:03:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2002-01-04 20:54:51                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-04 20:54:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 20:54:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 20:54:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 20:54:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 20:54:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 20:54:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 20:54:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 20:54:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 20:54:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 20:54:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 20:54:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-04 20:54:52                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x757e  
      Audit Success   12292      2002-01-04 20:54:53                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2002-01-04 20:54:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 20:54:53                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x210    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-04 20:54:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x1398e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 20:54:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x139d4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 20:54:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 20:54:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x1398e    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 20:54:54                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-04 20:54:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x19677   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2002-01-04 20:55:11                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x139d4      ,   .  ,  ,  .        .  
      Audit Success   103        2002-01-04 20:55:12                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2002-01-04 20:56:06                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-04 20:56:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 20:56:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 20:56:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 20:56:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 20:56:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 20:56:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 20:56:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 20:56:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 20:56:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-04 20:56:06                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x70f2  
      Audit Success   12544      2002-01-04 20:56:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 20:56:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 20:56:08                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2002-01-04 20:56:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 20:56:08                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x214    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-04 20:56:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x1380e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x214    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 20:56:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x1386c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x214    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 20:56:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 20:56:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x1380e    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 20:56:09                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-04 20:56:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x175d1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2002-01-04 20:56:23                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x1386c      ,   .  ,  ,  .        .  
      Audit Success   103        2002-01-04 20:56:24                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2002-01-04 21:11:03                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-04 21:11:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:11:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:11:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:11:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:11:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:11:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:11:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:11:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:11:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:11:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:11:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-04 21:11:03                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x76c4  
      Audit Success   12292      2002-01-04 21:11:05                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2002-01-04 21:11:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:11:05                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x214    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-04 21:11:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13743   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x214    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:11:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x1379a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x214    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:11:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:11:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13743    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 21:11:06                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-04 21:11:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x17801   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2002-01-04 21:11:19                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x1379a      ,   .  ,  ,  .        .  
      Audit Success   103        2002-01-04 21:11:20                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2002-01-04 21:12:01                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-04 21:12:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2002-01-04 21:12:01                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7834  
      Audit Success   12544      2002-01-04 21:12:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:12:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:12:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:12:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:12:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:12:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:12:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:12:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:12:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:12:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 21:12:03                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2002-01-04 21:12:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:12:03                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x214    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-04 21:12:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13174   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x214    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:12:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x131b4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x214    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:12:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:12:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13174    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 21:12:04                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-04 21:12:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x17dc0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:12:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:12:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2002-01-04 21:12:19                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x131b4      ,   .  ,  ,  .        .  
      Audit Success   103        2002-01-04 21:12:20                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2002-01-04 21:15:35                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-04 21:15:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:15:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:15:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:15:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:15:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-04 21:15:36                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x78ae  
      Audit Success   12544      2002-01-04 21:15:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:15:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:15:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:15:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:15:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:15:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 21:15:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:15:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 21:15:43                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2002-01-04 21:15:43                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1ac    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-04 21:15:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x14413   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ac    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:15:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x1445f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ac    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:15:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x14413    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 21:15:45                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-04 21:15:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1804b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2002-01-04 21:16:17                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x1445f      ,   .  ,  ,  .        .  
      Audit Success   103        2002-01-04 21:16:19                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2002-01-04 21:17:22                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   101        2002-01-04 21:17:25                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12288      2002-01-04 21:29:37                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-04 21:29:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:29:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:29:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-04 21:29:38                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7987  
      Audit Success   12544      2002-01-04 21:29:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:29:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 21:29:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:29:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 21:29:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:29:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:29:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:29:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2002-01-04 21:29:42                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2002-01-04 21:29:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:29:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 21:29:46                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2002-01-04 21:29:46                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1ac    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-04 21:29:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x143af   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ac    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:29:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x143f2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ac    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:29:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x143af    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 21:29:48                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-04 21:29:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x17ba8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:30:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:30:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 21:31:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:31:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2002-01-04 21:35:20                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x143f2      ,   .  ,  ,  .        .  
      Audit Success   103        2002-01-04 21:35:21                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2002-01-04 21:37:40                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-04 21:37:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:37:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:37:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:37:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:37:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:37:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:37:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-04 21:37:40                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x74d4  
      Audit Success   12544      2002-01-04 21:37:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:37:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:37:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:37:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:37:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:37:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 21:37:42                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2002-01-04 21:37:42                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x210    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-04 21:37:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13c9d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:37:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13d82   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:37:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x17860   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:37:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13c9d    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 21:37:43                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-04 21:37:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:37:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 21:39:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:39:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2002-01-04 21:40:40                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13d82      ,   .  ,  ,  .        .  
      Audit Success   12544      2002-01-04 21:40:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:40:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2002-01-04 21:40:42                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2002-01-04 21:42:10                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-04 21:42:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2002-01-04 21:42:10                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x6b3d  
      Audit Success   12544      2002-01-04 21:42:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:42:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 21:42:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:42:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:42:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:42:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:42:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:42:13                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-04 21:42:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13099   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:42:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x130e1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:42:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:42:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:42:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:42:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:42:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:42:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13099    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 21:42:14                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2002-01-04 21:42:14                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-04 21:42:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x18e2f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   103        2002-01-04 21:43:10                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12545      2002-01-04 21:43:10                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x130e1      ,   .  ,  ,  .        .  
      Audit Success   12288      2002-01-04 21:43:57                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-04 21:43:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:43:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:43:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:43:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:43:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:43:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:43:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:43:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:43:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:43:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:43:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-04 21:43:57                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x74c9  
      Audit Success   12544      2002-01-04 21:43:58                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x210    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12288      2002-01-04 21:44:53                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12288      2002-01-04 21:48:39                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-04 21:48:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:48:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:48:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-04 21:48:39                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x74b7  
      Audit Success   101        2002-01-04 21:48:40                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2002-01-04 21:48:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:48:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:48:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:48:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:48:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:48:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:48:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:48:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 21:48:41                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2002-01-04 21:48:41                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x218    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-04 21:48:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12ceb   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x218    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:48:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12d56   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x218    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:48:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:48:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12ceb    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 21:48:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 21:48:42                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-04 21:48:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x17cb6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 21:48:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:48:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 21:48:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 21:48:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2002-01-04 22:08:26                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-04 22:08:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 22:08:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 22:08:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:08:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 22:08:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-04 22:08:26                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x734a  
      Audit Success   101        2002-01-04 22:08:27                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2002-01-04 22:08:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 22:08:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 22:08:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:08:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 22:08:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 22:08:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 22:08:28                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2002-01-04 22:08:28                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x214    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-04 22:08:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12bda   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x214    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 22:08:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12c0b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x214    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 22:08:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:08:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12bda    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 22:08:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 22:08:29                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-04 22:08:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x17d72   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 22:08:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:08:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 22:08:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:08:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2002-01-04 22:17:46                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-04 22:17:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 22:17:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:17:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-04 22:17:47                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x77b5  
      Audit Success   12544      2002-01-04 22:17:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 22:17:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:17:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 22:17:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 22:17:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 22:17:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:17:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 22:17:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2002-01-04 22:17:50                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2002-01-04 22:17:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:17:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 22:17:54                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2002-01-04 22:17:55                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-04 22:17:55                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1ac    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-04 22:17:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x14620   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ac    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 22:17:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x14651   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ac    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:17:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x14620    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 22:17:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x18196   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 22:18:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:18:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2002-01-04 22:19:36                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-04 22:19:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2002-01-04 22:19:37                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x795e  
      Audit Success   12544      2002-01-04 22:19:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 22:19:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:19:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 22:19:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 22:19:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:19:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 22:19:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 22:19:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:19:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 22:19:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2002-01-04 22:19:41                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2002-01-04 22:19:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:19:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 22:19:46                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2002-01-04 22:19:46                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1b0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-04 22:19:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x144a5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 22:19:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x144d6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:19:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x144a5    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 22:19:47                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-04 22:19:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x18b1e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 22:20:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:20:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2002-01-04 22:23:25                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-04 22:23:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 22:23:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:23:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-04 22:23:26                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x790a  
      Audit Success   12544      2002-01-04 22:23:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 22:23:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:23:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 22:23:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 22:23:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 22:23:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:23:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 22:23:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2002-01-04 22:23:29                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2002-01-04 22:23:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:23:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 22:23:33                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2002-01-04 22:23:33                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1ac    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-04 22:23:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x14257   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ac    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 22:23:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x14288   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ac    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:23:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x14257    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 22:23:36                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-04 22:23:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x17f27   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 22:23:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:23:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 22:24:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 22:24:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:24:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 22:24:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 22:25:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 22:25:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2002-01-04 23:11:38                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-04 23:11:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2002-01-04 23:11:39                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7ab2  
      Audit Success   12544      2002-01-04 23:11:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 23:11:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 23:11:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 23:11:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 23:11:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 23:11:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 23:11:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 23:11:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 23:11:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 23:11:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2002-01-04 23:11:43                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2002-01-04 23:11:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 23:11:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 23:11:48                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2002-01-04 23:11:48                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1ac    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-04 23:11:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x146e9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ac    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 23:11:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x1471a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ac    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 23:11:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x146e9    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 23:11:50                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-04 23:11:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x18eab   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 23:12:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 23:12:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2002-01-04 23:13:14                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-04 23:13:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 23:13:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 23:13:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-04 23:13:15                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7a8d  
      Audit Success   12544      2002-01-04 23:13:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 23:13:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 23:13:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 23:13:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 23:13:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 23:13:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 23:13:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 23:13:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2002-01-04 23:13:19                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2002-01-04 23:13:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 23:13:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 23:13:23                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2002-01-04 23:13:24                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1ac    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-04 23:13:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x149d0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ac    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 23:13:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x14a41   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ac    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 23:13:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x149d0    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 23:13:26                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-04 23:13:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x17258   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 23:13:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 23:13:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 23:14:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 23:14:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 23:14:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 23:14:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 23:15:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 23:15:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2002-01-04 23:20:25                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x14a41      ,   .  ,  ,  .        .  
      Audit Success   12544      2002-01-04 23:20:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 23:20:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2002-01-04 23:20:27                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2002-01-04 23:57:57                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-04 23:57:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2002-01-04 23:57:57                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x74c2  
      Audit Success   12544      2002-01-04 23:57:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 23:57:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 23:57:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 23:57:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 23:57:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 23:57:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 23:57:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 23:57:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 23:57:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-04 23:57:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 23:57:59                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x210    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-04 23:57:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12db7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 23:57:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12de8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x210    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 23:57:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12db7    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-04 23:58:00                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2002-01-04 23:58:00                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-04 23:58:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 23:58:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-04 23:58:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x19a2f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-04 23:58:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-04 23:58:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2002-01-04 23:59:23                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12de8      ,   .  ,  ,  .        .  
      Audit Success   103        2002-01-04 23:59:24                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2002-01-05 00:00:11                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-05 00:00:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 00:00:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 00:00:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 00:00:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 00:00:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 00:00:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 00:00:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-05 00:00:12                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x793c  
      Audit Success   12544      2002-01-05 00:00:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 00:00:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 00:00:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 00:00:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 00:00:15                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x22c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-05 00:00:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12e81   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x22c    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 00:00:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12eec   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x22c    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 00:00:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12e81    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 00:00:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 00:00:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-05 00:00:17                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2002-01-05 00:00:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1b3b2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12292      2002-01-05 00:00:21                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-05 00:00:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 00:00:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 00:02:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 00:02:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2002-01-05 00:06:51                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12eec      ,   .  ,  ,  .        .  
      Audit Success   12544      2002-01-05 00:06:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 00:06:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2002-01-05 00:06:54                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2002-01-05 00:07:38                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-05 00:07:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 00:07:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 00:07:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 00:07:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 00:07:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 00:07:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 00:07:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-05 00:07:39                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x754e  
      Audit Success   12544      2002-01-05 00:07:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 00:07:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 00:07:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 00:07:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 00:07:42                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x21c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-05 00:07:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12efc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x21c    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 00:07:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12f34   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x21c    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 00:07:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 00:07:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12efc    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 00:07:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-05 00:07:44                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2002-01-05 00:07:45                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-05 00:07:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1ad0b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 00:07:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 00:07:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 00:09:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 00:09:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2002-01-05 00:14:56                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12f34      ,   .  ,  ,  .        .  
      Audit Success   12544      2002-01-05 00:14:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1e0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 00:14:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2002-01-05 00:15:00                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2002-01-05 00:15:50                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-05 00:15:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 00:15:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 00:15:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-05 00:15:50                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7934  
      Audit Success   12544      2002-01-05 00:15:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 00:15:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 00:15:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 00:15:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 00:15:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 00:15:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 00:15:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 00:15:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 00:15:53                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x234    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-05 00:15:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12d30   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x234    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 00:15:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12d72   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x234    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 00:15:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12d30    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 00:15:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 00:15:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-05 00:15:55                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2002-01-05 00:15:57                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-05 00:15:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1be81   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 00:16:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 00:16:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 00:18:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 00:18:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2002-01-05 00:25:40                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12d72      ,   .  ,  ,  .        .  
      Audit Success   12544      2002-01-05 00:25:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 00:25:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2002-01-05 00:25:44                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2002-01-05 01:48:22                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-05 01:48:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 01:48:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 01:48:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 01:48:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 01:48:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 01:48:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 01:48:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-05 01:48:23                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x786c  
      Audit Success   12544      2002-01-05 01:48:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 01:48:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 01:48:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 01:48:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 01:48:26                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-05 01:48:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12dac   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 01:48:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12ddd   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 01:48:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 01:48:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12dac    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 01:48:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-05 01:48:29                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2002-01-05 01:48:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1bcb0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12292      2002-01-05 01:48:32                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-05 01:48:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 01:48:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 01:50:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 01:50:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 01:51:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 01:51:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 01:52:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 01:52:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 01:52:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 01:52:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 01:52:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 01:52:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-05 01:54:26                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP      :  0x3e7    :    : 0x9ac    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x109429  
      Audit Success   13568      2002-01-05 01:54:26                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  USER-PC$     :  WORKGROUP      :  0x3e7    :    : 0x9ac    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x109429  
      Audit Success   12545      2002-01-05 01:55:13                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x12ddd      ,   .  ,  ,  .        .  
      Audit Success   12544      2002-01-05 01:55:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1dc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 01:55:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2002-01-05 01:55:16                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2002-01-05 19:34:30                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-05 19:34:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2002-01-05 19:34:30                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x6ed0  
      Audit Success   12544      2002-01-05 19:34:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 19:34:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 19:34:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 19:34:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 19:34:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 19:34:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 19:34:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 19:34:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 19:34:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 19:34:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 19:34:35                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x260    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-05 19:34:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13273   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 19:34:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x132a9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 19:34:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13273    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 19:34:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 19:34:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-05 19:34:38                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2002-01-05 19:34:40                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-05 19:34:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1bc06   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 19:34:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 19:34:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 19:36:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 19:36:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 19:56:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 19:56:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2002-01-05 20:04:36                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x132a9      ,   .  ,  ,  .        .  
      Audit Success   12544      2002-01-05 20:04:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 20:04:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2002-01-05 20:04:40                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2002-01-05 21:44:58                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-05 21:44:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:44:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 21:44:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-05 21:44:58                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7958  
      Audit Success   12544      2002-01-05 21:44:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:44:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 21:44:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 21:44:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 21:45:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:45:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 21:45:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 21:45:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 21:45:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:45:03                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-05 21:45:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13383   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:45:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x133c1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 21:45:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 21:45:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13383    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-05 21:45:04                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2002-01-05 21:45:05                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-05 21:45:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1648d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:45:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 21:45:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2002-01-05 21:46:59                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-05 21:46:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2002-01-05 21:46:59                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7b3b  
      Audit Success   12544      2002-01-05 21:47:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:47:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:47:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 21:47:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 21:47:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 21:47:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 21:47:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:47:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 21:47:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 21:47:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2002-01-05 21:47:02                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2002-01-05 21:47:05                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-05 21:47:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x135ba   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:47:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x135eb   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 21:47:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x135ba    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 21:47:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 21:47:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-05 21:47:08                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2002-01-05 21:47:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1935e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12292      2002-01-05 21:47:11                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-05 21:47:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 21:47:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2002-01-05 21:47:48                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x135eb      ,   .  ,  ,  .        .  
      Audit Success   103        2002-01-05 21:47:51                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2002-01-05 21:48:49                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-05 21:48:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:48:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:48:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:48:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 21:48:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 21:48:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 21:48:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-05 21:48:50                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7abe  
      Audit Success   12544      2002-01-05 21:48:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:48:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 21:48:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 21:48:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 21:48:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:48:54                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-05 21:48:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x132f0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:48:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x1332a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 21:48:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 21:48:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x132f0    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-05 21:48:55                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2002-01-05 21:48:57                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-05 21:48:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1647d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:49:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 21:49:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2002-01-05 21:50:26                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-05 21:50:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2002-01-05 21:50:26                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7a4a  
      Audit Success   12544      2002-01-05 21:50:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:50:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:50:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 21:50:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 21:50:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 21:50:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 21:50:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:50:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 21:50:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 21:50:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2002-01-05 21:50:29                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2002-01-05 21:50:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:50:34                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-05 21:50:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x137aa   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:50:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x137db   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 21:50:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-05 21:50:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x137aa    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-05 21:50:35                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2002-01-05 21:50:37                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-05 21:50:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x18abb   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-05 21:50:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 21:50:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-05 21:52:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 21:52:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2002-01-05 22:32:02                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x137db      ,   .  ,  ,  .        .  
      Audit Success   12544      2002-01-05 22:32:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-05 22:32:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2002-01-05 22:32:08                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2002-01-06 00:50:34                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-06 00:50:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 00:50:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 00:50:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-06 00:50:34                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7bb2  
      Audit Success   12544      2002-01-06 00:50:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 00:50:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 00:50:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 00:50:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 00:50:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 00:50:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2002-01-06 00:50:36                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2002-01-06 00:50:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 00:50:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-06 00:50:39                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x24c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-06 00:50:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x138d6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 00:50:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13926   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 00:50:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 00:50:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x138d6    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 00:50:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-06 00:50:41                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2002-01-06 00:50:42                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-06 00:50:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x19720   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 00:50:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 00:50:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-06 00:52:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 00:52:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-06 00:53:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x208    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 00:53:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2002-01-06 00:58:15                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-06 00:58:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 00:58:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 00:58:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-06 00:58:15                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x794d  
      Audit Success   12544      2002-01-06 00:58:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 00:58:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 00:58:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 00:58:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 00:58:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 00:58:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 00:58:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 00:58:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2002-01-06 00:58:17                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2002-01-06 00:58:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 00:58:19                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x248    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-06 00:58:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13ae4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x248    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 00:58:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13b23   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x248    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 00:58:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 00:58:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13ae4    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-06 00:58:21                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2002-01-06 00:58:23                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-06 00:58:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x19169   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 00:58:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 00:58:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2002-01-06 01:01:09                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-06 01:01:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:01:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:01:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-06 01:01:09                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x78d3  
      Audit Success   12544      2002-01-06 01:01:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:01:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:01:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:01:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:01:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 01:01:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 01:01:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 01:01:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2002-01-06 01:01:11                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2002-01-06 01:01:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:01:13                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x244    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-06 01:01:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13a83   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:01:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13ab8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x244    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:01:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 01:01:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13a83    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-06 01:01:14                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2002-01-06 01:01:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x19242   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12292      2002-01-06 01:01:17                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-06 01:01:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:01:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2002-01-06 01:04:39                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-06 01:04:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:04:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1fc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:04:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1fc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:04:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 01:04:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-06 01:04:40                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7901  
      Audit Success   12544      2002-01-06 01:04:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1fc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:04:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1fc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:04:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1fc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:04:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 01:04:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 01:04:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2002-01-06 01:04:42                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2002-01-06 01:04:43                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x240    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-06 01:04:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x1337c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:04:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x133bd   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x240    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:04:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x1337c    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-06 01:04:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1fc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:04:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-06 01:04:45                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2002-01-06 01:04:47                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-06 01:04:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x18f97   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:04:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1fc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:04:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-06 01:06:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1fc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:06:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2002-01-06 01:14:58                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-06 01:14:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:15:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x224    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:15:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-06 01:15:00                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7a93  
      Audit Success   12544      2002-01-06 01:15:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x224    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:15:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x224    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:15:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x224    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:15:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x224    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:15:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 01:15:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 01:15:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 01:15:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2002-01-06 01:15:03                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2002-01-06 01:15:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x224    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:15:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-06 01:15:07                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2002-01-06 01:15:07                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1fc    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-06 01:15:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x14097   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1fc    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:15:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x140d2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1fc    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:15:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x14097    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-06 01:15:10                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12545      2002-01-06 01:15:12                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x140d2      ,   .  ,  ,  .        .  
      Audit Success   12544      2002-01-06 01:15:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x17c86   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   103        2002-01-06 01:15:16                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2002-01-06 01:17:23                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-06 01:17:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:17:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:17:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-06 01:17:24                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7961  
      Audit Success   12544      2002-01-06 01:17:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:17:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:17:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 01:17:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-06 01:17:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:17:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:17:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 01:17:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2002-01-06 01:17:27                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2002-01-06 01:17:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:17:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-06 01:17:31                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x200    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-06 01:17:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13734   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:17:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13766   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:17:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13734    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-06 01:17:32                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2002-01-06 01:17:34                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-06 01:17:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x185ae   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:17:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:17:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2002-01-06 01:19:13                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-06 01:19:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:19:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:19:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-06 01:19:14                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x78c6  
      Audit Success   12544      2002-01-06 01:19:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:19:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:19:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 01:19:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-06 01:19:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:19:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:19:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 01:19:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2002-01-06 01:19:17                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2002-01-06 01:19:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:19:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-06 01:19:22                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2002-01-06 01:19:22                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x200    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-06 01:19:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x1398a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:19:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x139ce   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:19:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x1398a    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-06 01:19:25                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-06 01:19:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x17e8c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:19:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:19:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-06 01:21:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:21:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2002-01-06 01:25:04                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-06 01:25:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:25:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:25:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2002-01-06 01:25:05                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7b07  
      Audit Success   12544      2002-01-06 01:25:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:25:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:25:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 01:25:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-06 01:25:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:25:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:25:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 01:25:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2002-01-06 01:25:08                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2002-01-06 01:25:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:25:13                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x200    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-06 01:25:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x135aa   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:25:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x135ea   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:25:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 01:25:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x135aa    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-06 01:25:14                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2002-01-06 01:25:17                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-06 01:25:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x191cc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 01:25:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 01:25:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2002-01-06 14:35:39                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-06 14:35:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2002-01-06 14:35:40                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7a9f  
      Audit Success   12544      2002-01-06 14:35:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 14:35:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 14:35:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 14:35:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 14:35:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 14:35:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-06 14:35:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 14:35:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 14:35:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 14:35:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2002-01-06 14:35:43                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2002-01-06 14:35:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 14:35:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-06 14:35:48                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x200    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-06 14:35:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13a4d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 14:35:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13a83   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 14:35:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13a4d    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-06 14:35:50                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2002-01-06 14:35:53                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-06 14:35:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x19390   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 14:36:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 14:36:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2002-01-06 14:36:16                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13a83      ,   .  ,  ,  .        .  
      Audit Success   103        2002-01-06 14:36:20                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2002-01-06 14:38:36                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-06 14:38:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2002-01-06 14:38:37                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7c0b  
      Audit Success   12544      2002-01-06 14:38:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 14:38:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 14:38:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 14:38:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-06 14:38:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 14:38:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 14:38:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 14:38:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 14:38:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 14:38:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2002-01-06 14:38:40                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2002-01-06 14:38:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 14:38:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-06 14:38:46                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2002-01-06 14:38:46                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1fc    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-06 14:38:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13b53   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1fc    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 14:38:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13b84   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1fc    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 14:38:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13b53    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-06 14:38:48                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-06 14:38:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x18d83   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 14:39:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x228    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 14:39:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2002-01-06 14:40:21                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13b84      ,   .  ,  ,  .        .  
      Audit Success   103        2002-01-06 14:40:22                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2002-01-06 14:41:05                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-06 14:41:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2002-01-06 14:41:05                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7a4d  
      Audit Success   12544      2002-01-06 14:41:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 14:41:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 14:41:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 14:41:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 14:41:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 14:41:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 14:41:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 14:41:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-06 14:41:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 14:41:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-06 14:41:09                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x24c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-06 14:41:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x132df   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 14:41:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x1334d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 14:41:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 14:41:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x132df    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 14:41:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-06 14:41:11                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2002-01-06 14:41:13                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-06 14:41:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1984c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 14:41:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 14:41:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-06 14:43:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x200    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 14:43:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2002-01-06 14:49:35                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2002-01-06 14:49:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2002-01-06 14:49:35                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x7c2f  
      Audit Success   12544      2002-01-06 14:49:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1fc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 14:49:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1fc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 14:49:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1fc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 14:49:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 14:49:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 14:49:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-06 14:49:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1fc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 14:49:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1fc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 14:49:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2002-01-06 14:49:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2002-01-06 14:49:38                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2002-01-06 14:49:39                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  user     :  user-PC   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x250    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2002-01-06 14:49:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13a06   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 14:49:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13a4b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\winlogon.exe      :     : USER-PC     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 14:49:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-3990141723-738477068-3967223031-1000     :  user     :  user-PC    :  0x13a06    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-06 14:49:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1fc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 14:49:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2002-01-06 14:49:43                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2002-01-06 14:49:44                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2002-01-06 14:49:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1916f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2002-01-06 14:49:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1fc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 14:49:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2002-01-06 14:51:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  USER-PC$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1fc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2002-01-06 14:51:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
                        2002-01-02 01:27:29                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-02 01:27:43                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
                4          2002-01-02 01:27:48                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-02 01:27:48                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-02 01:27:50                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-02 01:27:50                                  Service Control Manager         7036:  ""    .  
                7010       2002-01-02 01:27:50                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-02 01:27:51                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-02 01:27:51                                  EventLog                        6005:    .  
                        2002-01-02 01:27:51                                  EventLog                        6013:    22 .  
                        2002-01-02 01:27:51                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-02 01:27:51                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-02 01:27:51                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-02 01:27:51                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-02 01:27:51                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:27:51                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                        2002-01-02 01:27:54                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-02 01:27:55                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-02 01:27:56                                  Service Control Manager         7036:  ""    .  
                        2002-01-02 01:27:56                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 01:27:56                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:27:56                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-02 01:27:56                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:27:56                                  Service Control Manager         7036:  "    "    .  
                        2002-01-02 01:27:56                                  Service Control Manager         7036:  "     "    .  
                        2002-01-02 01:27:56                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:27:57                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-02 01:27:57                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:27:57                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-02 01:27:57                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-02 01:27:57                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:27:57                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:27:57                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 01:27:57                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 01:27:57                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:27:57                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-02 01:27:57                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 01:27:57                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 01:27:57                                  Service Control Manager         7036:  "  "    .  
                1101       2002-01-02 01:27:57                           Microsoft-Windows-Winlogon      7001:           
                4          2002-01-02 01:27:57  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-02 01:27:57  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-02 01:27:58                                  Service Control Manager         7036:  "    "    .  
                        2002-01-02 01:27:58                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-02 01:27:58                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:27:58                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:27:58                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-02 01:27:59                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-02 01:28:00                                  Service Control Manager         7036:  ""    .  
                        2002-01-02 01:28:00                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:28:00                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:28:00                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:28:01                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:28:03                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:28:05                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:28:05                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:28:05                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:28:05                                  Service Control Manager         7036:  "  "    .  
                7005       2002-01-02 01:28:05                           Microsoft-Windows-UserPnp       20003:       pci      PCI\VEN_10DE&DEV_0449&SUBSYS_CB8410DE&REV_A1\3&267A616A&0&40   : 0.  
                7005       2002-01-02 01:28:06                           Microsoft-Windows-UserPnp       20001:       FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\machine.inf      PCI\VEN_10DE&DEV_0449&SUBSYS_CB8410DE&REV_A1\3&267A616A&0&40   : 0x0.  
                7005       2002-01-02 01:28:06                           Microsoft-Windows-UserPnp       20001:       FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\machine.inf      ACPI\PNP0B00\4&347393C0&0   : 0x0.  
                7005       2002-01-02 01:28:08                           Microsoft-Windows-UserPnp       20003:       atapi      PCIIDE\IDECHANNEL\4&1A587C1A&0&0   : 0.  
                        2002-01-02 01:28:11                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:28:11                                  Service Control Manager         7036:  "  "    .  
                7005       2002-01-02 01:28:11                           Microsoft-Windows-UserPnp       20001:       FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\mshdc.inf      PCIIDE\IDECHANNEL\4&1A587C1A&0&0   : 0x0.  
                7005       2002-01-02 01:28:11                           Microsoft-Windows-UserPnp       20001:       FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\machine.inf      PCI\VEN_10DE&DEV_0444&SUBSYS_82491043&REV_A1\3&267A616A&0&00   : 0x0.  
                7005       2002-01-02 01:28:12                           Microsoft-Windows-UserPnp       20003:       volsnap      STORAGE\VOLUME\{2744D380-FF0F-11D5-A8D6-806E6F6E6963}#0000000000007E00   : 0.  
                7005       2002-01-02 01:28:12                           Microsoft-Windows-UserPnp       20001:       FileRepository\volume.inf_x86_neutral_6dee0205881d1a1d\volume.inf      STORAGE\VOLUME\{2744D380-FF0F-11D5-A8D6-806E6F6E6963}#0000000000007E00   : 0x0.  
                7005       2002-01-02 01:28:13                           Microsoft-Windows-UserPnp       20003:       volsnap      STORAGE\VOLUME\{2744D380-FF0F-11D5-A8D6-806E6F6E6963}#00000004E22D6A00   : 0.  
                7005       2002-01-02 01:28:13                           Microsoft-Windows-UserPnp       20001:       FileRepository\volume.inf_x86_neutral_6dee0205881d1a1d\volume.inf      STORAGE\VOLUME\{2744D380-FF0F-11D5-A8D6-806E6F6E6963}#00000004E22D6A00   : 0x0.  
                7005       2002-01-02 01:28:14                           Microsoft-Windows-UserPnp       20003:       AmdK8      ACPI\AUTHENTICAMD_-_X86_FAMILY_15_MODEL_75_-_AMD_ATHLON(TM)_64_X2_DUAL_CORE_PROCESSOR_4200+\_2   : 0.  
                        2002-01-02 01:28:16                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:28:19                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:28:19                                  Service Control Manager         7036:  " "    .  
                7005       2002-01-02 01:28:20                           Microsoft-Windows-UserPnp       20001:       FileRepository\cpu.inf_x86_neutral_729b871528391032\cpu.inf      ACPI\AUTHENTICAMD_-_X86_FAMILY_15_MODEL_75_-_AMD_ATHLON(TM)_64_X2_DUAL_CORE_PROCESSOR_4200+\_2   : 0x0.  
                7005       2002-01-02 01:28:21                           Microsoft-Windows-UserPnp       20003:       AmdK8      ACPI\AUTHENTICAMD_-_X86_FAMILY_15_MODEL_75_-_AMD_ATHLON(TM)_64_X2_DUAL_CORE_PROCESSOR_4200+\_1   : 0.  
                7005       2002-01-02 01:28:22                           Microsoft-Windows-UserPnp       20001:       FileRepository\cpu.inf_x86_neutral_729b871528391032\cpu.inf      ACPI\AUTHENTICAMD_-_X86_FAMILY_15_MODEL_75_-_AMD_ATHLON(TM)_64_X2_DUAL_CORE_PROCESSOR_4200+\_1   : 0x0.  
                7005       2002-01-02 01:28:23                           Microsoft-Windows-UserPnp       20001:       FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\machine.inf      PCI\VEN_10DE&DEV_0445&SUBSYS_82491043&REV_A1\3&267A616A&0&0A   : 0x0.  
                7005       2002-01-02 01:28:24                           Microsoft-Windows-UserPnp       20003:       HDAudBus      PCI\VEN_10DE&DEV_044A&SUBSYS_82861043&REV_A1\3&267A616A&0&38   : 0.  
                        2002-01-02 01:28:28                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-02 01:28:29                           Service Control Manager         7045:    .     :     NVIDIA nForce    :  system32\DRIVERS\nvm62x32.sys   :        :      :    
                7005       2002-01-02 01:28:29                           Microsoft-Windows-UserPnp       20001:       FileRepository\hdaudbus.inf_x86_neutral_77479a4820fb8643\hdaudbus.inf      PCI\VEN_10DE&DEV_044A&SUBSYS_82861043&REV_A1\3&267A616A&0&38   : 0x0.  
                7005       2002-01-02 01:28:31                           Microsoft-Windows-UserPnp       20003:       NVENETFD      PCI\VEN_10DE&DEV_0450&SUBSYS_82491043&REV_A1\3&267A616A&0&30   : 0.  
                7005       2002-01-02 01:28:35                           Microsoft-Windows-UserPnp       20001:       FileRepository\netnvm32.inf_x86_neutral_163a5a97980bb89d\netnvm32.inf      PCI\VEN_10DE&DEV_0450&SUBSYS_82491043&REV_A1\3&267A616A&0&30   : 0x0.  
                7005       2002-01-02 01:28:36                           Microsoft-Windows-UserPnp       20001:       FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\machine.inf      PCI\VEN_10DE&DEV_0446&SUBSYS_82491043&REV_A1\3&267A616A&0&09   : 0x0.  
                7005       2002-01-02 01:28:37                           Microsoft-Windows-UserPnp       20003:       usbohci      PCI\VEN_10DE&DEV_0454&SUBSYS_82491043&REV_A1\3&267A616A&0&10   : 0.  
                7005       2002-01-02 01:28:38                           Microsoft-Windows-UserPnp       20001:       FileRepository\usbport.inf_x86_neutral_f9abf85fd00186bd\usbport.inf      PCI\VEN_10DE&DEV_0454&SUBSYS_82491043&REV_A1\3&267A616A&0&10   : 0x0.  
                7005       2002-01-02 01:28:39                           Microsoft-Windows-UserPnp       20003:       pciide      PCI\VEN_10DE&DEV_045D&SUBSYS_82491043&REV_A1\3&267A616A&0&50   : 0.  
                7005       2002-01-02 01:28:49                           Microsoft-Windows-UserPnp       20001:       FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\mshdc.inf      PCI\VEN_10DE&DEV_045D&SUBSYS_82491043&REV_A1\3&267A616A&0&50   : 0x0.  
                7005       2002-01-02 01:28:49                           Microsoft-Windows-UserPnp       20003:       msisadrv      PCI\VEN_10DE&DEV_0441&SUBSYS_82491043&REV_A2\3&267A616A&0&08   : 0.  
                7005       2002-01-02 01:28:49                           Microsoft-Windows-UserPnp       20001:       FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\machine.inf      PCI\VEN_10DE&DEV_0441&SUBSYS_82491043&REV_A2\3&267A616A&0&08   : 0x0.  
                7005       2002-01-02 01:28:50                           Microsoft-Windows-UserPnp       20003:       pciide      PCI\VEN_10DE&DEV_0448&SUBSYS_82491043&REV_A1\3&267A616A&0&48   : 0.  
                7005       2002-01-02 01:28:53                           Microsoft-Windows-UserPnp       20001:       FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\mshdc.inf      PCI\VEN_10DE&DEV_0448&SUBSYS_82491043&REV_A1\3&267A616A&0&48   : 0x0.  
                7005       2002-01-02 01:28:53                           Microsoft-Windows-UserPnp       20003:       usbehci      PCI\VEN_10DE&DEV_0455&SUBSYS_82491043&REV_A1\3&267A616A&0&11   : 0.  
                7005       2002-01-02 01:28:54                           Microsoft-Windows-UserPnp       20001:       FileRepository\usbport.inf_x86_neutral_f9abf85fd00186bd\usbport.inf      PCI\VEN_10DE&DEV_0455&SUBSYS_82491043&REV_A1\3&267A616A&0&11   : 0x0.  
                7005       2002-01-02 01:28:54                           Microsoft-Windows-UserPnp       20003:       usbhub      USB\ROOT_HUB\4&197F762D&0   : 0.  
                7005       2002-01-02 01:28:54                           Microsoft-Windows-UserPnp       20001:       FileRepository\usbport.inf_x86_neutral_f9abf85fd00186bd\usbport.inf      USB\ROOT_HUB\4&197F762D&0   : 0x0.  
                7005       2002-01-02 01:28:55                           Microsoft-Windows-UserPnp       20001:       FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\machine.inf      ACPI\PNP0000\4&347393C0&0   : 0x0.  
                7005       2002-01-02 01:28:55                           Microsoft-Windows-UserPnp       20003:       atapi      PCIIDE\IDECHANNEL\4&1A587C1A&0&1   : 0.  
                7005       2002-01-02 01:28:56                           Microsoft-Windows-UserPnp       20001:       FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\mshdc.inf      PCIIDE\IDECHANNEL\4&1A587C1A&0&1   : 0x0.  
                7005       2002-01-02 01:28:56                           Microsoft-Windows-UserPnp       20001:       NULL Driver      ACPI\ATK0110\1010110   : 0xe0000203.  
                7005       2002-01-02 01:28:56                           Microsoft-Windows-UserPnp       20001:       FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\machine.inf      ACPI\PNP0100\4&347393C0&0   : 0x0.  
                7005       2002-01-02 01:28:56                           Microsoft-Windows-UserPnp       20001:       FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\machine.inf      ACPI\PNP0C02\2E   : 0x0.  
                7005       2002-01-02 01:28:57                           Microsoft-Windows-UserPnp       20001:       FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\machine.inf      ACPI\PNP0103\0   : 0x0.  
                7005       2002-01-02 01:28:59                           Microsoft-Windows-UserPnp       20003:       nvlddmkm      PCI\VEN_10DE&DEV_0402&SUBSYS_00000000&REV_A1\4&13AB9918&0&0068   : 0.  
                7005       2002-01-02 01:29:00                           Microsoft-Windows-UserPnp       20001:       FileRepository\nv_lh.inf_x86_neutral_bbe628dbdd6fce25\nv_lh.inf      PCI\VEN_10DE&DEV_0402&SUBSYS_00000000&REV_A1\4&13AB9918&0&0068   : 0x0.  
                7005       2002-01-02 01:29:00                           Microsoft-Windows-UserPnp       20003:       usbhub      USB\ROOT_HUB20\4&4102DBA&0   : 0.  
                7005       2002-01-02 01:29:00                           Microsoft-Windows-UserPnp       20001:       FileRepository\usbport.inf_x86_neutral_f9abf85fd00186bd\usbport.inf      USB\ROOT_HUB20\4&4102DBA&0   : 0x0.  
                7005       2002-01-02 01:29:01                           Microsoft-Windows-UserPnp       20001:       FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\machine.inf      ACPI\PNP0C04\4&347393C0&0   : 0x0.  
                7005       2002-01-02 01:29:01                           Microsoft-Windows-UserPnp       20001:       FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\machine.inf      ACPI\PNP0200\4&347393C0&0   : 0x0.  
                7005       2002-01-02 01:29:02                           Microsoft-Windows-UserPnp       20003:       i8042prt      ACPI\PNP0303\4&347393C0&0   : 0.  
                7005       2002-01-02 01:29:02                           Microsoft-Windows-UserPnp       20003:       kbdclass      ACPI\PNP0303\4&347393C0&0   : 0.  
                7005       2002-01-02 01:29:02                           Microsoft-Windows-UserPnp       20001:       FileRepository\keyboard.inf_x86_neutral_50ad659974198591\keyboard.inf      ACPI\PNP0303\4&347393C0&0   : 0x0.  
                7005       2002-01-02 01:29:02                           Microsoft-Windows-UserPnp       20003:       Parport      ACPI\PNP0400\4&347393C0&0   : 0.  
                7005       2002-01-02 01:29:02                           Microsoft-Windows-UserPnp       20003:       Parvdm      ACPI\PNP0400\4&347393C0&0   : 0.  
                7005       2002-01-02 01:29:03                           Microsoft-Windows-UserPnp       20001:       FileRepository\msports.inf_x86_neutral_c1a802e06677f73f\msports.inf      ACPI\PNP0400\4&347393C0&0   : 0x0.  
                7005       2002-01-02 01:29:03                           Microsoft-Windows-UserPnp       20003:       fdc      ACPI\PNP0700\4&347393C0&0   : 0.  
                7005       2002-01-02 01:29:03                           Microsoft-Windows-UserPnp       20001:       FileRepository\fdc.inf_x86_neutral_67322cb863995ea8\fdc.inf      ACPI\PNP0700\4&347393C0&0   : 0x0.  
                7005       2002-01-02 01:29:05                           Microsoft-Windows-UserPnp       20003:       HdAudAddService      HDAUDIO\FUNC_01&VEN_10EC&DEV_0883&SUBSYS_10438286&REV_1000\4&36C8AB97&0&0001   : 0.  
                7005       2002-01-02 01:29:06                           Microsoft-Windows-UserPnp       20001:       FileRepository\hdaudio.inf_x86_neutral_5a5e688ecb9e273f\hdaudio.inf      HDAUDIO\FUNC_01&VEN_10EC&DEV_0883&SUBSYS_10438286&REV_1000\4&36C8AB97&0&0001   : 0x0.  
                7005       2002-01-02 01:29:07                           Microsoft-Windows-UserPnp       20003:       atapi      PCIIDE\IDECHANNEL\4&13C7D258&0&0   : 0.  
                7005       2002-01-02 01:29:17                           Microsoft-Windows-UserPnp       20001:       FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\mshdc.inf      PCIIDE\IDECHANNEL\4&13C7D258&0&0   : 0x0.  
                7005       2002-01-02 01:29:17                           Microsoft-Windows-UserPnp       20001:       FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\machine.inf      ACPI\PNP0800\4&347393C0&0   : 0x0.  
                7005       2002-01-02 01:29:18                           Microsoft-Windows-UserPnp       20003:       atapi      PCIIDE\IDECHANNEL\4&13C7D258&0&1   : 0.  
                7005       2002-01-02 01:29:18                           Microsoft-Windows-UserPnp       20001:       FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\mshdc.inf      PCIIDE\IDECHANNEL\4&13C7D258&0&1   : 0x0.  
                7005       2002-01-02 01:29:18                           Microsoft-Windows-UserPnp       20003:       flpydisk      FDC\GENERIC_FLOPPY_DRIVE\5&2523678&0&0   : 0.  
                7005       2002-01-02 01:29:19                           Microsoft-Windows-UserPnp       20001:       FileRepository\flpydisk.inf_x86_neutral_2102f5344367a352\flpydisk.inf      FDC\GENERIC_FLOPPY_DRIVE\5&2523678&0&0   : 0x0.  
                7005       2002-01-02 01:29:19                           Microsoft-Windows-UserPnp       20003:       disk      IDE\DISKST3250410AS_____________________________3.AAA___\5&2BC02221&0&0.0.0   : 0.  
                7005       2002-01-02 01:29:29                           Microsoft-Windows-UserPnp       20001:       FileRepository\disk.inf_x86_neutral_b431b61a11f8df6c\disk.inf      IDE\DISKST3250410AS_____________________________3.AAA___\5&2BC02221&0&0.0.0   : 0x0.  
                7005       2002-01-02 01:29:30                           Microsoft-Windows-UserPnp       20001:       FileRepository\machine.inf_x86_neutral_a97a2a0d0fbc6696\machine.inf      LPTENUM\MICROSOFTRAWPORT\5&12EA4FBC&0&LPT1   : 0x0.  
                7005       2002-01-02 01:29:30                           Microsoft-Windows-UserPnp       20003:       cdrom      IDE\CDROMPIONEER_DVD-RW__DVR-219L________________1.01____\5&1906717C&0&1.0.0   : 0.  
                7005       2002-01-02 01:29:31                           Microsoft-Windows-UserPnp       20001:       FileRepository\cdrom.inf_x86_neutral_6381e09675524225\cdrom.inf      IDE\CDROMPIONEER_DVD-RW__DVR-219L________________1.01____\5&1906717C&0&1.0.0   : 0x0.  
                          2002-01-02 01:29:46  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-02 01:30:00                                  Service Control Manager         7036:  "    (BITS)"    .  
                        2002-01-02 01:30:00                                  Service Control Manager         7036:  "Microsoft .NET Framework NGEN v2.0.50727_X86"    .  
                        2002-01-02 01:30:01                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-02 01:30:01                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-02 01:30:01                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:30:02                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-02 01:30:02                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:30:04                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-02 01:30:12  user                            USER32                          1074:  rundll32.exe   ""   USER-PC    user-PC\user  : :  ()     : 0x80010002     :     :   
                        2002-01-02 01:30:15  user                            USER32                          1074:  C:\Windows\system32\winlogon.exe (USER-PC)   ""   USER-PC    user-PC\user  :        : 0x500ff     :     :   
                1102       2002-01-02 01:30:15                           Microsoft-Windows-Winlogon      7002:           
                        2002-01-02 01:30:16                                  EventLog                        6006:    .  
                        2002-01-02 01:30:16                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-02 01:30:16                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:30:16                                  Service Control Manager         7036:  "Microsoft .NET Framework NGEN v2.0.50727_X86"    .  
                        2002-01-02 01:30:16                                  Service Control Manager         7036:  ""    .  
                        2002-01-02 01:30:16                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:30:16                                  Service Control Manager         7036:  "     "    .  
                        2002-01-02 01:30:16                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:30:16                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-02 01:30:16                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:30:16                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-02 01:30:16                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-02 01:30:16                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:30:16                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:30:16                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:30:16                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:30:16                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-02 01:30:16                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-02 01:30:16                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-02 01:30:16                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-02 01:30:16                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:30:16                                  Service Control Manager         7036:  " "    .  
                4          2002-01-02 01:30:16  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51047:   DHCPv6 .    : 1  
                4          2002-01-02 01:30:16  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50037:    DHCPv4.    : 1  
                        2002-01-02 01:30:17                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-02 01:30:17                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                103        2002-01-02 01:30:17                                  Microsoft-Windows-Kernel-Power  109:      .  
                7010       2002-01-02 01:30:17                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "false"      PlugPlay: "false"     
                        2002-01-02 01:30:19                                  Microsoft-Windows-Kernel-General  13:  .  
                        2002-01-02 01:30:37                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-02 01:30:40                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
                4          2002-01-02 01:30:45                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-02 01:30:45                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-02 01:30:51                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-02 01:30:51                                  Service Control Manager         7036:  ""    .  
                        2002-01-02 01:30:51                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-02 01:30:51                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-02 01:30:51                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-02 01:30:51                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-02 01:30:52                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-02 01:30:52                                  EventLog                        6005:    .  
                        2002-01-02 01:30:52                                  EventLog                        6013:    14 .  
                        2002-01-02 01:30:52                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-02 01:30:52                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-02 01:30:52                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:30:52                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-02 01:30:52                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-02 01:30:52                                  Service Control Manager         7036:  ""    .  
                        2002-01-02 01:30:52                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:30:52                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:30:52                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 01:30:52                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-02 01:30:52                                  Service Control Manager         7036:  "    "    .  
                        2002-01-02 01:30:52                                  Service Control Manager         7036:  "     "    .  
                        2002-01-02 01:30:52                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:30:52                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:30:52                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-02 01:30:52                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-02 01:30:52                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-02 01:30:52                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:30:52                                  Service Control Manager         7036:  " "    .  
                4          2002-01-02 01:30:52  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-02 01:30:52  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-02 01:30:53                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 01:30:53                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:30:53                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-02 01:30:53                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 01:30:53                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 01:30:53                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:30:53                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:30:53                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-02 01:30:53                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-02 01:30:53                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-02 01:30:53                                  Service Control Manager         7036:  "    "    .  
                1101       2002-01-02 01:30:53                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-02 01:30:54                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:30:54                                  Service Control Manager         7036:  ""    .  
                        2002-01-02 01:30:54                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:30:54                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:30:54                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:30:54                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:30:55                                  Service Control Manager         7036:  "   "    .  
                7005       2002-01-02 01:30:56                           Microsoft-Windows-UserPnp       20003:       monitor      DISPLAY\GSM4B31\5&114FA321&0&UID67109121   : 0.  
                7005       2002-01-02 01:30:57                           Microsoft-Windows-UserPnp       20001:       FileRepository\monitor.inf_x86_neutral_f7168ca1d7f8ec24\monitor.inf      DISPLAY\GSM4B31\5&114FA321&0&UID67109121   : 0x0.  
                        2002-01-02 01:30:58                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:31:11                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:31:18                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 01:31:18                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-02 01:32:04  user                            USER32                          1074:  Explorer.EXE   ""   USER-PC    user-PC\user  :  ()     : 0x0     :     :   
                        2002-01-02 01:32:06                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:32:06                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:32:06  user                            USER32                          1074:  C:\Windows\system32\winlogon.exe (USER-PC)   ""   USER-PC    user-PC\user  :        : 0x500ff     :     :   
                1102       2002-01-02 01:32:06                           Microsoft-Windows-Winlogon      7002:           
                4          2002-01-02 01:32:06  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51047:   DHCPv6 .    : 1  
                4          2002-01-02 01:32:06  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50037:    DHCPv4.    : 1  
                        2002-01-02 01:32:07                                  EventLog                        6006:    .  
                        2002-01-02 01:32:07                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-02 01:32:07                                  Service Control Manager         7036:  ""    .  
                        2002-01-02 01:32:07                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-02 01:32:07                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:32:07                                  Service Control Manager         7036:  "     "    .  
                        2002-01-02 01:32:07                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:32:07                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:32:07                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:32:07                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:32:07                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-02 01:32:07                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-02 01:32:07                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:32:07                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-02 01:32:07                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 01:32:07                                  Service Control Manager         7036:  "Windows Search"    .  
                7010       2002-01-02 01:32:07                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "false"      PlugPlay: "false"     
                103        2002-01-02 01:32:08                                  Microsoft-Windows-Kernel-Power  109:      .  
                        2002-01-02 01:32:10                                  Microsoft-Windows-Kernel-General  13:  .  
                        2002-01-02 01:32:27                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-02 01:32:30                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
                4          2002-01-02 01:32:35                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-02 01:32:35                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-02 01:32:41                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                7010       2002-01-02 01:32:41                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-02 01:32:42                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-02 01:32:42                                  EventLog                        6005:    .  
                        2002-01-02 01:32:42                                  EventLog                        6013:    14 .  
                        2002-01-02 01:32:42                                  Service Control Manager         7036:  ""    .  
                        2002-01-02 01:32:42                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-02 01:32:42                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-02 01:32:42                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-02 01:32:42                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-02 01:32:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:32:42                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-02 01:32:42                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-02 01:32:42                                  Service Control Manager         7036:  ""    .  
                        2002-01-02 01:32:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:32:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:32:42                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 01:32:42                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-02 01:32:42                                  Service Control Manager         7036:  "    "    .  
                        2002-01-02 01:32:42                                  Service Control Manager         7036:  "     "    .  
                        2002-01-02 01:32:42                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:32:42                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:32:42                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-02 01:32:42                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-02 01:32:42                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-02 01:32:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:32:42                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 01:32:42                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                4          2002-01-02 01:32:42  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-02 01:32:42  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-02 01:32:43                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 01:32:43                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:32:43                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-02 01:32:43                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 01:32:43                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 01:32:43                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:32:43                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-02 01:32:43                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-02 01:32:43                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:32:43                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-02 01:32:43                                  Service Control Manager         7036:  "    "    .  
                1101       2002-01-02 01:32:43                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-02 01:32:44                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:32:44                                  Service Control Manager         7036:  ""    .  
                        2002-01-02 01:32:44                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:32:44                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:32:44                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:32:44                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:32:44                                  Service Control Manager         7036:  "  "    .  
                          2002-01-02 01:33:32  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-02 01:36:29                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-02 01:36:32                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
          Unknown         63         2002-01-02 01:36:37                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                4          2002-01-02 01:36:38                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-02 01:36:38                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-02 01:36:44                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-02 01:36:44                                  EventLog                        6005:    .  
                        2002-01-02 01:36:44                                  EventLog                        6013:    15 .  
                        2002-01-02 01:36:44                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-02 01:36:44                                  Service Control Manager         7036:  ""    .  
                        2002-01-02 01:36:44                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-02 01:36:44                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-02 01:36:44                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-02 01:36:44                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-02 01:36:44                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:36:44                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-02 01:36:44                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-02 01:36:44                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-02 01:36:45                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-02 01:36:45                                  Service Control Manager         7036:  ""    .  
                        2002-01-02 01:36:45                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:36:45                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:36:45                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 01:36:45                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-02 01:36:45                                  Service Control Manager         7036:  "    "    .  
                        2002-01-02 01:36:45                                  Service Control Manager         7036:  "     "    .  
                        2002-01-02 01:36:45                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:36:45                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:36:45                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-02 01:36:45                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-02 01:36:45                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-02 01:36:45                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:36:45                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 01:36:45                                  Service Control Manager         7036:  " "    .  
                4          2002-01-02 01:36:45  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-02 01:36:45  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                            2002-01-02 01:36:46                                  Service Control Manager         7026:    ()    :   cdrom  
                        2002-01-02 01:36:46                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:36:46                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-02 01:36:46                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 01:36:46                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 01:36:46                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:36:46                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-02 01:36:46                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:36:46                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-02 01:36:46                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-02 01:36:46                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:36:46                                  Service Control Manager         7036:  "    "    .  
                        2002-01-02 01:36:46                                  Service Control Manager         7036:  ""    .  
                        2002-01-02 01:36:46                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:36:46                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:36:46                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:36:46                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:36:46                                  Service Control Manager         7036:  "   "    .  
                1101       2002-01-02 01:36:46                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-02 01:36:48                                  Service Control Manager         7036:  "  "    .  
                            2002-01-02 01:36:49                                  BugCheck                        
                        2002-01-02 01:36:56                                  Service Control Manager         7036:  "   Windows"    .  
                7005       2002-01-02 01:36:59                           Microsoft-Windows-UserPnp       20001:       FileRepository\usb.inf_x86_neutral_2620fd493cad7d41\usb.inf      USB\VID_0000&PID_0000\5&46718C6&0&1   : 0x0.  
                        2002-01-02 01:38:46                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 01:38:47                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:38:47                                  Service Control Manager         7036:  "    (BITS)"    .  
                        2002-01-02 01:38:47                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-02 01:38:49                                  Service Control Manager         7036:  "Microsoft .NET Framework NGEN v2.0.50727_X86"    .  
                        2002-01-02 01:38:52                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-02 01:38:53                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-02 01:38:53                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:38:55                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 01:38:56                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-02 01:38:58                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-02 01:39:00                                  Service Control Manager         7036:  "  Windows"    .  
                          2002-01-02 01:39:36  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-02 01:43:54                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 01:49:15                                  Service Control Manager         7036:  "Microsoft .NET Framework NGEN v2.0.50727_X86"    .  
                        2002-01-02 01:49:15                           Service Control Manager         7040:    "Microsoft .NET Framework NGEN v2.0.50727_X86"    ""  "".  
                        2002-01-02 01:53:54                                  Service Control Manager         7036:  "   - WinHTTP"    .  
                        2002-01-02 01:53:54                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 02:00:50                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-02 02:00:53                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
                4          2002-01-02 02:00:56                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-02 02:00:56                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
          Unknown         63         2002-01-02 02:00:56                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                            2002-01-02 02:01:02                                  EventLog                        6008:      1:59:22  ?02.?01.?2002  .  
                        2002-01-02 02:01:02                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-02 02:01:02                                  EventLog                        6005:    .  
                        2002-01-02 02:01:02                                  EventLog                        6013:    12 .  
                        2002-01-02 02:01:02                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-02 02:01:02                                  Service Control Manager         7036:  ""    .  
                        2002-01-02 02:01:02                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-02 02:01:02                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-02 02:01:02                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-02 02:01:02                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-02 02:01:02                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-02 02:01:02                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-02 02:01:03                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 02:01:03                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-02 02:01:03                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-02 02:01:03                                  Service Control Manager         7036:  ""    .  
                        2002-01-02 02:01:03                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 02:01:03                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 02:01:03                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 02:01:03                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-02 02:01:03                                  Service Control Manager         7036:  "    "    .  
                        2002-01-02 02:01:03                                  Service Control Manager         7036:  "     "    .  
                        2002-01-02 02:01:03                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 02:01:03                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 02:01:03                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-02 02:01:03                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-02 02:01:03                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-02 02:01:03                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 02:01:03                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 02:01:03                                  Service Control Manager         7036:  " "    .  
                4          2002-01-02 02:01:03  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-02 02:01:03  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-02 02:01:04                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 02:01:05                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-02 02:01:05                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 02:01:05                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 02:01:05                                  Service Control Manager         7036:  "  "    .  
                1101       2002-01-02 02:01:05                           Microsoft-Windows-Winlogon      7001:           
                            2002-01-02 02:01:06                                  BugCheck                        
                        2002-01-02 02:01:06                                  Service Control Manager         7036:  "    "    .  
                        2002-01-02 02:01:06                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-02 02:01:06                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 02:01:06                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-02 02:01:06                                  Service Control Manager         7036:  "  IP"    .  
                            2002-01-02 02:01:07                                  Service Control Manager         7026:    ()    :   cdrom  
                        2002-01-02 02:01:07                                  Service Control Manager         7036:  ""    .  
                        2002-01-02 02:01:07                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 02:01:07                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 02:01:07                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 02:01:07                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-02 02:01:07                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 02:01:08                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 02:01:08                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 02:01:08                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 02:01:22                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 02:01:30                                  Service Control Manager         7036:  " "    .  
                        2002-01-02 02:01:31                                  Service Control Manager         7036:  "Windows Search"    .  
                          2002-01-02 02:01:57  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-02 02:03:07                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-02 02:03:07                                  Service Control Manager         7036:  "    (BITS)"    .  
                        2002-01-02 02:03:07                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-02 02:03:07                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-02 02:03:08                                  Service Control Manager         7036:  "   "    .  
                        2002-01-02 02:03:08                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-02 02:03:08                                  Service Control Manager         7036:  "  "    .  
                        2002-01-02 02:03:09                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 20:54:33                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-04 20:54:36                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
                4          2002-01-04 20:54:39                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-04 20:54:39                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
          Unknown         63         2002-01-04 20:54:39                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                            2002-01-04 20:54:52                                  EventLog                        6008:      2:03:56  ?02.?01.?2002  .  
                        2002-01-04 20:54:52                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-04 20:54:52                                  EventLog                        6005:    .  
                        2002-01-04 20:54:52                                  EventLog                        6013:    19 .  
                        2002-01-04 20:54:52                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-04 20:54:52                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 20:54:52                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-04 20:54:52                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-04 20:54:52                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-04 20:54:52                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 20:54:52                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:54:52                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-04 20:54:52                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-04 20:54:52                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 20:54:52                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-04 20:54:52                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-04 20:54:53                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:54:53                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:54:53                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 20:54:53                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-04 20:54:53                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 20:54:53                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 20:54:53                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 20:54:53                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-04 20:54:53                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 20:54:53                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 20:54:53                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-04 20:54:53                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:54:53                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 20:54:53                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 20:54:53                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:54:53                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 20:54:53                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 20:54:53                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 20:54:53                                  Service Control Manager         7036:  "  "    .  
                1101       2002-01-04 20:54:53                           Microsoft-Windows-Winlogon      7001:           
                4          2002-01-04 20:54:53  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-04 20:54:53  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                            2002-01-04 20:54:54                                  Service Control Manager         7026:    ()    :   cdrom  
                        2002-01-04 20:54:54                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-04 20:54:54                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 20:54:54                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 20:54:54                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-04 20:54:54                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 20:54:54                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 20:54:54                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 20:54:54                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:54:54                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:54:54                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:54:54                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:54:54                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 20:55:12                                  EventLog                        6006:    .  
                        2002-01-04 20:55:12                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:55:12                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:55:12                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 20:55:12                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:55:12                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 20:55:12                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 20:55:12                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 20:55:12                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:55:12                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:55:12                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 20:55:12                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 20:55:12                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 20:55:12                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:55:12                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 20:55:12                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-04 20:55:12  user                            USER32                          1074:  C:\Windows\system32\winlogon.exe (USER-PC)   " "   USER-PC    user-PC\user  :        : 0x500ff     :      :   
                1102       2002-01-04 20:55:12                           Microsoft-Windows-Winlogon      7002:           
                4          2002-01-04 20:55:12  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51047:   DHCPv6 .    : 1  
                4          2002-01-04 20:55:12  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50037:    DHCPv4.    : 1  
                        2002-01-04 20:55:13                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                103        2002-01-04 20:55:13                                  Microsoft-Windows-Kernel-Power  109:      .  
                7010       2002-01-04 20:55:13                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "false"      PlugPlay: "false"     
                        2002-01-04 20:55:18                                  Microsoft-Windows-Kernel-General  13:  .  
                        2002-01-04 20:55:53                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-04 20:55:56                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
                4          2002-01-04 20:56:00                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-04 20:56:00                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-04 20:56:06                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-04 20:56:06                                  EventLog                        6005:    .  
                        2002-01-04 20:56:06                                  EventLog                        6013:    13 .  
                        2002-01-04 20:56:06                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-04 20:56:06                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 20:56:06                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-04 20:56:06                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-04 20:56:06                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-04 20:56:06                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 20:56:06                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-04 20:56:06                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-04 20:56:07                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-04 20:56:07                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:56:07                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:56:07                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-04 20:56:07                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-04 20:56:07                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 20:56:07                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:56:07                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:56:07                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 20:56:07                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-04 20:56:07                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 20:56:07                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 20:56:07                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 20:56:07                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 20:56:07                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-04 20:56:07                                  Service Control Manager         7036:  "DHCP-"    .  
                4          2002-01-04 20:56:07  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-04 20:56:07  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-04 20:56:08                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 20:56:08                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 20:56:08                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:56:09                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 20:56:09                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 20:56:09                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 20:56:09                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:56:09                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 20:56:09                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 20:56:09                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-04 20:56:09                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 20:56:09                                  Service Control Manager         7036:  "  IP"    .  
                1101       2002-01-04 20:56:09                           Microsoft-Windows-Winlogon      7001:           
                            2002-01-04 20:56:10                                  Service Control Manager         7026:    ()    :   cdrom  
                        2002-01-04 20:56:10                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 20:56:10                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 20:56:10                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:56:10                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:56:10                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:56:13                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 20:56:15                                  Service Control Manager         7036:  "  "    .  
                          2002-01-04 20:56:15  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 3   : 8   : 1           .  
                        2002-01-04 20:56:23                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:56:23  user                            USER32                          1074:  C:\Windows\system32\winlogon.exe (USER-PC)   " "   USER-PC    user-PC\user  :        : 0x500ff     :      :   
                1102       2002-01-04 20:56:23                           Microsoft-Windows-Winlogon      7002:           
                        2002-01-04 20:56:24                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:56:24                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 20:56:24                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:56:24                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 20:56:24                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 20:56:24                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 20:56:24                                  EventLog                        6006:    .  
                        2002-01-04 20:56:24                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:56:24                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:56:24                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 20:56:24                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 20:56:24                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 20:56:24                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 20:56:24                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 20:56:24                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-04 20:56:24                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                103        2002-01-04 20:56:24                                  Microsoft-Windows-Kernel-Power  109:      .  
                4          2002-01-04 20:56:24  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51047:   DHCPv6 .    : 1  
                4          2002-01-04 20:56:24  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50037:    DHCPv4.    : 1  
                7010       2002-01-04 20:56:24                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "false"      PlugPlay: "false"     
                        2002-01-04 20:56:30                                  Microsoft-Windows-Kernel-General  13:  .  
                        2002-01-04 21:10:50                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-04 21:10:53                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
                4          2002-01-04 21:10:57                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-04 21:10:57                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-04 21:11:03                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-04 21:11:03                                  EventLog                        6005:    .  
                        2002-01-04 21:11:03                                  EventLog                        6013:    13 .  
                        2002-01-04 21:11:03                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-04 21:11:03                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:11:03                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-04 21:11:03                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-04 21:11:03                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-04 21:11:03                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 21:11:03                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:11:03                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-04 21:11:03                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-04 21:11:04                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-04 21:11:04                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-04 21:11:04                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:11:04                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:11:04                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:11:04                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:11:04                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-04 21:11:04                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 21:11:04                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 21:11:04                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:11:04                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:11:04                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-04 21:11:04                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 21:11:04                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-04 21:11:04                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-04 21:11:04  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-04 21:11:04  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-04 21:11:05                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:11:05                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:11:05                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:11:05                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 21:11:05                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:11:05                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:11:05                                  Service Control Manager         7036:  "  "    .  
                1101       2002-01-04 21:11:05                           Microsoft-Windows-Winlogon      7001:           
                            2002-01-04 21:11:06                                  BugCheck                        
                        2002-01-04 21:11:06                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 21:11:06                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 21:11:06                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-04 21:11:06                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:11:06                                  Service Control Manager         7036:  "  IP"    .  
                            2002-01-04 21:11:07                                  Service Control Manager         7026:    ()    :   cdrom  
                        2002-01-04 21:11:07                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:11:07                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:11:07                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:11:07                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:11:07                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:11:07                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:11:08                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:11:08                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:11:11                           Microsoft-Windows-StartupRepair  1001:        .  
                        2002-01-04 21:11:11                           Microsoft-Windows-StartupRepair  1123: Windows    .  : 0xa  
                        2002-01-04 21:11:11                           Microsoft-Windows-StartupRepair  1213:      .  
                7005       2002-01-04 21:11:12                           Microsoft-Windows-UserPnp       20003:       i8042prt      ACPI\PNP0F03\4&347393C0&0   : 0.  
                7005       2002-01-04 21:11:12                           Microsoft-Windows-UserPnp       20003:       mouclass      ACPI\PNP0F03\4&347393C0&0   : 0.  
                7005       2002-01-04 21:11:12                           Microsoft-Windows-UserPnp       20001:       FileRepository\msmouse.inf_x86_neutral_7a9084e0177406eb\msmouse.inf      ACPI\PNP0F03\4&347393C0&0   : 0x0.  
                        2002-01-04 21:11:20                                  EventLog                        6006:    .  
                        2002-01-04 21:11:20                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:11:20                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:11:20                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:11:20                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:11:20                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 21:11:20                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:11:20                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 21:11:20                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:11:20                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:11:20  user                            USER32                          1074:  C:\Windows\system32\winlogon.exe (USER-PC)   " "   USER-PC    user-PC\user  :        : 0x500ff     :      :   
                1102       2002-01-04 21:11:20                           Microsoft-Windows-Winlogon      7002:           
                4          2002-01-04 21:11:20  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51047:   DHCPv6 .    : 1  
                4          2002-01-04 21:11:20  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50037:    DHCPv4.    : 1  
                        2002-01-04 21:15:17                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-04 21:15:20                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
          Unknown         63         2002-01-04 21:15:22                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                4          2002-01-04 21:15:27                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-04 21:15:27                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-04 21:15:36                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-04 21:15:36                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:15:36                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-04 21:15:36                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-04 21:15:37                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-04 21:15:37                                  EventLog                        6005:    .  
                        2002-01-04 21:15:37                                  EventLog                        6013:    20 .  
                        2002-01-04 21:15:37                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-04 21:15:37                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-04 21:15:37                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-04 21:15:37                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 21:15:37                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:15:38                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-04 21:15:39                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-04 21:15:39                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:15:39                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:15:39                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:15:39                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:15:39                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-04 21:15:39                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 21:15:39                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 21:15:39                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:15:39                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:15:40                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-04 21:15:40                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-04 21:15:40                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 21:15:40                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-04 21:15:40  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-04 21:15:40  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-04 21:15:41                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:15:42                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:15:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:15:43                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 21:15:43                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:15:44                                  Service Control Manager         7036:  "  "    .  
                1101       2002-01-04 21:15:44                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-04 21:15:45                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:15:45                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-04 21:15:45                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:15:45                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 21:15:46                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 21:15:47                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:15:47                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-04 21:15:47                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:15:48                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:15:48                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:15:49                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:15:49                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:15:50                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:16:18                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:16:18  user                            USER32                          1074:  C:\Windows\system32\winlogon.exe (USER-PC)   " "   USER-PC    user-PC\user  :        : 0x500ff     :      :   
                1102       2002-01-04 21:16:18                           Microsoft-Windows-Winlogon      7002:           
                        2002-01-04 21:16:19                                  EventLog                        6006:    .  
                        2002-01-04 21:16:19                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:16:19                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 21:16:19                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:16:19                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-04 21:16:19                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:16:19                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 21:16:19                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:16:19                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:16:19                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-04 21:16:19  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51047:   DHCPv6 .    : 1  
                4          2002-01-04 21:16:19  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50037:    DHCPv4.    : 1  
                7010       2002-01-04 21:16:19                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "false"      PlugPlay: "false"     
                        2002-01-04 21:17:04                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-04 21:17:07                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
          Unknown         63         2002-01-04 21:17:09                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                4          2002-01-04 21:17:14                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-04 21:17:14                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-04 21:17:23                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                7010       2002-01-04 21:17:23                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-04 21:17:24                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-04 21:17:24                                  EventLog                        6005:    .  
                        2002-01-04 21:17:24                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:17:24                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-04 21:17:24                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-04 21:17:24                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-04 21:17:24                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                        2002-01-04 21:17:25                                  EventLog                        6013:    20 .  
                        2002-01-04 21:17:25                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 21:17:25                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:17:26                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-04 21:17:26                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-04 21:17:26                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:17:26                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:17:26                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:17:26                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:17:27                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-04 21:17:27                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 21:17:27                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 21:17:27                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:17:27                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:17:27                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-04 21:17:27                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 21:17:27                                  Service Control Manager         7036:  "DNS-"    .  
                4          2002-01-04 21:17:27  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-04 21:17:27  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-04 21:17:28                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:17:28                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:17:29                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:17:29                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:17:30                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 21:17:30                                  Service Control Manager         7036:  " "    .  
                1101       2002-01-04 21:17:30                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-04 21:17:31                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:17:32                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:17:32                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-04 21:17:32                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:17:32                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 21:17:33                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 21:17:34                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-04 21:17:34                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:17:35                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:17:35                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:17:36                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:17:36                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:17:37                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:17:38                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:17:47  user                            USER32                          1074:  C:\Windows\system32\winlogon.exe (USER-PC)   " "   USER-PC    user-PC\user  :        : 0x500ff     :      :   
                1102       2002-01-04 21:17:47                           Microsoft-Windows-Winlogon      7002:           
                        2002-01-04 21:17:48                                  EventLog                        6006:    .  
                        2002-01-04 21:17:48                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:17:48                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 21:17:48                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:17:48                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:17:48                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:17:48                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:17:48                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 21:17:48                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-04 21:17:48  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51047:   DHCPv6 .    : 1  
                4          2002-01-04 21:17:48  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50037:    DHCPv4.    : 1  
                        2002-01-04 21:24:54                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-04 21:29:18                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-04 21:29:21                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
          Unknown         63         2002-01-04 21:29:23                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                4          2002-01-04 21:29:28                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-04 21:29:28                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-04 21:29:38                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                7010       2002-01-04 21:29:38                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-04 21:29:39                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:29:39                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-04 21:29:39                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-04 21:29:39                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                        2002-01-04 21:29:40                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-04 21:29:40                                  EventLog                        6005:    .  
                        2002-01-04 21:29:40                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-04 21:29:41                                  EventLog                        6013:    22 .  
                        2002-01-04 21:29:41                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 21:29:41                                  Service Control Manager         7036:  "  "    .  
                            2002-01-04 21:29:42                                  BugCheck                        
                        2002-01-04 21:29:42                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-04 21:29:42                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-04 21:29:42                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:29:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:29:43                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:29:43                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:29:43                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-04 21:29:43                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 21:29:43                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 21:29:43                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:29:43                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:29:43                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                4          2002-01-04 21:29:43  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                        2002-01-04 21:29:44                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 21:29:44                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-04 21:29:44                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-04 21:29:44  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-04 21:29:45                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:29:45                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:29:46                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:29:46                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 21:29:46                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:29:47                                  Service Control Manager         7036:  "  "    .  
                1101       2002-01-04 21:29:47                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-04 21:29:48                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:29:48                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-04 21:29:48                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:29:48                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 21:29:49                                  Service Control Manager         7036:  "  Windows"    .  
                            2002-01-04 21:29:50                                  Service Control Manager         7026:    ()    :   cdrom  
                        2002-01-04 21:29:50                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:29:50                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-04 21:29:50                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:29:50                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:29:51                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:29:51                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:29:51                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:29:53                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:30:03                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:30:05                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:30:12                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:30:13                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-04 21:30:14                                  BugCheck                        
                        2002-01-04 21:30:41                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-04 21:30:41                                  Service Control Manager         7036:  "  PNP-"    .  
                          2002-01-04 21:31:24  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-04 21:31:51                                  Service Control Manager         7036:  "    (BITS)"    .  
                        2002-01-04 21:31:51                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-04 21:31:51                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 21:31:51                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:31:51                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:31:53                                  Service Control Manager         7036:  "  Windows"    .  
                          2002-01-04 21:32:24  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-04 21:35:18  user                            USER32                          1074:  Explorer.EXE   " "   USER-PC    user-PC\user  :  ()     : 0x0     :      :   
                        2002-01-04 21:35:20  user                            USER32                          1074:  C:\Windows\system32\winlogon.exe (USER-PC)   " "   USER-PC    user-PC\user  :        : 0x500ff     :      :   
                1102       2002-01-04 21:35:20                           Microsoft-Windows-Winlogon      7002:           
                        2002-01-04 21:35:21                                  EventLog                        6006:    .  
                        2002-01-04 21:35:21                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 21:35:21                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:35:21                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:35:21                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 21:35:21                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:35:21                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:35:21                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-04 21:35:21                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:35:21                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 21:35:21                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 21:35:21                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:35:21                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:35:21                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-04 21:35:21                                  Service Control Manager         7036:  "  PNP-"    .  
                        2002-01-04 21:35:21                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 21:35:21                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:35:21                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-04 21:35:21                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 21:35:21                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:35:21                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:35:21                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:35:21                                  Service Control Manager         7036:  "Superfetch"    .  
                4          2002-01-04 21:35:21  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51047:   DHCPv6 .    : 1  
                4          2002-01-04 21:35:21  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50037:    DHCPv4.    : 1  
                7010       2002-01-04 21:35:21                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "false"      PlugPlay: "false"     
                        2002-01-04 21:35:22                                  Service Control Manager         7036:  "Windows Search"    .  
                103        2002-01-04 21:35:22                                  Microsoft-Windows-Kernel-Power  109:      .  
                        2002-01-04 21:35:25                                  Microsoft-Windows-Kernel-General  13:  .  
                        2002-01-04 21:37:27                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-04 21:37:30                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
                4          2002-01-04 21:37:34                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-04 21:37:34                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-04 21:37:40                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-04 21:37:40                                  EventLog                        6005:    .  
                        2002-01-04 21:37:40                                  EventLog                        6013:    13 .  
                        2002-01-04 21:37:40                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-04 21:37:40                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:37:40                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-04 21:37:40                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-04 21:37:40                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-04 21:37:40                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-04 21:37:40                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-04 21:37:41                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 21:37:41                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:37:41                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-04 21:37:41                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-04 21:37:41                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:37:41                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:37:41                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:37:41                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:37:41                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-04 21:37:41                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 21:37:41                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 21:37:41                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:37:41                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:37:41                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-04 21:37:41                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 21:37:41                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-04 21:37:41                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:37:41                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:37:41                                  Service Control Manager         7036:  " "    .  
                4          2002-01-04 21:37:41  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-04 21:37:41  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-04 21:37:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:37:42                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 21:37:42                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:37:42                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:37:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:37:42                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:37:42                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-04 21:37:42                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 21:37:42                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-04 21:37:42                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 21:37:42                                  Service Control Manager         7036:  ""    .  
                1101       2002-01-04 21:37:42                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-04 21:37:43                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:37:43                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:37:43                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:37:43                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:37:43                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:37:43                                  Service Control Manager         7036:  "  "    .  
                7005       2002-01-04 21:37:48                           Microsoft-Windows-UserPnp       20003:       cdrom      IDE\CDROMPIONEER_DVD-RW__DVR-219L________________1.01____\5&2BC02221&0&0.1.0   : 0.  
                7005       2002-01-04 21:37:49                           Microsoft-Windows-UserPnp       20001:       FileRepository\cdrom.inf_x86_neutral_6381e09675524225\cdrom.inf      IDE\CDROMPIONEER_DVD-RW__DVR-219L________________1.01____\5&2BC02221&0&0.1.0   : 0x0.  
                        2002-01-04 21:37:57                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:37:58                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-04 21:38:29                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:38:31                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:38:32                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 21:38:32                           Microsoft-Windows-Application-Experience  201:       .  
                          2002-01-04 21:38:33  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-04 21:39:16                           Microsoft-Windows-Application-Experience  206:          .  
                        2002-01-04 21:39:43                                  Service Control Manager         7036:  "    (BITS)"    .  
                        2002-01-04 21:39:43                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-04 21:39:43                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-04 21:39:44                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 21:39:44                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:39:45                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 21:39:49                                  Service Control Manager         7036:  "   "    .  
                          2002-01-04 21:40:33  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-04 21:40:39  user                            USER32                          1074:  C:\Windows\system32\wbem\wmiprvse.exe (USER-PC)   ""   USER-PC    user-PC\user  :        : 0x80070015     :     :   
                1102       2002-01-04 21:40:41                           Microsoft-Windows-Winlogon      7002:           
                        2002-01-04 21:40:42                                  EventLog                        6006:    .  
                        2002-01-04 21:40:42                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 21:40:42                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 21:40:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:40:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:40:42                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 21:40:42                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:40:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:40:42                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:40:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:40:42                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 21:40:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:40:42                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 21:40:42                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 21:40:42                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-04 21:40:42                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:40:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:40:42                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 21:40:42                                  Service Control Manager         7036:  "Superfetch"    .  
                1          2002-01-04 21:40:42                           Microsoft-Windows-WindowsUpdateClient  27:   .  
                4          2002-01-04 21:40:42  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51047:   DHCPv6 .    : 1  
                4          2002-01-04 21:40:42  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50037:    DHCPv4.    : 1  
                        2002-01-04 21:40:43                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:40:43                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-04 21:40:43                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-04 21:40:43                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 21:40:43                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:40:43                                  Service Control Manager         7036:  "Windows Search"    .  
                103        2002-01-04 21:40:43                                  Microsoft-Windows-Kernel-Power  109:      .  
                7010       2002-01-04 21:40:43                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "false"      PlugPlay: "false"     
                        2002-01-04 21:40:46                                  Microsoft-Windows-Kernel-General  13:  .  
                        2002-01-04 21:41:57                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-04 21:42:00                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
                4          2002-01-04 21:42:04                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-04 21:42:04                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-04 21:42:12                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                7010       2002-01-04 21:42:12                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-04 21:42:13                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-04 21:42:13                                  EventLog                        6005:    .  
                        2002-01-04 21:42:13                                  EventLog                        6013:    15 .  
                        2002-01-04 21:42:13                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:42:13                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-04 21:42:13                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-04 21:42:13                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-04 21:42:13                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 21:42:13                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:42:13                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-04 21:42:13                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-04 21:42:13                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:42:13                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:42:13                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:42:13                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:42:13                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-04 21:42:13                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 21:42:13                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 21:42:13                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:42:13                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-04 21:42:13                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:42:13                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 21:42:13                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-04 21:42:13                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:42:13                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:42:13                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                4          2002-01-04 21:42:13  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-04 21:42:13  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-04 21:42:14                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:42:14                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:42:14                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 21:42:14                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:42:14                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:42:14                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:42:14                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-04 21:42:14                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:42:14                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 21:42:14                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 21:42:14                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-04 21:42:14                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:42:14                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:42:14                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:42:14                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:42:14                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:42:14                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:42:14                                  Service Control Manager         7036:  "   "    .  
                1101       2002-01-04 21:42:14                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-04 21:42:17                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:43:08  user                            USER32                          1074:  C:\Windows\system32\wbem\wmiprvse.exe (USER-PC)   ""   USER-PC    user-PC\user  :        : 0x80070015     :     :   
                        2002-01-04 21:43:10                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:43:10                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:43:10                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 21:43:10                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:43:10                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:43:10                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 21:43:10                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:43:10                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:43:10                                  Service Control Manager         7036:  "  "    .  
                1102       2002-01-04 21:43:10                           Microsoft-Windows-Winlogon      7002:           
                4          2002-01-04 21:43:10  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51047:   DHCPv6 .    : 1  
                4          2002-01-04 21:43:10  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50037:    DHCPv4.    : 1  
                        2002-01-04 21:43:11                                  EventLog                        6006:    .  
                        2002-01-04 21:48:25                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-04 21:48:28                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
          Unknown         63         2002-01-04 21:48:31                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                4          2002-01-04 21:48:33                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-04 21:48:33                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-04 21:48:39                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-04 21:48:39                                  Service Control Manager         7036:  ""    .  
                7010       2002-01-04 21:48:39                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-04 21:48:40                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-04 21:48:40                                  EventLog                        6005:    .  
                        2002-01-04 21:48:40                                  EventLog                        6013:    14 .  
                        2002-01-04 21:48:40                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-04 21:48:40                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-04 21:48:40                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-04 21:48:40                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 21:48:40                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:48:40                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-04 21:48:40                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-04 21:48:40                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:48:40                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:48:40                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:48:40                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:48:40                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-04 21:48:40                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 21:48:40                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 21:48:40                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:48:40                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:48:40                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-04 21:48:40                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 21:48:40                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-04 21:48:40                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:48:40                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                4          2002-01-04 21:48:40  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-04 21:48:40  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-04 21:48:41                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:48:41                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:48:41                                  Service Control Manager         7036:  "  "    .  
                1101       2002-01-04 21:48:41                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-04 21:48:42                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 21:48:42                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:48:42                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:48:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:48:42                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-04 21:48:42                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:48:42                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 21:48:42                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-04 21:48:42                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 21:48:42                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 21:48:42                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:48:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:48:42                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 21:48:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:48:42                                  Service Control Manager         7036:  "  "    .  
                            2002-01-04 21:48:43                                  BugCheck                        
                        2002-01-04 21:48:46                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-04 21:48:57                                  BugCheck                        
                        2002-01-04 21:48:57                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 21:48:57                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-04 21:49:01                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:49:05                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 21:49:06                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:05:46                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-04 22:05:49                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
          Unknown         63         2002-01-04 22:05:51                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                4          2002-01-04 22:05:53                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-04 22:05:53                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-04 22:06:00                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-04 22:06:00                                  EventLog                        6005:    .  
                        2002-01-04 22:06:00                                  EventLog                        6013:    14 .  
                        2002-01-04 22:08:12                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-04 22:08:15                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
          Unknown         63         2002-01-04 22:08:18                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                4          2002-01-04 22:08:20                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-04 22:08:20                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-04 22:08:26                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-04 22:08:26                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 22:08:26                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-04 22:08:26                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-04 22:08:27                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-04 22:08:27                                  EventLog                        6005:    .  
                        2002-01-04 22:08:27                                  EventLog                        6013:    14 .  
                        2002-01-04 22:08:27                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-04 22:08:27                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-04 22:08:27                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-04 22:08:27                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 22:08:27                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:08:27                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-04 22:08:27                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-04 22:08:27                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 22:08:27                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:08:27                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:08:27                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:08:27                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-04 22:08:27                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 22:08:27                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 22:08:27                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:08:27                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:08:27                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-04 22:08:27                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 22:08:27                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-04 22:08:27                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-04 22:08:27  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-04 22:08:27  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-04 22:08:28                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:08:28                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:08:28                                  Service Control Manager         7036:  "  "    .  
                1101       2002-01-04 22:08:28                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-04 22:08:29                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 22:08:29                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:08:29                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:08:29                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:08:29                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-04 22:08:29                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:08:29                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 22:08:29                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-04 22:08:29                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 22:08:29                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:08:29                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 22:08:29                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:08:29                                  Service Control Manager         7036:  "  "    .  
                            2002-01-04 22:08:30                                  BugCheck                        
                        2002-01-04 22:08:30                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:08:30                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:08:32                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-04 22:08:47                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:08:48                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-04 22:17:29                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-04 22:17:32                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
          Unknown         63         2002-01-04 22:17:34                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                4          2002-01-04 22:17:38                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-04 22:17:38                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-04 22:17:47                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                7010       2002-01-04 22:17:47                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-04 22:17:48                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-04 22:17:48                                  EventLog                        6005:    .  
                        2002-01-04 22:17:48                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 22:17:48                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-04 22:17:48                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-04 22:17:48                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-04 22:17:48                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                        2002-01-04 22:17:49                                  EventLog                        6013:    19 .  
                        2002-01-04 22:17:49                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 22:17:49                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:17:50                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-04 22:17:50                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-04 22:17:51                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 22:17:51                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:17:51                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:17:51                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:17:51                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-04 22:17:51                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 22:17:51                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 22:17:51                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:17:51                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:17:51                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-04 22:17:51                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 22:17:51                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-04 22:17:51                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:17:51                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-04 22:17:51  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-04 22:17:51  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-04 22:17:52                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:17:54                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:17:54                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:17:54                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 22:17:55                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:17:55                                  Service Control Manager         7036:  "  "    .  
                1101       2002-01-04 22:17:55                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-04 22:17:56                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:17:56                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-04 22:17:56                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:17:56                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 22:17:57                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 22:17:58                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:17:58                                  Service Control Manager         7036:  "  IP"    .  
                            2002-01-04 22:17:59                                  Service Control Manager         7026:    ()    :   cdrom  
                        2002-01-04 22:17:59                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 22:17:59                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:18:00                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:18:00                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:18:00                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:18:00                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:18:01                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:18:04                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:18:04                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:18:05                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:18:05                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:18:12                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:18:12                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:18:14                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:18:16                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-04 22:18:17                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:18:17                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:19:19                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-04 22:19:22                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
          Unknown         63         2002-01-04 22:19:23                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                4          2002-01-04 22:19:28                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-04 22:19:28                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-04 22:19:38                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-04 22:19:38                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 22:19:38                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-04 22:19:38                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-04 22:19:39                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-04 22:19:39                                  EventLog                        6005:    .  
                        2002-01-04 22:19:39                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-04 22:19:39                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-04 22:19:39                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-04 22:19:40                                  EventLog                        6013:    20 .  
                        2002-01-04 22:19:40                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 22:19:40                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:19:41                                  Service Control Manager         7036:  "    Windows Audio"    .  
                            2002-01-04 22:19:42                                  BugCheck                        
                        2002-01-04 22:19:42                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-04 22:19:42                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 22:19:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:19:43                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:19:43                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:19:43                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-04 22:19:43                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 22:19:43                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 22:19:43                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:19:43                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:19:43                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-04 22:19:43                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 22:19:43                                  Service Control Manager         7036:  "DNS-"    .  
                4          2002-01-04 22:19:43  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-04 22:19:43  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-04 22:19:44                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:19:44                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:19:45                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:19:46                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:19:46                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 22:19:47                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:19:47                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:19:47                                  Service Control Manager         7036:  " "    .  
                1101       2002-01-04 22:19:47                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-04 22:19:48                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 22:19:48                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-04 22:19:49                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:19:49                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 22:19:50                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:19:51                                  Service Control Manager         7036:  "  IP"    .  
                            2002-01-04 22:19:52                                  Service Control Manager         7026:    ()    :   cdrom  
                        2002-01-04 22:19:52                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 22:19:52                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:19:52                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:19:52                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:19:52                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:19:53                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:20:09                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:20:12                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:20:13                                  Service Control Manager         7036:  "Windows Search"    .  
                7005       2002-01-04 22:20:16                           Microsoft-Windows-UserPnp       20003:       volsnap      STORAGE\VOLUME\{14FA0F40-0150-11D6-B1C5-806E6F6E6963}#0000000000007E00   : 0.  
                7005       2002-01-04 22:20:16                           Microsoft-Windows-UserPnp       20001:       FileRepository\volume.inf_x86_neutral_6dee0205881d1a1d\volume.inf      STORAGE\VOLUME\{14FA0F40-0150-11D6-B1C5-806E6F6E6963}#0000000000007E00   : 0x0.  
                        2002-01-04 22:20:17                                  BugCheck                        
                        2002-01-04 22:20:26                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:23:08                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-04 22:23:11                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
          Unknown         63         2002-01-04 22:23:13                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                4          2002-01-04 22:23:17                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-04 22:23:17                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-04 22:23:26                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                7010       2002-01-04 22:23:26                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-04 22:23:27                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-04 22:23:27                                  EventLog                        6005:    .  
                        2002-01-04 22:23:27                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 22:23:27                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-04 22:23:27                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-04 22:23:27                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-04 22:23:27                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                        2002-01-04 22:23:28                                  EventLog                        6013:    19 .  
                        2002-01-04 22:23:28                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 22:23:28                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:23:29                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-04 22:23:29                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-04 22:23:30                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 22:23:30                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:23:30                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:23:30                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:23:30                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-04 22:23:30                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 22:23:30                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 22:23:30                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:23:30                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:23:30                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-04 22:23:30                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-04 22:23:30                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 22:23:30                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-04 22:23:30  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-04 22:23:30  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-04 22:23:31                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:23:33                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:23:33                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:23:33                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 22:23:34                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:23:34                                  Service Control Manager         7036:  "  "    .  
                1101       2002-01-04 22:23:34                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-04 22:23:35                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:23:35                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-04 22:23:36                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:23:36                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 22:23:36                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 22:23:37                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:23:37                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-04 22:23:38                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 22:23:39                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:23:39                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:23:40                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:23:41                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:23:53                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 22:23:56                                  Service Control Manager         7036:  "Windows Search"    .  
                7005       2002-01-04 22:23:59                           Microsoft-Windows-UserPnp       20003:       volsnap      STORAGE\VOLUME\{14FA0F40-0150-11D6-B1C5-806E6F6E6963}#0000000000007E00   : 0.  
                7005       2002-01-04 22:23:59                           Microsoft-Windows-UserPnp       20001:       FileRepository\volume.inf_x86_neutral_6dee0205881d1a1d\volume.inf      STORAGE\VOLUME\{14FA0F40-0150-11D6-B1C5-806E6F6E6963}#0000000000007E00   : 0x0.  
                7005       2002-01-04 22:24:00                           Microsoft-Windows-UserPnp       20003:       cdrom      IDE\CDROMPIONEER_DVD-RW__DVR-219L________________1.01____\5&1906717C&0&1.1.0   : 0.  
                7005       2002-01-04 22:24:02                           Microsoft-Windows-UserPnp       20001:       FileRepository\cdrom.inf_x86_neutral_6381e09675524225\cdrom.inf      IDE\CDROMPIONEER_DVD-RW__DVR-219L________________1.01____\5&1906717C&0&1.1.0   : 0x0.  
                        2002-01-04 22:24:04                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:24:08                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:24:09                                  Service Control Manager         7036:  "   "    .  
                          2002-01-04 22:24:13  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-04 22:24:27                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:24:27                                  Service Control Manager         7036:  "    (Microsoft)"    .  
                          2002-01-04 22:25:14  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-04 22:25:38                                  Service Control Manager         7036:  "    (BITS)"    .  
                        2002-01-04 22:25:39                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-04 22:25:39                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-04 22:25:39                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 22:25:40                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:25:41                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 22:26:02                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 22:27:56                                  Service Control Manager         7036:  "  "    .  
                          2002-01-04 22:28:13  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-04 22:29:05                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 22:30:56                                  Service Control Manager         7036:  "    (Microsoft)"    .  
                        2002-01-04 23:11:22                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-04 23:11:25                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
          Unknown         63         2002-01-04 23:11:26                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                4          2002-01-04 23:11:30                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-04 23:11:30                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-04 23:11:40                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-04 23:11:40                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 23:11:40                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-04 23:11:40                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-04 23:11:41                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-04 23:11:41                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-04 23:11:41                                  Service Control Manager         7036:  "   (RPC)"    .  
                            2002-01-04 23:11:42                                  EventLog                        6008:      22:32:13  ?04.?01.?2002  .  
                        2002-01-04 23:11:42                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-04 23:11:42                                  EventLog                        6005:    .  
                        2002-01-04 23:11:42                                  EventLog                        6013:    19 .  
                        2002-01-04 23:11:42                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 23:11:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:11:43                                  Service Control Manager         7036:  "    Windows Audio"    .  
                            2002-01-04 23:11:44                                  BugCheck                        
                        2002-01-04 23:11:44                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-04 23:11:45                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 23:11:45                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:11:45                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 23:11:45                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-04 23:11:45                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:11:45                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 23:11:45                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 23:11:45                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 23:11:45                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 23:11:45                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-04 23:11:45                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-04 23:11:45                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 23:11:45                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-04 23:11:45  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-04 23:11:45  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-04 23:11:46                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 23:11:47                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 23:11:48                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:11:48                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 23:11:49                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 23:11:49                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:11:49                                  Service Control Manager         7036:  " "    .  
                1101       2002-01-04 23:11:49                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-04 23:11:50                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 23:11:51                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-04 23:11:51                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 23:11:51                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 23:11:52                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 23:11:53                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-04 23:11:54                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 23:11:54                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:11:54                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:11:54                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:11:55                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 23:11:55                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:12:08                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 23:12:11                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-04 23:12:56                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-04 23:12:59                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
          Unknown         63         2002-01-04 23:13:01                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                4          2002-01-04 23:13:05                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-04 23:13:05                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-04 23:13:15                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-04 23:13:15                                  Service Control Manager         7036:  ""    .  
                7010       2002-01-04 23:13:15                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-04 23:13:16                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-04 23:13:16                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-04 23:13:16                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-04 23:13:16                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                            2002-01-04 23:13:17                                  EventLog                        6008:      23:11:42  ?04.?01.?2002  .  
                        2002-01-04 23:13:17                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-04 23:13:17                                  EventLog                        6005:    .  
                        2002-01-04 23:13:17                                  EventLog                        6013:    20 .  
                        2002-01-04 23:13:17                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 23:13:17                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:13:18                                  Service Control Manager         7036:  "    Windows Audio"    .  
                            2002-01-04 23:13:19                                  BugCheck                        
                        2002-01-04 23:13:19                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-04 23:13:20                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 23:13:20                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:13:20                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 23:13:20                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-04 23:13:20                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:13:20                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 23:13:20                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 23:13:20                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 23:13:20                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 23:13:20                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-04 23:13:20                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-04 23:13:20                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 23:13:20                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-04 23:13:20  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-04 23:13:20  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-04 23:13:21                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 23:13:23                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 23:13:23                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:13:23                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 23:13:23                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 23:13:24                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:13:25                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 23:13:25                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-04 23:13:25                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 23:13:25                                  Service Control Manager         7036:  "    "    .  
                1101       2002-01-04 23:13:25                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-04 23:13:26                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 23:13:27                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 23:13:27                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-04 23:13:28                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 23:13:28                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:13:28                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:13:29                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:13:29                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 23:13:31                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:13:45                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 23:13:47                                  BugCheck                        
                        2002-01-04 23:13:48                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-04 23:13:51                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:13:53                                  Service Control Manager         7036:  "   "    .  
                          2002-01-04 23:14:01  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-04 23:14:27                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:14:27                                  Service Control Manager         7036:  "    (Microsoft)"    .  
                          2002-01-04 23:15:02  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-04 23:15:28                                  Service Control Manager         7036:  "    (BITS)"    .  
                        2002-01-04 23:15:28                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-04 23:15:28                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-04 23:15:29                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 23:15:29                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:15:29                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 23:15:30                                  Service Control Manager         7036:  "  Windows"    .  
                          2002-01-04 23:16:01  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-04 23:16:06                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 23:17:27                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:18:32                                  Service Control Manager         7036:  "  PNP-"    .  
                7005       2002-01-04 23:18:47                           Microsoft-Windows-UserPnp       20003:       USBSTOR      USB\VID_4102&PID_1052\5&2C3B98B9&0&4   : 0.  
                7005       2002-01-04 23:18:47                           Microsoft-Windows-UserPnp       20001:       FileRepository\usbstor.inf_x86_neutral_c77d41a490bdc63d\usbstor.inf      USB\VID_4102&PID_1052\5&2C3B98B9&0&4   : 0x0.  
                7005       2002-01-04 23:18:48                           Microsoft-Windows-UserPnp       20003:       disk      USBSTOR\DISK&VEN_IRIVER&PROD_E150&REV_0100\6&3244539F&0&___K&0   : 0.  
                        2002-01-04 23:18:49                                  Service Control Manager         7036:  "   "    .  
                7005       2002-01-04 23:18:49                           Microsoft-Windows-UserPnp       20001:       FileRepository\disk.inf_x86_neutral_b431b61a11f8df6c\disk.inf      USBSTOR\DISK&VEN_IRIVER&PROD_E150&REV_0100\6&3244539F&0&___K&0   : 0x0.  
                7005       2002-01-04 23:18:50                           Microsoft-Windows-UserPnp       20003:       disk      USBSTOR\DISK&VEN_IRIVER&PROD_E150&REV_0100\6&3244539F&0&___K&1   : 0.  
                7005       2002-01-04 23:18:50                           Microsoft-Windows-UserPnp       20001:       FileRepository\disk.inf_x86_neutral_b431b61a11f8df6c\disk.inf      USBSTOR\DISK&VEN_IRIVER&PROD_E150&REV_0100\6&3244539F&0&___K&1   : 0x0.  
                7005       2002-01-04 23:18:51                           Microsoft-Windows-UserPnp       20003:       volsnap      STORAGE\VOLUME\_??_USBSTOR#DISK&VEN_IRIVER&PROD_E150&REV_0100#6&3244539F&0&___K&0#{53F56307-B6BF-11D0-94F2-00A0C91EFB8B}   : 0.  
                7005       2002-01-04 23:18:51                           Microsoft-Windows-UserPnp       20001:       FileRepository\volume.inf_x86_neutral_6dee0205881d1a1d\volume.inf      STORAGE\VOLUME\_??_USBSTOR#DISK&VEN_IRIVER&PROD_E150&REV_0100#6&3244539F&0&___K&0#{53F56307-B6BF-11D0-94F2-00A0C91EFB8B}   : 0x0.  
                        2002-01-04 23:18:52                                  Service Control Manager         7036:  "  "    .  
                7005       2002-01-04 23:18:52                           Microsoft-Windows-UserPnp       20003:       volsnap      STORAGE\VOLUME\_??_USBSTOR#DISK&VEN_IRIVER&PROD_E150&REV_0100#6&3244539F&0&___K&1#{53F56307-B6BF-11D0-94F2-00A0C91EFB8B}   : 0.  
                7005       2002-01-04 23:18:52                           Microsoft-Windows-UserPnp       20001:       FileRepository\volume.inf_x86_neutral_6dee0205881d1a1d\volume.inf      STORAGE\VOLUME\_??_USBSTOR#DISK&VEN_IRIVER&PROD_E150&REV_0100#6&3244539F&0&___K&1#{53F56307-B6BF-11D0-94F2-00A0C91EFB8B}   : 0x0.  
                7005       2002-01-04 23:18:55                           Microsoft-Windows-UserPnp       20003:       umbus      UMB\UMB\1&841921D&0&WPDBUSENUMROOT   : 0.  
                7005       2002-01-04 23:18:55                           Microsoft-Windows-UserPnp       20001:       FileRepository\umbus.inf_x86_neutral_79120b2cb6857971\umbus.inf      UMB\UMB\1&841921D&0&WPDBUSENUMROOT   : 0x0.  
                        2002-01-04 23:18:56                                  Service Control Manager         7036:  "Windows Driver Foundation - User-mode Driver Framework"    .  
                        2002-01-04 23:18:56                           Service Control Manager         7040:    "Windows Driver Foundation - User-mode Driver Framework"    ""  "".  
                        2002-01-04 23:18:56                           Service Control Manager         7045:    .     :  WUDFRd    :  system32\DRIVERS\WUDFRd.sys   :        :      :    
                48         2002-01-04 23:18:56                           Microsoft-Windows-DriverFrameworks-UserMode  10000:  ,       1.9.0,    WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_IRIVER&PROD_E150&REV_0100#6&3244539F&0&___K&0#.  
                48         2002-01-04 23:18:56                           Microsoft-Windows-DriverFrameworks-UserMode  10001:      WpdFs (CLSID {112DE495-AC4C-46F8-B663-6A4266C53313}) .      1.9.0    .  
                48         2002-01-04 23:18:56                           Microsoft-Windows-DriverFrameworks-UserMode  10100:     .  
                16         2002-01-04 23:18:57                                  WPDClassInstaller               
                32         2002-01-04 23:18:57                                  WPDClassInstaller               
                32         2002-01-04 23:18:57                                  WPDClassInstaller               
                7005       2002-01-04 23:18:57                           Microsoft-Windows-UserPnp       20003:       WUDFRd      WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_IRIVER&PROD_E150&REV_0100#6&3244539F&0&___K&0#   : 0.  
                7005       2002-01-04 23:18:57                           Microsoft-Windows-UserPnp       20001:       FileRepository\wpdfs.inf_x86_neutral_fc4ebadff3a40ae4\wpdfs.inf      WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_IRIVER&PROD_E150&REV_0100#6&3244539F&0&___K&0#   : 0x0.  
                48         2002-01-04 23:18:58                           Microsoft-Windows-DriverFrameworks-UserMode  10000:  ,       1.9.0,    WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_IRIVER&PROD_E150&REV_0100#6&3244539F&0&___K&1#.  
                48         2002-01-04 23:18:58                           Microsoft-Windows-DriverFrameworks-UserMode  10002:      WpdFs (CLSID {112DE495-AC4C-46F8-B663-6A4266C53313}) .      1.9.0    .  
                48         2002-01-04 23:18:58                           Microsoft-Windows-DriverFrameworks-UserMode  10100:     .  
                16         2002-01-04 23:18:59                                  WPDClassInstaller               
                7005       2002-01-04 23:18:59                           Microsoft-Windows-UserPnp       20003:       WUDFRd      WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_IRIVER&PROD_E150&REV_0100#6&3244539F&0&___K&1#   : 0.  
                32         2002-01-04 23:19:00                                  WPDClassInstaller               
                32         2002-01-04 23:19:00                                  WPDClassInstaller               
                7005       2002-01-04 23:19:00                           Microsoft-Windows-UserPnp       20001:       FileRepository\wpdfs.inf_x86_neutral_fc4ebadff3a40ae4\wpdfs.inf      WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_IRIVER&PROD_E150&REV_0100#6&3244539F&0&___K&1#   : 0x0.  
                          2002-01-04 23:19:01  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-04 23:19:12                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:20:23  user                            USER32                          1074:  Explorer.EXE   " "   USER-PC    user-PC\user  :  ()     : 0x0     :      :   
                        2002-01-04 23:20:26  user                            USER32                          1074:  C:\Windows\system32\winlogon.exe (USER-PC)   " "   USER-PC    user-PC\user  :        : 0x500ff     :      :   
                1102       2002-01-04 23:20:26                           Microsoft-Windows-Winlogon      7002:           
                        2002-01-04 23:20:27                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 23:20:27                                  EventLog                        6006:    .  
                        2002-01-04 23:20:27                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 23:20:27                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:20:27                                  Service Control Manager         7036:  "    (Microsoft)"    .  
                        2002-01-04 23:20:27                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:20:27                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:20:27                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 23:20:27                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:20:27                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 23:20:27                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:20:27                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 23:20:27                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 23:20:27                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 23:20:27                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 23:20:27                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 23:20:27                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-04 23:20:27                                  Service Control Manager         7036:  "  PNP-"    .  
                        2002-01-04 23:20:27                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:20:27                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-04 23:20:27                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 23:20:27                                  Service Control Manager         7036:  "  "    .  
                1          2002-01-04 23:20:27                           Microsoft-Windows-WindowsUpdateClient  27:   .  
                4          2002-01-04 23:20:27  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51047:   DHCPv6 .    : 1  
                4          2002-01-04 23:20:27  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50037:    DHCPv4.    : 1  
                        2002-01-04 23:20:28                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 23:20:28                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-04 23:20:28                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 23:20:28                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                7010       2002-01-04 23:20:28                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "false"      PlugPlay: "false"     
                        2002-01-04 23:20:29                                  Service Control Manager         7036:  "Windows Search"    .  
                103        2002-01-04 23:20:29                                  Microsoft-Windows-Kernel-Power  109:      .  
                        2002-01-04 23:20:32                                  Microsoft-Windows-Kernel-General  13:  .  
                        2002-01-04 23:57:45                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-04 23:57:48                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
                4          2002-01-04 23:57:51                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-04 23:57:51                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-04 23:57:58                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-04 23:57:58                                  EventLog                        6005:    .  
                        2002-01-04 23:57:58                                  EventLog                        6013:    12 .  
                        2002-01-04 23:57:58                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-04 23:57:58                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 23:57:58                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-04 23:57:58                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-04 23:57:58                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-04 23:57:58                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 23:57:58                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:57:58                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-04 23:57:58                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-04 23:57:58                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 23:57:58                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:57:58                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:57:58                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 23:57:58                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-04 23:57:58                                  Service Control Manager         7036:  "    "    .  
                        2002-01-04 23:57:58                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 23:57:58                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 23:57:58                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-04 23:57:58                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-04 23:57:59                                  Service Control Manager         7036:  "Windows Driver Foundation - User-mode Driver Framework"    .  
                        2002-01-04 23:57:59                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-04 23:57:59                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 23:57:59                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 23:57:59                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-04 23:57:59                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-04 23:57:59  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-04 23:57:59  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-04 23:58:00                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 23:58:00                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 23:58:00                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:58:00                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-04 23:58:00                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 23:58:00                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 23:58:00                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:58:00                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-04 23:58:00                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 23:58:00                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 23:58:00                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-04 23:58:00                                  Service Control Manager         7036:  "    "    .  
                1101       2002-01-04 23:58:00                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-04 23:58:01                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 23:58:01                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 23:58:01                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:58:01                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:58:01                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:58:01                                  Service Control Manager         7036:  "   "    .  
                            2002-01-04 23:58:04                                  cdrom                           7:     \Device\CdRom0.  
                        2002-01-04 23:58:07                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 23:58:07                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-04 23:58:26                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 23:58:43                                  Service Control Manager         7036:  "  "    .  
                          2002-01-04 23:58:51  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-04 23:59:21  user                            USER32                          1074:  Explorer.EXE   ""   USER-PC    user-PC\user  :  ()     : 0x0     :     :   
                        2002-01-04 23:59:24                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:59:24                                  EventLog                        6006:    .  
                        2002-01-04 23:59:24                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:59:24                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-04 23:59:24                                  Service Control Manager         7036:  ""    .  
                        2002-01-04 23:59:24                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-04 23:59:24                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:59:24                                  Service Control Manager         7036:  "     "    .  
                        2002-01-04 23:59:24                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 23:59:24                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:59:24                                  Service Control Manager         7036:  "  "    .  
                        2002-01-04 23:59:24                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 23:59:24                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-04 23:59:24                                  Service Control Manager         7036:  "   "    .  
                        2002-01-04 23:59:24  user                            USER32                          1074:  C:\Windows\system32\winlogon.exe (USER-PC)   ""   USER-PC    user-PC\user  :        : 0x500ff     :     :   
                1102       2002-01-04 23:59:24                           Microsoft-Windows-Winlogon      7002:           
                4          2002-01-04 23:59:24  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51047:   DHCPv6 .    : 1  
                4          2002-01-04 23:59:24  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50037:    DHCPv4.    : 1  
                7010       2002-01-04 23:59:24                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "false"      PlugPlay: "false"     
                        2002-01-04 23:59:25                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-04 23:59:25                                  Service Control Manager         7036:  " "    .  
                        2002-01-04 23:59:25                                  Service Control Manager         7036:  "Windows Search"    .  
                103        2002-01-04 23:59:25                                  Microsoft-Windows-Kernel-Power  109:      .  
                        2002-01-04 23:59:32                                  Microsoft-Windows-Kernel-General  13:  .  
                        2002-01-04 23:59:56                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-05 00:00:00                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
                4          2002-01-05 00:00:04                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-05 00:00:04                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-05 00:00:12                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-05 00:00:12                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 00:00:12                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-05 00:00:12                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-05 00:00:12                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-05 00:00:12                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-05 00:00:12                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-05 00:00:13                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-05 00:00:13                                  EventLog                        6005:    .  
                        2002-01-05 00:00:13                                  EventLog                        6013:    16 .  
                        2002-01-05 00:00:13                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 00:00:13                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:00:14                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-05 00:00:14                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-05 00:00:14                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 00:00:14                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:00:14                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:00:14                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 00:00:14                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-05 00:00:14                                  Service Control Manager         7036:  "    "    .  
                        2002-01-05 00:00:14                                  Service Control Manager         7036:  "     "    .  
                        2002-01-05 00:00:14                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:00:14                                  Service Control Manager         7036:  "Windows Driver Foundation - User-mode Driver Framework"    .  
                        2002-01-05 00:00:15                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:00:15                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-05 00:00:15                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-05 00:00:15                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-05 00:00:15                                  Service Control Manager         7036:  "  "    .  
                1101       2002-01-05 00:00:15                           Microsoft-Windows-Winlogon      7001:           
                4          2002-01-05 00:00:15  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-05 00:00:15  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-05 00:00:16                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 00:00:16                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 00:00:17                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:00:18                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 00:00:18                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 00:00:18                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 00:00:19                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:00:19                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-05 00:00:19                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:00:19                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 00:00:19                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-05 00:00:20                                  Service Control Manager         7036:  "    "    .  
                        2002-01-05 00:00:20                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 00:00:21                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:00:21                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:00:21                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:00:21                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:00:22                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:00:25                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 00:00:27                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-05 00:00:47                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-05 00:00:47                                  Service Control Manager         7036:  "  PNP-"    .  
                          2002-01-05 00:01:03  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-05 00:01:54                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:02:21                                  Service Control Manager         7036:  "    (BITS)"    .  
                        2002-01-05 00:02:22                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:02:22                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-05 00:02:23                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:02:23                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 00:02:24                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:02:26                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 00:02:51                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:06:48  user                            USER32                          1074:  Explorer.EXE   ""   USER-PC    user-PC\user  :  ()     : 0x0     :     :   
                        2002-01-05 00:06:51  user                            USER32                          1074:  C:\Windows\system32\winlogon.exe (USER-PC)   ""   USER-PC    user-PC\user  :        : 0x500ff     :     :   
                1102       2002-01-05 00:06:51                           Microsoft-Windows-Winlogon      7002:           
                        2002-01-05 00:06:53                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 00:06:54                                  EventLog                        6006:    .  
                        2002-01-05 00:06:54                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 00:06:54                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:06:54                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:06:54                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:06:54                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-05 00:06:54                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 00:06:54                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:06:54                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-05 00:06:54                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:06:54                                  Service Control Manager         7036:  "     "    .  
                        2002-01-05 00:06:54                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 00:06:54                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:06:54                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-05 00:06:54                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-05 00:06:54                                  Service Control Manager         7036:  "  PNP-"    .  
                        2002-01-05 00:06:54                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:06:54                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 00:06:54                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:06:54                                  Service Control Manager         7036:  "  Windows"    .  
                1          2002-01-05 00:06:54                           Microsoft-Windows-WindowsUpdateClient  27:   .  
                4          2002-01-05 00:06:54  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51047:   DHCPv6 .    : 1  
                4          2002-01-05 00:06:54  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50037:    DHCPv4.    : 1  
                7010       2002-01-05 00:06:54                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "false"      PlugPlay: "false"     
                        2002-01-05 00:06:55                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:06:55                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 00:06:55                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-05 00:06:55                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 00:06:55                                  Service Control Manager         7036:  "Windows Search"    .  
                103        2002-01-05 00:06:56                                  Microsoft-Windows-Kernel-Power  109:      .  
                        2002-01-05 00:06:59                                  Microsoft-Windows-Kernel-General  13:  .  
                        2002-01-05 00:07:23                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-05 00:07:27                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
                4          2002-01-05 00:07:31                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-05 00:07:31                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-05 00:07:39                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-05 00:07:39                                  EventLog                        6005:    .  
                        2002-01-05 00:07:39                                  EventLog                        6013:    16 .  
                        2002-01-05 00:07:39                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-05 00:07:39                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 00:07:39                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-05 00:07:39                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-05 00:07:39                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-05 00:07:39                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-05 00:07:39                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-05 00:07:40                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 00:07:40                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:07:41                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-05 00:07:41                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-05 00:07:41                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 00:07:41                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:07:41                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:07:41                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 00:07:41                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-05 00:07:41                                  Service Control Manager         7036:  "    "    .  
                        2002-01-05 00:07:41                                  Service Control Manager         7036:  "     "    .  
                        2002-01-05 00:07:41                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:07:41                                  Service Control Manager         7036:  "Windows Driver Foundation - User-mode Driver Framework"    .  
                        2002-01-05 00:07:41                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:07:41                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                4          2002-01-05 00:07:41  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-05 00:07:41  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-05 00:07:42                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-05 00:07:42                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-05 00:07:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:07:42                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 00:07:42                                  Service Control Manager         7036:  " "    .  
                1101       2002-01-05 00:07:42                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-05 00:07:44                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:07:44                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 00:07:44                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 00:07:45                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:07:45                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 00:07:45                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 00:07:45                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-05 00:07:45                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:07:46                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-05 00:07:47                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 00:07:47                                  Service Control Manager         7036:  "    "    .  
                        2002-01-05 00:07:47                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:07:48                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:07:48                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:07:48                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:07:48                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:07:48                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:07:54                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 00:07:56                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-05 00:09:15                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-05 00:09:15                                  Service Control Manager         7036:  "  PNP-"    .  
                          2002-01-05 00:09:29  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-05 00:09:47                                  Service Control Manager         7036:  "    (BITS)"    .  
                        2002-01-05 00:09:48                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-05 00:09:49                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:09:49                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:09:50                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 00:09:50                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:09:52                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 00:13:22                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:14:23                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:14:52                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:14:53  user                            USER32                          1074:  Explorer.EXE   ""   USER-PC    user-PC\user  :  ()     : 0x0     :     :   
                        2002-01-05 00:14:54                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:14:57  user                            USER32                          1074:  C:\Windows\system32\winlogon.exe (USER-PC)   ""   USER-PC    user-PC\user  :        : 0x500ff     :     :   
                1102       2002-01-05 00:14:57                           Microsoft-Windows-Winlogon      7002:           
                        2002-01-05 00:14:59                                  Service Control Manager         7036:  "  Windows"    .  
                1          2002-01-05 00:14:59                           Microsoft-Windows-WindowsUpdateClient  27:   .  
                        2002-01-05 00:15:00                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 00:15:00                                  EventLog                        6006:    .  
                        2002-01-05 00:15:00                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:15:00                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:15:00                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:15:00                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-05 00:15:00                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:15:00                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 00:15:00                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-05 00:15:00                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:15:00                                  Service Control Manager         7036:  "     "    .  
                        2002-01-05 00:15:00                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:15:00                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 00:15:00                                  Service Control Manager         7036:  "  PNP-"    .  
                        2002-01-05 00:15:00                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 00:15:00                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:15:00                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-05 00:15:00                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-05 00:15:00                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:15:00                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 00:15:00                                  Service Control Manager         7036:  " "    .  
                4          2002-01-05 00:15:00  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51047:   DHCPv6 .    : 1  
                4          2002-01-05 00:15:00  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50037:    DHCPv4.    : 1  
                7010       2002-01-05 00:15:00                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "false"      PlugPlay: "false"     
                        2002-01-05 00:15:01                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-05 00:15:01                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 00:15:01                                  Service Control Manager         7036:  "Windows Search"    .  
                103        2002-01-05 00:15:01                                  Microsoft-Windows-Kernel-Power  109:      .  
                        2002-01-05 00:15:04                                  Microsoft-Windows-Kernel-General  13:  .  
                        2002-01-05 00:15:35                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-05 00:15:39                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
                4          2002-01-05 00:15:43                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-05 00:15:43                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-05 00:15:51                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-05 00:15:51                                  EventLog                        6005:    .  
                        2002-01-05 00:15:51                                  EventLog                        6013:    16 .  
                        2002-01-05 00:15:51                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-05 00:15:51                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 00:15:51                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-05 00:15:51                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-05 00:15:51                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-05 00:15:51                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 00:15:51                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-05 00:15:51                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-05 00:15:52                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:15:52                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-05 00:15:52                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-05 00:15:53                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 00:15:53                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:15:53                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:15:53                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-05 00:15:53                                  Service Control Manager         7036:  "    "    .  
                        2002-01-05 00:15:53                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 00:15:53                                  Service Control Manager         7036:  "     "    .  
                        2002-01-05 00:15:53                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:15:53                                  Service Control Manager         7036:  "Windows Driver Foundation - User-mode Driver Framework"    .  
                        2002-01-05 00:15:53                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:15:53                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-05 00:15:53                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-05 00:15:53                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-05 00:15:53                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-05 00:15:53  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-05 00:15:53  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-05 00:15:54                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 00:15:54                                  Service Control Manager         7036:  " "    .  
                1101       2002-01-05 00:15:54                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-05 00:15:55                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:15:56                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 00:15:56                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 00:15:56                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 00:15:56                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:15:57                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 00:15:57                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:15:57                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-05 00:15:57                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-05 00:15:57                                  Service Control Manager         7036:  "    "    .  
                        2002-01-05 00:15:58                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:15:58                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 00:15:59                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:15:59                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:15:59                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:15:59                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:16:04                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 00:16:05                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-05 00:17:59                                  Service Control Manager         7036:  "    (BITS)"    .  
                        2002-01-05 00:17:59                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-05 00:17:59                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:18:00                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-05 00:18:00                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:18:01                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 00:18:01                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:18:03                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 00:21:05                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:23:02                                  Service Control Manager         7036:  "  "    .  
                          2002-01-05 00:23:41  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-05 00:25:38  user                            USER32                          1074:  Explorer.EXE   " "   USER-PC    user-PC\user  :  ()     : 0x0     :      :   
                        2002-01-05 00:25:39                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:25:40                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:25:41  user                            USER32                          1074:  C:\Windows\system32\winlogon.exe (USER-PC)   " "   USER-PC    user-PC\user  :        : 0x500ff     :      :   
                1102       2002-01-05 00:25:41                           Microsoft-Windows-Winlogon      7002:           
                        2002-01-05 00:25:43                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 00:25:44                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 00:25:44                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:25:44                                  EventLog                        6006:    .  
                        2002-01-05 00:25:44                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:25:44                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:25:44                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-05 00:25:44                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:25:44                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 00:25:44                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-05 00:25:44                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:25:44                                  Service Control Manager         7036:  "     "    .  
                        2002-01-05 00:25:44                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 00:25:44                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:25:44                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-05 00:25:44                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 00:25:44                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 00:25:44                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 00:25:44                                  Service Control Manager         7036:  "  Windows"    .  
                1          2002-01-05 00:25:44                           Microsoft-Windows-WindowsUpdateClient  27:   .  
                4          2002-01-05 00:25:44  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51047:   DHCPv6 .    : 1  
                4          2002-01-05 00:25:44  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50037:    DHCPv4.    : 1  
                7010       2002-01-05 00:25:44                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "false"      PlugPlay: "false"     
                        2002-01-05 00:25:45                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-05 00:25:45                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-05 00:25:45                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 00:25:45                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 00:25:45                                  Service Control Manager         7036:  "Windows Search"    .  
                103        2002-01-05 00:25:45                                  Microsoft-Windows-Kernel-Power  109:      .  
                        2002-01-05 00:25:49                                  Microsoft-Windows-Kernel-General  13:  .  
                        2002-01-05 01:48:08                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-05 01:48:12                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
                4          2002-01-05 01:48:15                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-05 01:48:15                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-05 01:48:23                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-05 01:48:23                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 01:48:23                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-05 01:48:23                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-05 01:48:23                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-05 01:48:23                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-05 01:48:23                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-05 01:48:24                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-05 01:48:24                                  EventLog                        6005:    .  
                        2002-01-05 01:48:24                                  EventLog                        6013:    15 .  
                        2002-01-05 01:48:24                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 01:48:24                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 01:48:25                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-05 01:48:25                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-05 01:48:25                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 01:48:25                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 01:48:25                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 01:48:25                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 01:48:25                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-05 01:48:25                                  Service Control Manager         7036:  "    "    .  
                        2002-01-05 01:48:25                                  Service Control Manager         7036:  "     "    .  
                        2002-01-05 01:48:25                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 01:48:25                                  Service Control Manager         7036:  "Windows Driver Foundation - User-mode Driver Framework"    .  
                        2002-01-05 01:48:25                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-05 01:48:25                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 01:48:25                                  Service Control Manager         7036:  "DHCP-"    .  
                4          2002-01-05 01:48:25  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-05 01:48:25  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-05 01:48:26                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-05 01:48:26                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 01:48:26                                  Service Control Manager         7036:  " "    .  
                1101       2002-01-05 01:48:26                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-05 01:48:27                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 01:48:29                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 01:48:30                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 01:48:30                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 01:48:30                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 01:48:30                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 01:48:31                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-05 01:48:31                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 01:48:31                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 01:48:31                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-05 01:48:31                                  Service Control Manager         7036:  "    "    .  
                        2002-01-05 01:48:32                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 01:48:33                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 01:48:33                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 01:48:33                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 01:48:34                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 01:48:34                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 01:48:39                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 01:48:41                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-05 01:50:33                                  Service Control Manager         7036:  "    (BITS)"    .  
                        2002-01-05 01:50:33                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-05 01:50:34                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 01:50:34                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-05 01:50:34                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 01:50:35                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 01:50:35                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 01:50:38                                  Service Control Manager         7036:  "  Windows"    .  
                          2002-01-05 01:51:15  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-05 01:51:20                                  Service Control Manager         7036:  "    "    .  
                        2002-01-05 01:51:20                           Microsoft-Windows-Application-Experience  201:       .  
                        2002-01-05 01:51:24                           Microsoft-Windows-Application-Experience  206:          .  
                        2002-01-05 01:51:33                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-05 01:52:48                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 01:52:48                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 01:52:53                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 01:52:53                                  Service Control Manager         7036:  "    (Microsoft)"    .  
                        2002-01-05 01:53:32                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 01:53:33                                  Service Control Manager         7036:  "   Windows"    .  
                7005       2002-01-05 01:54:15                           Microsoft-Windows-UserPnp       20001:       FileRepository\volsnap.inf_x86_neutral_42f862e05fcb0306\volsnap.inf      STORAGE\VOLUMESNAPSHOT\HARDDISKVOLUMESNAPSHOT1   : 0x0.  
                        2002-01-05 01:55:10  user                            USER32                          1074:  Explorer.EXE   " "   USER-PC    user-PC\user  :  ()     : 0x0     :      :   
                        2002-01-05 01:55:14  user                            USER32                          1074:  C:\Windows\system32\winlogon.exe (USER-PC)   " "   USER-PC    user-PC\user  :        : 0x500ff     :      :   
                1102       2002-01-05 01:55:14                           Microsoft-Windows-Winlogon      7002:           
                        2002-01-05 01:55:15                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 01:55:16                                  EventLog                        6006:    .  
                        2002-01-05 01:55:16                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 01:55:16                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 01:55:16                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 01:55:16                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 01:55:16                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 01:55:16                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 01:55:16                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 01:55:16                                  Service Control Manager         7036:  "     "    .  
                        2002-01-05 01:55:16                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-05 01:55:16                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 01:55:16                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 01:55:16                                  Service Control Manager         7036:  "    (Microsoft)"    .  
                        2002-01-05 01:55:16                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-05 01:55:16                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 01:55:16                                  Service Control Manager         7036:  "  "    .  
                1          2002-01-05 01:55:16                           Microsoft-Windows-WindowsUpdateClient  27:   .  
                4          2002-01-05 01:55:16  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51047:   DHCPv6 .    : 1  
                4          2002-01-05 01:55:16  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50037:    DHCPv4.    : 1  
                        2002-01-05 01:55:17                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 01:55:17                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-05 01:55:17                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-05 01:55:17                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 01:55:17                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 01:55:17                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 01:55:17                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 01:55:17                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-05 01:55:17                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 01:55:17                                  Service Control Manager         7036:  "  Windows"    .  
                7010       2002-01-05 01:55:17                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "false"      PlugPlay: "false"     
                        2002-01-05 01:55:18                                  Service Control Manager         7036:  "Windows Search"    .  
                103        2002-01-05 01:55:18                                  Microsoft-Windows-Kernel-Power  109:      .  
                        2002-01-05 01:55:22                                  Microsoft-Windows-Kernel-General  13:  .  
                        2002-01-05 19:34:15                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-05 19:34:18                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
                4          2002-01-05 19:34:22                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-05 19:34:22                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-05 19:34:32                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-05 19:34:32                                  Service Control Manager         7036:  ""    .  
                7010       2002-01-05 19:34:32                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-05 19:34:33                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-05 19:34:33                                  EventLog                        6005:    .  
                        2002-01-05 19:34:33                                  EventLog                        6013:    18 .  
                        2002-01-05 19:34:33                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-05 19:34:33                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-05 19:34:33                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-05 19:34:33                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 19:34:33                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                        2002-01-05 19:34:34                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 19:34:34                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-05 19:34:34                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-05 19:34:34                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 19:34:34                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 19:34:35                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 19:34:35                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 19:34:35                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-05 19:34:35                                  Service Control Manager         7036:  "    "    .  
                        2002-01-05 19:34:35                                  Service Control Manager         7036:  "     "    .  
                        2002-01-05 19:34:35                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 19:34:35                                  Service Control Manager         7036:  "Windows Driver Foundation - User-mode Driver Framework"    .  
                        2002-01-05 19:34:35                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-05 19:34:35                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 19:34:35                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-05 19:34:35                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-05 19:34:35                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-05 19:34:35  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-05 19:34:35  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-05 19:34:36                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 19:34:36                                  Service Control Manager         7036:  " "    .  
                1101       2002-01-05 19:34:36                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-05 19:34:38                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 19:34:38                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 19:34:39                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 19:34:39                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 19:34:39                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 19:34:40                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-05 19:34:40                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 19:34:40                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 19:34:40                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-05 19:34:40                                  Service Control Manager         7036:  "    "    .  
                        2002-01-05 19:34:41                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 19:34:41                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 19:34:41                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 19:34:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 19:34:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 19:34:42                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 19:34:48                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 19:34:50                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-05 19:36:41                                  Service Control Manager         7036:  "    (BITS)"    .  
                        2002-01-05 19:36:42                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 19:36:42                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-05 19:36:42                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-05 19:36:43                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 19:36:44                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 19:36:44                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 19:36:47                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 19:39:47                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 19:41:45                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 19:47:38                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 19:51:47                                  Service Control Manager         7036:  "   - WinHTTP"    .  
                          2002-01-05 19:54:20  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-05 19:56:55                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 20:04:33  user                            USER32                          1074:  Explorer.EXE   " "   USER-PC    user-PC\user  :  ()     : 0x0     :      :   
                        2002-01-05 20:04:34                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 20:04:37  user                            USER32                          1074:  C:\Windows\system32\winlogon.exe (USER-PC)   " "   USER-PC    user-PC\user  :        : 0x500ff     :      :   
                1102       2002-01-05 20:04:37                           Microsoft-Windows-Winlogon      7002:           
                        2002-01-05 20:04:39                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 20:04:39                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 20:04:39                                  Service Control Manager         7036:  "  "    .  
                1          2002-01-05 20:04:39                           Microsoft-Windows-WindowsUpdateClient  27:   .  
                        2002-01-05 20:04:40                                  EventLog                        6006:    .  
                        2002-01-05 20:04:40                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 20:04:40                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 20:04:40                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 20:04:40                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 20:04:40                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-05 20:04:40                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-05 20:04:40                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 20:04:40                                  Service Control Manager         7036:  "     "    .  
                        2002-01-05 20:04:40                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 20:04:40                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 20:04:40                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-05 20:04:40                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-05 20:04:40                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 20:04:40                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 20:04:40                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 20:04:40                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 20:04:40                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 20:04:40                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-05 20:04:40                                  Service Control Manager         7036:  "  Windows"    .  
                4          2002-01-05 20:04:40  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51047:   DHCPv6 .    : 1  
                4          2002-01-05 20:04:40  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50037:    DHCPv4.    : 1  
                7010       2002-01-05 20:04:40                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "false"      PlugPlay: "false"     
                        2002-01-05 20:04:41                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 20:04:41                                  Service Control Manager         7036:  "Windows Search"    .  
                103        2002-01-05 20:04:41                                  Microsoft-Windows-Kernel-Power  109:      .  
                        2002-01-05 20:04:44                                  Microsoft-Windows-Kernel-General  13:  .  
                        2002-01-05 21:44:41                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-05 21:44:45                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
                4          2002-01-05 21:44:50                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-05 21:44:50                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-05 21:44:59                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-05 21:44:59                                  EventLog                        6005:    .  
                        2002-01-05 21:44:59                                  EventLog                        6013:    18 .  
                        2002-01-05 21:44:59                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-05 21:44:59                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 21:44:59                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-05 21:44:59                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-05 21:44:59                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-05 21:44:59                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 21:44:59                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-05 21:44:59                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-05 21:45:00                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:45:00                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-05 21:45:01                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-05 21:45:01                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:45:01                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-05 21:45:02                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 21:45:02                                  Service Control Manager         7036:  "    "    .  
                        2002-01-05 21:45:02                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:45:02                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:45:02                                  Service Control Manager         7036:  "     "    .  
                        2002-01-05 21:45:02                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:45:02                                  Service Control Manager         7036:  "Windows Driver Foundation - User-mode Driver Framework"    .  
                        2002-01-05 21:45:02                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:45:02                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-05 21:45:02                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-05 21:45:02                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-05 21:45:02                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-05 21:45:02  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-05 21:45:02  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-05 21:45:03                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:45:03                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:45:04                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:45:04                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 21:45:04                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:45:04                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:45:04                                  Service Control Manager         7036:  "Superfetch"    .  
                1101       2002-01-05 21:45:04                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-05 21:45:05                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:45:05                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:45:05                                  Service Control Manager         7036:  "    "    .  
                        2002-01-05 21:45:05                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:45:06                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 21:45:06                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-05 21:45:07                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 21:45:07                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:45:07                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:45:07                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:45:08                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:45:21                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:45:22                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-05 21:46:42                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-05 21:46:46                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
          Unknown         63         2002-01-05 21:46:50                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                4          2002-01-05 21:46:51                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-05 21:46:51                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-05 21:47:00                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-05 21:47:00                                  EventLog                        6005:    .  
                        2002-01-05 21:47:00                                  EventLog                        6013:    18 .  
                        2002-01-05 21:47:00                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-05 21:47:00                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 21:47:00                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-05 21:47:00                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-05 21:47:00                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-05 21:47:00                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 21:47:00                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-05 21:47:00                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-05 21:47:01                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:47:02                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-05 21:47:02                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-05 21:47:02                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:47:03                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-05 21:47:04                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 21:47:04                                  Service Control Manager         7036:  "    "    .  
                        2002-01-05 21:47:04                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:47:04                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:47:04                                  Service Control Manager         7036:  "     "    .  
                        2002-01-05 21:47:04                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:47:04                                  Service Control Manager         7036:  "Windows Driver Foundation - User-mode Driver Framework"    .  
                        2002-01-05 21:47:04                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:47:04                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-05 21:47:04                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-05 21:47:04                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-05 21:47:04                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-05 21:47:04  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-05 21:47:04  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                1101       2002-01-05 21:47:06                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-05 21:47:07                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:47:07                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:47:08                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:47:09                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 21:47:09                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:47:09                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-05 21:47:09                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:47:09                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:47:10                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 21:47:10                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:47:10                                  Service Control Manager         7036:  "    "    .  
                        2002-01-05 21:47:10                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-05 21:47:10                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 21:47:11                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:47:11                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:47:12                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:47:12                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:47:12                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:47:20                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:47:22                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-05 21:47:49  user                            USER32                          1074:  C:\Windows\system32\winlogon.exe (USER-PC)   " "   USER-PC    user-PC\user  :        : 0x500ff     :      :   
                1102       2002-01-05 21:47:49                           Microsoft-Windows-Winlogon      7002:           
                        2002-01-05 21:47:51                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:47:51                                  EventLog                        6006:    .  
                        2002-01-05 21:47:51                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:47:51                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 21:47:51                                  Service Control Manager         7036:  "     "    .  
                        2002-01-05 21:47:51                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:47:51                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:47:51                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-05 21:47:51                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:47:51                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:47:51                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 21:47:51                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 21:47:51                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:47:51                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:47:51                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                4          2002-01-05 21:47:51  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51047:   DHCPv6 .    : 1  
                4          2002-01-05 21:47:51  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50037:    DHCPv4.    : 1  
                7010       2002-01-05 21:47:51                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "false"      PlugPlay: "false"     
                        2002-01-05 21:47:52                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-05 21:47:52                                  Service Control Manager         7036:  "Superfetch"    .  
                103        2002-01-05 21:47:52                                  Microsoft-Windows-Kernel-Power  109:      .  
                        2002-01-05 21:47:59                                  Microsoft-Windows-Kernel-General  13:  .  
                        2002-01-05 21:48:32                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-05 21:48:36                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
                4          2002-01-05 21:48:41                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-05 21:48:41                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-05 21:48:50                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-05 21:48:50                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 21:48:50                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-05 21:48:50                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-05 21:48:50                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-05 21:48:50                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-05 21:48:50                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-05 21:48:51                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-05 21:48:51                                  EventLog                        6005:    .  
                        2002-01-05 21:48:51                                  EventLog                        6013:    18 .  
                        2002-01-05 21:48:51                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 21:48:51                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:48:52                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-05 21:48:52                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-05 21:48:52                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 21:48:53                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-05 21:48:53                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:48:53                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:48:53                                  Service Control Manager         7036:  "    "    .  
                        2002-01-05 21:48:53                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:48:53                                  Service Control Manager         7036:  "     "    .  
                        2002-01-05 21:48:53                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:48:53                                  Service Control Manager         7036:  "Windows Driver Foundation - User-mode Driver Framework"    .  
                        2002-01-05 21:48:53                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:48:53                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-05 21:48:53                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-05 21:48:53                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-05 21:48:53                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-05 21:48:53  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-05 21:48:53  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-05 21:48:54                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:48:54                                  Service Control Manager         7036:  " "    .  
                1101       2002-01-05 21:48:54                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-05 21:48:55                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:48:55                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 21:48:55                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:48:55                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-05 21:48:55                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:48:55                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:48:56                                  Service Control Manager         7036:  "    "    .  
                        2002-01-05 21:48:57                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 21:48:57                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:48:57                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-05 21:48:58                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 21:48:58                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:48:58                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:48:58                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:48:59                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:48:59                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:49:08                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:49:10                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-05 21:50:09                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-05 21:50:13                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
          Unknown         63         2002-01-05 21:50:17                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                4          2002-01-05 21:50:18                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-05 21:50:18                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-05 21:50:27                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-05 21:50:27                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 21:50:27                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-05 21:50:27                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-05 21:50:27                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-05 21:50:27                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-05 21:50:27                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-05 21:50:28                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-05 21:50:28                                  EventLog                        6005:    .  
                        2002-01-05 21:50:28                                  EventLog                        6013:    18 .  
                        2002-01-05 21:50:28                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 21:50:28                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:50:29                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-05 21:50:29                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-05 21:50:30                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:50:30                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-05 21:50:31                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 21:50:31                                  Service Control Manager         7036:  "    "    .  
                        2002-01-05 21:50:31                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:50:31                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:50:31                                  Service Control Manager         7036:  "     "    .  
                        2002-01-05 21:50:31                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:50:31                                  Service Control Manager         7036:  "Windows Driver Foundation - User-mode Driver Framework"    .  
                        2002-01-05 21:50:31                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:50:31                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-05 21:50:31                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-05 21:50:31                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-05 21:50:31                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-05 21:50:31  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-05 21:50:31  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-05 21:50:33                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:50:34                                  Service Control Manager         7036:  " "    .  
                1101       2002-01-05 21:50:34                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-05 21:50:35                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:50:35                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 21:50:35                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:50:35                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:50:36                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:50:36                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-05 21:50:36                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:50:36                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 21:50:37                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-05 21:50:37                                  Service Control Manager         7036:  "    "    .  
                        2002-01-05 21:50:38                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 21:50:38                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:50:38                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:50:38                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:50:38                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:50:39                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:50:48                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 21:50:51                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-05 21:51:07                                  Service Control Manager         7036:  "    "    .  
                        2002-01-05 21:51:07                           Microsoft-Windows-Application-Experience  201:       .  
                          2002-01-05 21:51:17  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-05 21:52:39                                  Service Control Manager         7036:  "    (BITS)"    .  
                        2002-01-05 21:52:39                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 21:52:40                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-05 21:52:42                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-05 21:52:43                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:52:46                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 21:52:47                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 21:52:51                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 21:57:51                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 22:07:55                                  Service Control Manager         7036:  "   - WinHTTP"    .  
                        2002-01-05 22:30:36                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 22:31:56  user                            USER32                          1074:  Explorer.EXE   " "   USER-PC    user-PC\user  :  ()     : 0x0     :      :   
                        2002-01-05 22:31:59                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 22:32:03  user                            USER32                          1074:  C:\Windows\system32\winlogon.exe (USER-PC)   " "   USER-PC    user-PC\user  :        : 0x500ff     :      :   
                1102       2002-01-05 22:32:03                           Microsoft-Windows-Winlogon      7002:           
                        2002-01-05 22:32:06                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 22:32:07                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 22:32:07                                  Service Control Manager         7036:  "  "    .  
                1          2002-01-05 22:32:07                           Microsoft-Windows-WindowsUpdateClient  27:   .  
                        2002-01-05 22:32:08                                  Service Control Manager         7036:  ""    .  
                        2002-01-05 22:32:08                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 22:32:08                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 22:32:08                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 22:32:08                                  Service Control Manager         7036:  "DHCP-"    .  
                4          2002-01-05 22:32:08  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51047:   DHCPv6 .    : 1  
                4          2002-01-05 22:32:08  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50037:    DHCPv4.    : 1  
                        2002-01-05 22:32:09                                  EventLog                        6006:    .  
                        2002-01-05 22:32:09                                  Service Control Manager         7036:  "     "    .  
                        2002-01-05 22:32:09                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-05 22:32:09                                  Service Control Manager         7036:  "   "    .  
                        2002-01-05 22:32:09                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-05 22:32:09                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-05 22:32:09                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-05 22:32:09                                  Service Control Manager         7036:  "  "    .  
                        2002-01-05 22:32:09                                  Service Control Manager         7036:  "  Windows"    .  
                7010       2002-01-05 22:32:09                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "false"      PlugPlay: "false"     
                        2002-01-05 22:32:10                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-05 22:32:10                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 22:32:10                                  Service Control Manager         7036:  " "    .  
                        2002-01-05 22:32:10                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-05 22:32:11                                  Service Control Manager         7036:  "   "    .  
                103        2002-01-05 22:32:13                                  Microsoft-Windows-Kernel-Power  109:      .  
                        2002-01-05 22:32:17                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-05 22:32:19                                  Microsoft-Windows-Kernel-General  13:  .  
                        2002-01-06 00:49:09                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-06 00:49:13                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
                4          2002-01-06 00:49:17                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-06 00:49:17                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-06 00:49:25                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-06 00:49:25                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 00:49:25                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-06 00:49:25                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-06 00:49:25                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-06 00:49:25                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-06 00:49:25                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-06 00:49:26                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-06 00:49:26                                  EventLog                        6005:    .  
                        2002-01-06 00:49:26                                  EventLog                        6013:    16 .  
                        2002-01-06 00:49:26                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 00:49:26                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 00:49:27                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-06 00:49:27                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-06 00:49:27                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 00:49:27                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 00:49:27                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 00:49:27                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-06 00:49:27                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 00:49:27                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 00:49:27                                  Service Control Manager         7036:  "     "    .  
                        2002-01-06 00:49:27                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:00:53                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-06 01:00:57                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
                4          2002-01-06 01:01:01                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-06 01:01:01                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
          Unknown         63         2002-01-06 01:01:01                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                        2002-01-06 01:01:09                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-06 01:01:09                                  Service Control Manager         7036:  ""    .  
                7010       2002-01-06 01:01:09                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-06 01:01:10                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-06 01:01:10                                  EventLog                        6005:    .  
                        2002-01-06 01:01:10                                  EventLog                        6013:    17 .  
                        2002-01-06 01:01:10                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-06 01:01:10                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-06 01:01:10                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-06 01:01:10                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 01:01:10                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                            2002-01-06 01:01:11                                  BugCheck                        
                        2002-01-06 01:01:11                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:01:11                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-06 01:01:12                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-06 01:01:12                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 01:01:12                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:01:12                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:01:12                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-06 01:01:12                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 01:01:12                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:01:12                                  Service Control Manager         7036:  "     "    .  
                        2002-01-06 01:01:12                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:01:12                                  Service Control Manager         7036:  "Windows Driver Foundation - User-mode Driver Framework"    .  
                        2002-01-06 01:01:12                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-06 01:01:12                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:01:12                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-06 01:01:12                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-06 01:01:12                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-06 01:01:12  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-06 01:01:12  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-06 01:01:13                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:01:13                                  Service Control Manager         7036:  " "    .  
                1101       2002-01-06 01:01:13                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-06 01:01:14                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:01:15                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-06 01:01:16                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:01:16                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:01:16                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:01:16                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-06 01:01:16                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:01:16                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 01:01:16                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 01:01:16                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-06 01:01:17                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 01:01:17                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:01:17                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:01:17                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:01:17                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:01:17                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:01:17                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:01:26                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:01:29                                  Service Control Manager         7036:  "Windows Search"    .  
                          2002-01-06 01:02:01  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-06 01:02:16                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:04:24                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-06 01:04:28                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
          Unknown         63         2002-01-06 01:04:31                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                4          2002-01-06 01:04:32                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-06 01:04:32                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-06 01:04:40                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-06 01:04:40                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 01:04:40                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-06 01:04:40                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-06 01:04:40                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-06 01:04:40                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                            2002-01-06 01:04:41                                  EventLog                        6008:      1:03:01  ?06.?01.?2002  .  
                        2002-01-06 01:04:41                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-06 01:04:41                                  EventLog                        6005:    .  
                        2002-01-06 01:04:41                                  EventLog                        6013:    17 .  
                        2002-01-06 01:04:41                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-06 01:04:41                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 01:04:41                                  Service Control Manager         7036:  "  "    .  
                            2002-01-06 01:04:42                                  BugCheck                        
                        2002-01-06 01:04:42                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-06 01:04:42                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-06 01:04:42                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 01:04:43                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:04:43                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:04:43                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-06 01:04:43                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 01:04:43                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:04:43                                  Service Control Manager         7036:  "     "    .  
                        2002-01-06 01:04:43                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:04:43                                  Service Control Manager         7036:  "Windows Driver Foundation - User-mode Driver Framework"    .  
                        2002-01-06 01:04:43                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-06 01:04:43                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:04:43                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-06 01:04:43                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-06 01:04:43                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:04:43                                  Service Control Manager         7036:  " "    .  
                4          2002-01-06 01:04:43  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-06 01:04:43  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-06 01:04:44                                  Service Control Manager         7036:  " "    .  
                1101       2002-01-06 01:04:44                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-06 01:04:45                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:04:46                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-06 01:04:47                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:04:47                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:04:47                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:04:47                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-06 01:04:47                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:04:47                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 01:04:47                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 01:04:47                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-06 01:04:48                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 01:04:48                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:04:48                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:04:48                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:04:48                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:04:48                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:04:48                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:04:57                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:05:00                                  Service Control Manager         7036:  "Windows Search"    .  
                          2002-01-06 01:05:33  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-06 01:06:48                                  Service Control Manager         7036:  "    (BITS)"    .  
                        2002-01-06 01:06:48                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:06:48                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-06 01:06:49                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-06 01:06:49                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:06:50                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-06 01:06:50                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:06:52                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 01:07:45                                  Service Control Manager         7036:  "  PNP-"    .  
                        2002-01-06 01:07:56                                  Service Control Manager         7036:  "   "    .  
                          2002-01-06 01:09:32  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                          2002-01-06 01:11:32  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-06 01:11:52                                  Service Control Manager         7036:  "  "    .  
                          2002-01-06 01:12:32  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-06 01:14:39                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-06 01:14:43                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
          Unknown         63         2002-01-06 01:14:45                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                4          2002-01-06 01:14:49                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-06 01:14:49                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-06 01:15:00                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-06 01:15:00                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 01:15:00                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-06 01:15:00                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                            2002-01-06 01:15:01                                  EventLog                        6008:      1:13:31  ?06.?01.?2002  .  
                        2002-01-06 01:15:01                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-06 01:15:01                                  EventLog                        6005:    .  
                        2002-01-06 01:15:01                                  EventLog                        6013:    22 .  
                        2002-01-06 01:15:01                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-06 01:15:01                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-06 01:15:01                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-06 01:15:01                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 01:15:02                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:15:02                                  Service Control Manager         7036:  "    Windows Audio"    .  
                            2002-01-06 01:15:03                                  BugCheck                        
                        2002-01-06 01:15:03                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-06 01:15:03                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 01:15:04                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-06 01:15:04                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:15:04                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 01:15:04                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:15:04                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:15:04                                  Service Control Manager         7036:  "     "    .  
                        2002-01-06 01:15:04                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:15:04                                  Service Control Manager         7036:  "Windows Driver Foundation - User-mode Driver Framework"    .  
                        2002-01-06 01:15:04                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:15:04                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-06 01:15:04                                  Service Control Manager         7036:  "DHCP-"    .  
                4          2002-01-06 01:15:04  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-06 01:15:04  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-06 01:15:05                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-06 01:15:05                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:15:05                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:15:07                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:15:07                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:15:08                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-06 01:15:08                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:15:08                                  Service Control Manager         7036:  "  "    .  
                1101       2002-01-06 01:15:08                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-06 01:15:09                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:15:10                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-06 01:15:10                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:15:10                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 01:15:11                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 01:15:12                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:15:12                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-06 01:15:13                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 01:15:14                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:15:14                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:15:15                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:15:15                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:15:15                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:15:15  user                            USER32                          1074:  C:\Windows\system32\winlogon.exe (USER-PC)   " "   USER-PC    user-PC\user  :        : 0x500ff     :      :   
                1102       2002-01-06 01:15:15                           Microsoft-Windows-Winlogon      7002:           
                        2002-01-06 01:15:16                                  EventLog                        6006:    .  
                        2002-01-06 01:15:16                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:15:16                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-06 01:15:16                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 01:15:16                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:15:16                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:15:16                                  Service Control Manager         7036:  "     "    .  
                        2002-01-06 01:15:16                                  Service Control Manager         7036:  "   "    .  
                4          2002-01-06 01:15:16  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51047:   DHCPv6 .    : 1  
                4          2002-01-06 01:15:16  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50037:    DHCPv4.    : 1  
                        2002-01-06 01:17:03                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-06 01:17:07                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
          Unknown         63         2002-01-06 01:17:10                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                4          2002-01-06 01:17:14                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-06 01:17:14                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-06 01:17:24                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-06 01:17:24                                  Service Control Manager         7036:  ""    .  
                7010       2002-01-06 01:17:24                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-06 01:17:25                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-06 01:17:25                                  EventLog                        6005:    .  
                        2002-01-06 01:17:25                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-06 01:17:25                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-06 01:17:25                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-06 01:17:25                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                        2002-01-06 01:17:26                                  EventLog                        6013:    22 .  
                        2002-01-06 01:17:26                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 01:17:26                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:17:27                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-06 01:17:27                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-06 01:17:28                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 01:17:28                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:17:28                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:17:28                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-06 01:17:28                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 01:17:28                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:17:28                                  Service Control Manager         7036:  "     "    .  
                        2002-01-06 01:17:28                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:17:28                                  Service Control Manager         7036:  "Windows Driver Foundation - User-mode Driver Framework"    .  
                        2002-01-06 01:17:28                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:17:28                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-06 01:17:29                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-06 01:17:29                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-06 01:17:29                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-06 01:17:29  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-06 01:17:29  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-06 01:17:30                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:17:31                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:17:32                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:17:32                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-06 01:17:32                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:17:32                                  Service Control Manager         7036:  "  "    .  
                1101       2002-01-06 01:17:32                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-06 01:17:34                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:17:34                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 01:17:34                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-06 01:17:34                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:17:35                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 01:17:35                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:17:36                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-06 01:17:37                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 01:17:38                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:17:38                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:17:38                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:17:38                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:17:38                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:17:48                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:17:54                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:18:54                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-06 01:18:58                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
          Unknown         63         2002-01-06 01:19:00                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                4          2002-01-06 01:19:04                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-06 01:19:04                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-06 01:19:14                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                7010       2002-01-06 01:19:14                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-06 01:19:15                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 01:19:15                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-06 01:19:15                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-06 01:19:15                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-06 01:19:15                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                        2002-01-06 01:19:16                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-06 01:19:16                                  EventLog                        6005:    .  
                        2002-01-06 01:19:16                                  EventLog                        6013:    21 .  
                        2002-01-06 01:19:16                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 01:19:16                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:19:17                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-06 01:19:18                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-06 01:19:18                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 01:19:18                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:19:18                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:19:18                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:19:18                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-06 01:19:18                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 01:19:18                                  Service Control Manager         7036:  "     "    .  
                        2002-01-06 01:19:18                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:19:18                                  Service Control Manager         7036:  "Windows Driver Foundation - User-mode Driver Framework"    .  
                        2002-01-06 01:19:19                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:19:19                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-06 01:19:19                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-06 01:19:19                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-06 01:19:19                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-06 01:19:19  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-06 01:19:19  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-06 01:19:20                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:19:21                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:19:22                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:19:22                                  Service Control Manager         7036:  " Windows"    .  
                1101       2002-01-06 01:19:22                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-06 01:19:23                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:19:23                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:19:24                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:19:24                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-06 01:19:24                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 01:19:24                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:19:25                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 01:19:26                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-06 01:19:26                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:19:27                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 01:19:28                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:19:28                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:19:28                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:19:29                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:19:29                                  Service Control Manager         7036:  "  "    .  
                7005       2002-01-06 01:19:42                           Microsoft-Windows-UserPnp       20003:       tunnel      ROOT\*ISATAP\0001   : 0.  
                        2002-01-06 01:19:46                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:19:47                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:19:49                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-06 01:20:31                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:20:39                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-06 01:20:39                                  Service Control Manager         7036:  "  PNP-"    .  
                        2002-01-06 01:21:28                                  Service Control Manager         7036:  "    (BITS)"    .  
                        2002-01-06 01:21:28                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:21:29                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-06 01:21:30                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:21:31                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-06 01:21:31                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:21:33                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 01:24:44                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-06 01:24:48                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
          Unknown         63         2002-01-06 01:24:51                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                4          2002-01-06 01:24:55                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-06 01:24:55                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-06 01:25:06                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-06 01:25:06                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 01:25:06                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-06 01:25:06                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-06 01:25:06                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-06 01:25:06                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-06 01:25:06                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                            2002-01-06 01:25:07                                  EventLog                        6008:      1:23:00  ?06.?01.?2002  .  
                        2002-01-06 01:25:07                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-06 01:25:07                                  EventLog                        6005:    .  
                        2002-01-06 01:25:07                                  EventLog                        6013:    22 .  
                        2002-01-06 01:25:07                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 01:25:07                                  Service Control Manager         7036:  "  "    .  
                            2002-01-06 01:25:08                                  BugCheck                        
                        2002-01-06 01:25:08                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-06 01:25:08                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-06 01:25:09                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 01:25:09                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:25:09                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:25:09                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-06 01:25:09                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 01:25:09                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:25:09                                  Service Control Manager         7036:  "     "    .  
                        2002-01-06 01:25:09                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:25:10                                  Service Control Manager         7036:  "Windows Driver Foundation - User-mode Driver Framework"    .  
                        2002-01-06 01:25:10                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:25:11                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-06 01:25:11                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-06 01:25:11                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-06 01:25:11                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-06 01:25:11  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-06 01:25:11  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-06 01:25:12                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:25:13                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:25:14                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:25:14                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-06 01:25:14                                  Service Control Manager         7036:  " "    .  
                1101       2002-01-06 01:25:14                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-06 01:25:15                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 01:25:15                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:25:17                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-06 01:25:17                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:25:17                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 01:25:17                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 01:25:18                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:25:19                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-06 01:25:20                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 01:25:21                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:25:21                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:25:21                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:25:21                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 01:25:21                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 01:25:24                                  Service Control Manager         7036:  " "    .  
                7005       2002-01-06 01:25:35                           Microsoft-Windows-UserPnp       20003:       tunnel      ROOT\*ISATAP\0001   : 0.  
                        2002-01-06 14:35:10                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-06 14:35:14                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
          Unknown         63         2002-01-06 14:35:16                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                4          2002-01-06 14:35:20                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-06 14:35:20                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-06 14:35:41                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-06 14:35:41                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 14:35:41                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-06 14:35:41                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-06 14:35:41                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-06 14:35:41                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-06 14:35:41                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                            2002-01-06 14:35:42                                  EventLog                        6008:      1:25:51  ?06.?01.?2002  .  
                        2002-01-06 14:35:42                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-06 14:35:42                                  EventLog                        6005:    .  
                        2002-01-06 14:35:42                                  EventLog                        6013:    32 .  
                        2002-01-06 14:35:42                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 14:35:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:35:44                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-06 14:35:44                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-06 14:35:45                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 14:35:45                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:35:45                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:35:45                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 14:35:45                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-06 14:35:45                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 14:35:45                                  Service Control Manager         7036:  "     "    .  
                        2002-01-06 14:35:45                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:35:45                                  Service Control Manager         7036:  "Windows Driver Foundation - User-mode Driver Framework"    .  
                        2002-01-06 14:35:46                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:35:46                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-06 14:35:46                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-06 14:35:46                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-06 14:35:46                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-06 14:35:46  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-06 14:35:46  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-06 14:35:47                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 14:35:49                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 14:35:49                                  Service Control Manager         7036:  "  "    .  
                1101       2002-01-06 14:35:49                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-06 14:35:50                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-06 14:35:50                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 14:35:51                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:35:52                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 14:35:52                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-06 14:35:53                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:35:53                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 14:35:53                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 14:35:55                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:35:55                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-06 14:35:56                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 14:35:56                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:35:56                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:35:57                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:35:57                                  Service Control Manager         7036:  "  "    .  
                7005       2002-01-06 14:36:08                           Microsoft-Windows-UserPnp       20003:       tunnel      ROOT\*ISATAP\0002   : 0.  
                        2002-01-06 14:36:11                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 14:36:12                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:36:13                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-06 14:36:17  user                            USER32                          1074:  C:\Windows\system32\winlogon.exe (USER-PC)   " "   USER-PC    user-PC\user  :        : 0x500ff     :      :   
                1102       2002-01-06 14:36:17                           Microsoft-Windows-Winlogon      7002:           
                          2002-01-06 14:36:17  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-06 14:36:18                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:36:19                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:36:20                                  EventLog                        6006:    .  
                        2002-01-06 14:36:20                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 14:36:20                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:36:20                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-06 14:36:20                                  Service Control Manager         7036:  "     "    .  
                        2002-01-06 14:36:20                                  Service Control Manager         7036:  "   "    .  
                4          2002-01-06 14:36:20  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51047:   DHCPv6 .    : 1  
                4          2002-01-06 14:36:20  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50037:    DHCPv4.    : 1  
                        2002-01-06 14:38:15                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-06 14:38:19                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
          Unknown         63         2002-01-06 14:38:23                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                4          2002-01-06 14:38:27                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-06 14:38:27                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-06 14:38:38                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-06 14:38:38                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 14:38:38                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-06 14:38:38                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-06 14:38:38                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-06 14:38:39                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-06 14:38:39                                  EventLog                        6005:    .  
                        2002-01-06 14:38:39                                  EventLog                        6013:    24 .  
                        2002-01-06 14:38:39                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-06 14:38:39                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-06 14:38:39                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 14:38:40                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:38:40                                  Service Control Manager         7036:  "    Windows Audio"    .  
                            2002-01-06 14:38:41                                  BugCheck                        
                        2002-01-06 14:38:41                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-06 14:38:41                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 14:38:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:38:42                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-06 14:38:42                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 14:38:42                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 14:38:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:38:42                                  Service Control Manager         7036:  "     "    .  
                        2002-01-06 14:38:42                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:38:42                                  Service Control Manager         7036:  "Windows Driver Foundation - User-mode Driver Framework"    .  
                        2002-01-06 14:38:43                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:38:43                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-06 14:38:43                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-06 14:38:43                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-06 14:38:43                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-06 14:38:43  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-06 14:38:43  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-06 14:38:44                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 14:38:45                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 14:38:46                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:38:46                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-06 14:38:46                                  Service Control Manager         7036:  " "    .  
                1101       2002-01-06 14:38:46                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-06 14:38:47                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 14:38:47                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:38:48                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-06 14:38:48                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:38:48                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 14:38:49                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 14:38:50                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-06 14:38:50                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:38:52                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 14:38:52                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:38:53                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:38:53                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:38:53                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:38:54                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:39:11                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 14:39:13                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-06 14:39:16                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:39:52                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 14:39:52                           Microsoft-Windows-Application-Experience  201:       .  
                        2002-01-06 14:40:07                           Microsoft-Windows-Application-Experience  206:          .  
                        2002-01-06 14:40:17  user                            USER32                          1074:  Explorer.EXE   ""   USER-PC    user-PC\user  :  ()     : 0x0     :     :   
                        2002-01-06 14:40:21  user                            USER32                          1074:  C:\Windows\system32\winlogon.exe (USER-PC)   ""   USER-PC    user-PC\user  :        : 0x500ff     :     :   
                1102       2002-01-06 14:40:21                           Microsoft-Windows-Winlogon      7002:           
                        2002-01-06 14:40:22                                  EventLog                        6006:    .  
                        2002-01-06 14:40:22                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:40:22                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:40:22                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-06 14:40:22                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 14:40:22                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:40:22                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-06 14:40:22                                  Service Control Manager         7036:  "     "    .  
                        2002-01-06 14:40:22                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:40:22                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:40:22                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:40:22                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:40:22                                  Service Control Manager         7036:  "  Windows"    .  
                4          2002-01-06 14:40:22  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51047:   DHCPv6 .    : 1  
                4          2002-01-06 14:40:22  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50037:    DHCPv4.    : 1  
                7010       2002-01-06 14:40:22                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "false"      PlugPlay: "false"     
                        2002-01-06 14:40:23                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 14:40:23                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 14:40:23                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-06 14:40:23                                  Service Control Manager         7036:  "Windows Search"    .  
                103        2002-01-06 14:40:23                                  Microsoft-Windows-Kernel-Power  109:      .  
                        2002-01-06 14:40:27                                  Microsoft-Windows-Kernel-General  13:  .  
                        2002-01-06 14:40:51                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-06 14:40:55                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
                4          2002-01-06 14:40:58                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-06 14:40:58                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
                        2002-01-06 14:41:06                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-06 14:41:06                                  EventLog                        6005:    .  
                        2002-01-06 14:41:06                                  EventLog                        6013:    15 .  
                        2002-01-06 14:41:06                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-06 14:41:06                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 14:41:06                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-06 14:41:06                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-06 14:41:06                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-06 14:41:06                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 14:41:06                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-06 14:41:06                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                        2002-01-06 14:41:07                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:41:07                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-06 14:41:08                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-06 14:41:08                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 14:41:08                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:41:08                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:41:08                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 14:41:08                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-06 14:41:08                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 14:41:08                                  Service Control Manager         7036:  "     "    .  
                        2002-01-06 14:41:08                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:41:08                                  Service Control Manager         7036:  "Windows Driver Foundation - User-mode Driver Framework"    .  
                        2002-01-06 14:41:08                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:41:08                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-06 14:41:08                                  Service Control Manager         7036:  "DHCP-"    .  
                4          2002-01-06 14:41:08  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-06 14:41:08  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-06 14:41:09                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-06 14:41:09                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:41:09                                  Service Control Manager         7036:  " "    .  
                1101       2002-01-06 14:41:09                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-06 14:41:10                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 14:41:11                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:41:11                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-06 14:41:11                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 14:41:11                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 14:41:12                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:41:12                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-06 14:41:12                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:41:12                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 14:41:12                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-06 14:41:13                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 14:41:13                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 14:41:14                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:41:15                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:41:15                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:41:15                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:41:15                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:41:22                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 14:41:24                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-06 14:41:49                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 14:41:49                           Microsoft-Windows-Application-Experience  201:       .  
                        2002-01-06 14:42:00                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:42:01                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:42:08                           Microsoft-Windows-Application-Experience  206:          .  
                        2002-01-06 14:42:34  user                            Service Control Manager         7045:    .     :  Lavalys EVEREST Kernel Driver    :  C:\Program Files\Everest\kerneld.wnt   :        :      :    
                        2002-01-06 14:43:14                                  Service Control Manager         7036:  "    (BITS)"    .  
                        2002-01-06 14:43:15                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-06 14:43:15                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-06 14:43:15                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:43:16                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:43:16                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-06 14:43:17                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:43:19                                  Service Control Manager         7036:  "  Windows"    .  
                7005       2002-01-06 14:46:01                           Microsoft-Windows-UserPnp       20003:       USBSTOR      USB\VID_4102&PID_1052\5&2C3B98B9&0&1   : 0.  
                7005       2002-01-06 14:46:01                           Microsoft-Windows-UserPnp       20001:       FileRepository\usbstor.inf_x86_neutral_c77d41a490bdc63d\usbstor.inf      USB\VID_4102&PID_1052\5&2C3B98B9&0&1   : 0x0.  
                7005       2002-01-06 14:46:06                           Microsoft-Windows-UserPnp       20003:       disk      USBSTOR\DISK&VEN_IRIVER&PROD_E150&REV_0100\6&35B20BB7&0&___K&0   : 0.  
                7005       2002-01-06 14:46:07                           Microsoft-Windows-UserPnp       20001:       FileRepository\disk.inf_x86_neutral_b431b61a11f8df6c\disk.inf      USBSTOR\DISK&VEN_IRIVER&PROD_E150&REV_0100\6&35B20BB7&0&___K&0   : 0x0.  
                        2002-01-06 14:46:08                                  Service Control Manager         7036:  "   "    .  
                7005       2002-01-06 14:46:10                           Microsoft-Windows-UserPnp       20003:       disk      USBSTOR\DISK&VEN_IRIVER&PROD_E150&REV_0100\6&35B20BB7&0&___K&1   : 0.  
                7005       2002-01-06 14:46:10                           Microsoft-Windows-UserPnp       20001:       FileRepository\disk.inf_x86_neutral_b431b61a11f8df6c\disk.inf      USBSTOR\DISK&VEN_IRIVER&PROD_E150&REV_0100\6&35B20BB7&0&___K&1   : 0x0.  
                7005       2002-01-06 14:46:13                           Microsoft-Windows-UserPnp       20003:       volsnap      STORAGE\VOLUME\_??_USBSTOR#DISK&VEN_IRIVER&PROD_E150&REV_0100#6&35B20BB7&0&___K&0#{53F56307-B6BF-11D0-94F2-00A0C91EFB8B}   : 0.  
                7005       2002-01-06 14:46:13                           Microsoft-Windows-UserPnp       20001:       FileRepository\volume.inf_x86_neutral_6dee0205881d1a1d\volume.inf      STORAGE\VOLUME\_??_USBSTOR#DISK&VEN_IRIVER&PROD_E150&REV_0100#6&35B20BB7&0&___K&0#{53F56307-B6BF-11D0-94F2-00A0C91EFB8B}   : 0x0.  
                7005       2002-01-06 14:46:15                           Microsoft-Windows-UserPnp       20003:       volsnap      STORAGE\VOLUME\_??_USBSTOR#DISK&VEN_IRIVER&PROD_E150&REV_0100#6&35B20BB7&0&___K&1#{53F56307-B6BF-11D0-94F2-00A0C91EFB8B}   : 0.  
                7005       2002-01-06 14:46:16                           Microsoft-Windows-UserPnp       20001:       FileRepository\volume.inf_x86_neutral_6dee0205881d1a1d\volume.inf      STORAGE\VOLUME\_??_USBSTOR#DISK&VEN_IRIVER&PROD_E150&REV_0100#6&35B20BB7&0&___K&1#{53F56307-B6BF-11D0-94F2-00A0C91EFB8B}   : 0x0.  
                48         2002-01-06 14:46:29                           Microsoft-Windows-DriverFrameworks-UserMode  10000:  ,       1.9.0,    WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_IRIVER&PROD_E150&REV_0100#6&35B20BB7&0&___K&0#.  
                48         2002-01-06 14:46:29                           Microsoft-Windows-DriverFrameworks-UserMode  10002:      WpdFs (CLSID {112DE495-AC4C-46F8-B663-6A4266C53313}) .      1.9.0    .  
                48         2002-01-06 14:46:30                           Microsoft-Windows-DriverFrameworks-UserMode  10100:     .  
                7005       2002-01-06 14:46:30                           Microsoft-Windows-UserPnp       20003:       WUDFRd      WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_IRIVER&PROD_E150&REV_0100#6&35B20BB7&0&___K&0#   : 0.  
                16         2002-01-06 14:46:32                                  WPDClassInstaller               
                32         2002-01-06 14:46:33                                  WPDClassInstaller               
                32         2002-01-06 14:46:33                                  WPDClassInstaller               
                7005       2002-01-06 14:46:34                           Microsoft-Windows-UserPnp       20001:       FileRepository\wpdfs.inf_x86_neutral_fc4ebadff3a40ae4\wpdfs.inf      WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_IRIVER&PROD_E150&REV_0100#6&35B20BB7&0&___K&0#   : 0x0.  
                48         2002-01-06 14:46:36                           Microsoft-Windows-DriverFrameworks-UserMode  10000:  ,       1.9.0,    WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_IRIVER&PROD_E150&REV_0100#6&35B20BB7&0&___K&1#.  
                48         2002-01-06 14:46:36                           Microsoft-Windows-DriverFrameworks-UserMode  10002:      WpdFs (CLSID {112DE495-AC4C-46F8-B663-6A4266C53313}) .      1.9.0    .  
                48         2002-01-06 14:46:37                           Microsoft-Windows-DriverFrameworks-UserMode  10100:     .  
                7005       2002-01-06 14:46:37                           Microsoft-Windows-UserPnp       20003:       WUDFRd      WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_IRIVER&PROD_E150&REV_0100#6&35B20BB7&0&___K&1#   : 0.  
                16         2002-01-06 14:46:38                                  WPDClassInstaller               
                32         2002-01-06 14:46:38                                  WPDClassInstaller               
                32         2002-01-06 14:46:38                                  WPDClassInstaller               
                7005       2002-01-06 14:46:38                           Microsoft-Windows-UserPnp       20001:       FileRepository\wpdfs.inf_x86_neutral_fc4ebadff3a40ae4\wpdfs.inf      WPDBUSENUMROOT\UMB\2&37C186B&0&STORAGE#VOLUME#_??_USBSTOR#DISK&VEN_IRIVER&PROD_E150&REV_0100#6&35B20BB7&0&___K&1#   : 0x0.  
                        2002-01-06 14:49:20                           Microsoft-Windows-Kernel-General  12:   .  
                        2002-01-06 14:49:24                           Microsoft-Windows-FilterManager  6:    "FileInfo" ( 6.1, 2009-07-14T01:21:51.000000000Z)       .  
                4          2002-01-06 14:49:27                           Microsoft-Windows-Kernel-Processor-Power  26:  0   0   :  :     1,  :   0,   :   0  
                4          2002-01-06 14:49:27                           Microsoft-Windows-Kernel-Processor-Power  26:  1   0   :  :     1,  :   0,   :   0  
          Unknown         63         2002-01-06 14:49:27                           Microsoft-Windows-Kernel-Power  41:  ,    .      ,    ,   ,    .  
                        2002-01-06 14:49:36                                  Service Control Manager         7036:  "Plug-and-Play"    .  
                        2002-01-06 14:49:36                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 14:49:36                                  Service Control Manager         7036:  "   DCOM-"    .  
                        2002-01-06 14:49:36                                  Service Control Manager         7036:  "   RPC"    .  
                        2002-01-06 14:49:36                                  Service Control Manager         7036:  "   (RPC)"    .  
                        2002-01-06 14:49:36                           Microsoft-Windows-FilterManager  6:    "luafv" ( 6.1, 2009-07-14T01:15:44.000000000Z)       .  
                7010       2002-01-06 14:49:36                           Microsoft-Windows-UserPnp       20010:      (Plug and Play).        PlugPlay: "true"      PlugPlay: "true"     
                            2002-01-06 14:49:37                                  EventLog                        6008:      14:47:58  ?06.?01.?2002  .  
                        2002-01-06 14:49:37                                  EventLog                        6009: Microsoft (R) Windows (R) 6.01. 7601 Service Pack 1 Multiprocessor Free.  
                        2002-01-06 14:49:37                                  EventLog                        6005:    .  
                        2002-01-06 14:49:37                                  EventLog                        6013:    16 .  
                        2002-01-06 14:49:37                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 14:49:37                                  Service Control Manager         7036:  "  "    .  
                            2002-01-06 14:49:38                                  BugCheck                        
                        2002-01-06 14:49:38                                  Service Control Manager         7036:  "    Windows Audio"    .  
                        2002-01-06 14:49:38                                  Service Control Manager         7036:  "Windows Audio"    .  
                        2002-01-06 14:49:38                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 14:49:38                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:49:38                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:49:38                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 14:49:39                                  Service Control Manager         7036:  "  COM+"    .  
                        2002-01-06 14:49:39                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 14:49:39                                  Service Control Manager         7036:  "     "    .  
                        2002-01-06 14:49:39                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:49:39                                  Service Control Manager         7036:  "Windows Driver Foundation - User-mode Driver Framework"    .  
                        2002-01-06 14:49:39                                  Service Control Manager         7036:  "  NetBIOS  TCP/IP"    .  
                        2002-01-06 14:49:39                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:49:39                                  Service Control Manager         7036:  "DHCP-"    .  
                        2002-01-06 14:49:39                                  Service Control Manager         7036:  "DNS-"    .  
                        2002-01-06 14:49:39                                  Service Control Manager         7036:  "  "    .  
                4          2002-01-06 14:49:39  LOCAL SERVICE                   Microsoft-Windows-Dhcp-Client   50036:   DHCPv4   
                4          2002-01-06 14:49:39  LOCAL SERVICE                   Microsoft-Windows-DHCPv6-Client  51046:   DHCPv6   
                        2002-01-06 14:49:40                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 14:49:40                                  Service Control Manager         7036:  " "    .  
                1101       2002-01-06 14:49:40                           Microsoft-Windows-Winlogon      7001:           
                        2002-01-06 14:49:43                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:49:43                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-06 14:49:43                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 14:49:43                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 14:49:43                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:49:43                                  Service Control Manager         7036:  "Superfetch"    .  
                        2002-01-06 14:49:43                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:49:43                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 14:49:44                                  Service Control Manager         7036:  "  IP"    .  
                        2002-01-06 14:49:44                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 14:49:44                                  Service Control Manager         7036:  ""    .  
                        2002-01-06 14:49:45                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:49:45                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:49:45                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:49:45                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:49:45                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:49:45                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:49:56                                  Service Control Manager         7036:  " "    .  
                        2002-01-06 14:49:58                                  Service Control Manager         7036:  "Windows Search"    .  
                        2002-01-06 14:51:45                                  Service Control Manager         7036:  "    (BITS)"    .  
                        2002-01-06 14:51:46                                  Service Control Manager         7036:  " SSDP"    .  
                        2002-01-06 14:51:46                                  Service Control Manager         7036:  "   Windows"    .  
                        2002-01-06 14:51:46                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:51:47                                  Service Control Manager         7036:  " Windows"    .  
                        2002-01-06 14:51:48                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:51:50                                  Service Control Manager         7036:  "  Windows"    .  
                        2002-01-06 14:53:27                                  Service Control Manager         7036:  "   "    .  
                          2002-01-06 14:53:27  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 8   : 1           .  
                        2002-01-06 14:56:27                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:56:49                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:57:42                                  Service Control Manager         7036:  "  "    .  
                        2002-01-06 14:57:45                                  Service Control Manager         7036:  "   "    .  
                        2002-01-06 14:57:49                                  Service Control Manager         7036:  "    "    .  
                        2002-01-06 14:57:49                           Microsoft-Windows-Application-Experience  201:       .  
                        2002-01-06 14:57:51  user                            Service Control Manager         7045:    .     :  Lavalys EVEREST Kernel Driver    :  C:\Program Files\Everest\kerneld.wnt   :        :      :    
                        2002-01-06 14:58:24                                  Service Control Manager         7036:  "  "    .  


--------[   ]-------------------------------------------------------------------------------------------------------

      :
      Borland Database Engine                           -
      Borland InterBase Client                          -
      Easysoft ODBC-InterBase 6                         -
      Easysoft ODBC-InterBase 7                         -
      Firebird Client                                   -
      Jet Engine                                        4.00.9756.0
      MDAC                                              6.1.7601.17514 (win7sp1_rtm.101119-1850)
      ODBC                                              6.1.7601.17514 (win7sp1_rtm.101119-1850)
      MySQL Connector/ODBC                              -
      Oracle Client                                     -
      PsqlODBC                                          -
      Sybase ASE ODBC                                   -

     :
      Borland InterBase Server                          -
      Firebird Server                                   -
      Microsoft SQL Server                              -
      Microsoft SQL Server Compact Edition              -
      Microsoft SQL Server Express Edition              -
      MySQL Server                                      -
      Oracle Server                                     -
      PostgreSQL Server                                 -
      Sybase SQL Server                                 -


--------[  ODBC ]-----------------------------------------------------------------------------------------------

    Driver da Microsoft para arquivos texto (*.txt; *.csv)      odbcjt32.dll                              *.,*.asc,*.csv,*.tab,*.txt,*.csv
    Driver do Microsoft Access (*.mdb)                          odbcjt32.dll                              *.mdb
    Driver do Microsoft dBase (*.dbf)                           odbcjt32.dll                              *.dbf,*.ndx,*.mdx
    Driver do Microsoft Excel(*.xls)                            odbcjt32.dll                              *.xls
    Driver do Microsoft Paradox (*.db )                         odbcjt32.dll                              *.db
    Driver para o Microsoft Visual FoxPro                       vfpodbc.dll                               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft Access Driver (*.mdb)                             odbcjt32.dll                              *.mdb
    Microsoft Access-Treiber (*.mdb)                            odbcjt32.dll                              *.mdb
    Microsoft dBase Driver (*.dbf)                              odbcjt32.dll                              *.dbf,*.ndx,*.mdx
    Microsoft dBase VFP Driver (*.dbf)                          vfpodbc.dll                               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft dBase-Treiber (*.dbf)                             odbcjt32.dll                              *.dbf,*.ndx,*.mdx
    Microsoft Excel Driver (*.xls)                              odbcjt32.dll                              *.xls
    Microsoft Excel-Treiber (*.xls)                             odbcjt32.dll                              *.xls
    Microsoft FoxPro VFP Driver (*.dbf)                         vfpodbc.dll                               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft ODBC for Oracle                                   msorcl32.dll                              
    Microsoft Paradox Driver (*.db )                            odbcjt32.dll                              *.db
    Microsoft Paradox-Treiber (*.db )                           odbcjt32.dll                              *.db
    Microsoft Text Driver (*.txt; *.csv)                        odbcjt32.dll                              *.,*.asc,*.csv,*.tab,*.txt,*.csv
    Microsoft Text-Treiber (*.txt; *.csv)                       odbcjt32.dll                              *.,*.asc,*.csv,*.tab,*.txt,*.csv
    Microsoft Visual FoxPro Driver                              vfpodbc.dll                               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft Visual FoxPro-Treiber                             vfpodbc.dll                               *.dbf,*.cdx,*.idx,*.fpt
    SQL Server                                                  sqlsrv32.dll                              


--------[    ]--------------------------------------------------------------------------------------------

    Core i7 Extreme 965     3333   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1            14045 /
    Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1             8889 /
    Pentium EE 955          3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                 8025 /
    P4EE                    3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                 7895 /
    Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2             7667 /
    Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2             7174 /
    Athlon64 X2 4200+       2200   Asus M2N-X                                                              nForce520             Dual DDR2-737         5-5-5-18 CR2             6954 /
    Core 2 Duo E6700        2666   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2             6924 /
    Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                 6717 /
    Athlon64 X2 4000+       2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2             6264 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2             5987 /
    Core 2 Duo P8400        2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                 5850 /
    Phenom X4 9500          2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2             5019 /
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                 4960 /
    Core 2 Duo T5600        1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15                 4594 /
    Xeon                    3200   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                4584 /
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2              4352 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                 4012 /
    Core Duo T2500          2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15                 3976 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1              3938 /
    Xeon                    3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2-2-2-5                  3806 /
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12                 3654 /
    Xeon E5462              2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                 3540 /
    Atom 230                1600   Intel D945GCLF                                                          i945GC                DDR2-533 SDRAM        4-4-4-12                 3540 /
    Opteron 240             1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1              3529 /
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                        3408 /
    Xeon 5140               2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                 3348 /
    Xeon L5320              1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                 3155 /
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8                2983 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2             2832 /
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1              2769 /
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                        2754 /
    Opteron HE 2344         1700   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1             2737 /
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12                 2693 /
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7                2435 /
    Duron                   1600   Biostar M7VIQ                                                           KM266 Int.            DDR266 SDRAM          2.5-2-2-6 CR2             1601 /
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                                   1540 /
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-3-3-7                  1302 /
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5                  1134 /
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2             1061 /
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6                  1051 /
    PIII-E                   733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6                  1046 /
    PIII-S                  1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2              1041 /
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6                   954 /
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                                    841 /
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6                   767 /
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2               690 /
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6                   635 /
    PIII                     500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?                   620 /
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                         524 /
    PII                      333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?                   371 /
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5                   360 /
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5                   262 /
    PentiumPro               200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                         258 /
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4                   228 /
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6                   222 /
    PentiumMMX               200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                         188 /
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6                   167 /
    K6-2                     333   Amptron PM-9100LMR                                                      SiS5597 Ext.          PC66 SDRAM            3-3-3-6                   150 /
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6                   117 /


--------[    ]---------------------------------------------------------------------------------------------

    Core i7 Extreme 965     3333   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1            12038 /
    Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1             8814 /
    Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2             7086 /
    Xeon E5462              2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                 6712 /
    Athlon64 X2 4200+       2200   Asus M2N-X                                                              nForce520             Dual DDR2-737         5-5-5-18 CR2             6313 /
    Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2             5915 /
    Pentium EE 955          3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                 5636 /
    P4EE                    3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                 5618 /
    Core 2 Duo P8400        2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                 5522 /
    Athlon64 X2 4000+       2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2             5484 /
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2              5378 /
    Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                 4853 /
    Core 2 Duo E6700        2666   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2             4842 /
    Xeon                    3200   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                4197 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2             4083 /
    Phenom X4 9500          2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2             3861 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1              3824 /
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                 3584 /
    Core Duo T2500          2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15                 3410 /
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8                3112 /
    Core 2 Duo T5600        1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15                 3007 /
    Xeon                    3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2-2-2-5                  2840 /
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                        2838 /
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12                 2834 /
    Atom 230                1600   Intel D945GCLF                                                          i945GC                DDR2-533 SDRAM        4-4-4-12                 2832 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                 2785 /
    Xeon 5140               2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                 2487 /
    Xeon L5320              1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                 2315 /
    Opteron 240             1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1              2287 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2             2267 /
    Opteron HE 2344         1700   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1             2208 /
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1              2148 /
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7                2128 /
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                        2127 /
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2             2067 /
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12                 1876 /
    Duron                   1600   Biostar M7VIQ                                                           KM266 Int.            DDR266 SDRAM          2.5-2-2-6 CR2             1571 /
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-3-3-7                  1332 /
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5                  1204 /
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2              1057 /
    PIII-S                  1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2              1054 /
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6                  1049 /
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6                  1034 /
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6                   952 /
    PIII-E                   733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6                   848 /
    PIII                     500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?                   781 /
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                         761 /
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4                   692 /
    PentiumMMX               200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                         690 /
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6                   588 /
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                                    549 /
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6                   500 /
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                                    355 /
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6                   250 /
    PII                      333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?                   177 /
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6                   171 /
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5                   139 /
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5                   128 /
    PentiumPro               200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                          87 /
    K6-2                     333   Amptron PM-9100LMR                                                      SiS5597 Ext.          PC66 SDRAM            3-3-3-6                    77 /


--------[    ]----------------------------------------------------------------------------------------

    Core i7 Extreme 965     3333   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1            14153 /
    Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2             8444 /
    Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1             7241 /
    Athlon64 X2 4200+       2200   Asus M2N-X                                                              nForce520             Dual DDR2-737         5-5-5-18 CR2             6762 /
    Athlon64 X2 4000+       2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2             6567 /
    Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2             6225 /
    Pentium EE 955          3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                 6206 /
    P4EE                    3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                 6135 /
    Xeon E5462              2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                 5470 /
    Phenom X4 9500          2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2             5429 /
    Core 2 Duo E6700        2666   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2             5362 /
    Core 2 Duo P8400        2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                 5146 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2             4653 /
    Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                 4627 /
    Xeon                    3200   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                4124 /
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                 4018 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1              3714 /
    Opteron HE 2344         1700   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1             3373 /
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2              3179 /
    Core 2 Duo T5600        1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15                 3172 /
    Xeon                    3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2-2-2-5                  3161 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                 3144 /
    Core Duo T2500          2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15                 3103 /
    Xeon 5140               2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                 3000 /
    Xeon L5320              1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                 2905 /
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8                2645 /
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                        2542 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2             2511 /
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12                 2459 /
    Atom 230                1600   Intel D945GCLF                                                          i945GC                DDR2-533 SDRAM        4-4-4-12                 2397 /
    Opteron 240             1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1              2386 /
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                        2211 /
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1              2023 /
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12                 1963 /
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7                1729 /
    Duron                   1600   Biostar M7VIQ                                                           KM266 Int.            DDR266 SDRAM          2.5-2-2-6 CR2             1571 /
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2             1394 /
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-3-3-7                  1255 /
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5                  1184 /
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6                   950 /
    PIII-S                  1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2               907 /
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6                   886 /
    PIII-E                   733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6                   865 /
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2               784 /
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                                    623 /
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6                   574 /
    PIII                     500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?                   526 /
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                         504 /
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                                    476 /
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6                   311 /
    PII                      333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?                   245 /
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4                   182 /
    PentiumMMX               200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                         181 /
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5                   164 /
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5                   142 /
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6                   133 /
    PentiumPro               200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                         111 /
    K6-2                     333   Amptron PM-9100LMR                                                      SiS5597 Ext.          PC66 SDRAM            3-3-3-6                   100 /
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6                    83 /
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6                    81 /


--------[   ]---------------------------------------------------------------------------------------------

    Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1       47.2 ns
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2       55.2 ns
    Athlon64 X2 4200+       2200   Asus M2N-X                                                              nForce520             Dual DDR2-737         5-5-5-18 CR2       57.6 ns
    Core i7 Extreme 965     3333   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1       59.3 ns
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2       59.8 ns
    Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2       61.3 ns
    Athlon64 X2 4000+       2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2       62.1 ns
    Core 2 Duo E6700        2666   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2       69.3 ns
    Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15           70.9 ns
    Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2       74.7 ns
    Pentium EE 955          3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11           80.3 ns
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1        80.4 ns
    Core 2 Duo P8400        2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15           85.0 ns
    P4EE                    3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15           85.3 ns
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12           90.1 ns
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15           91.8 ns
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7          95.8 ns
    Opteron 240             1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1        97.9 ns
    Core Duo T2500          2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15           99.6 ns
    Atom 230                1600   Intel D945GCLF                                                          i945GC                DDR2-533 SDRAM        4-4-4-12          103.5 ns
    Xeon                    3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2-2-2-5           106.0 ns
    PIII-S                  1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2       108.1 ns
    Xeon 5140               2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15          109.0 ns
    Xeon E5462              2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15          110.6 ns
    Phenom X4 9500          2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2      112.6 ns
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8         112.8 ns
    Core 2 Duo T5600        1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15          113.7 ns
    PIII-E                   733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6           117.7 ns
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2       124.8 ns
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                            125.5 ns
    Xeon L5320              1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12          126.1 ns
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5           139.2 ns
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                 147.1 ns
    Xeon                    3200   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7         147.2 ns
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2      147.2 ns
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11          147.8 ns
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6           154.8 ns
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2       156.0 ns
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6           159.7 ns
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1       161.4 ns
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6           162.2 ns
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                 162.9 ns
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                            163.2 ns
    Duron                   1600   Biostar M7VIQ                                                           KM266 Int.            DDR266 SDRAM          2.5-2-2-6 CR2      163.8 ns
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12          166.2 ns
    PIII                     500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?           166.3 ns
    PentiumMMX               200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                 167.2 ns
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6           170.6 ns
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-3-3-7           175.7 ns
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5           183.8 ns
    K6-2                     333   Amptron PM-9100LMR                                                      SiS5597 Ext.          PC66 SDRAM            3-3-3-6           201.8 ns
    Opteron HE 2344         1700   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1      205.3 ns
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6           207.1 ns
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                 215.2 ns
    PentiumPro               200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                 233.6 ns
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4           234.9 ns
    PII                      333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?           248.9 ns
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6           266.1 ns
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6           275.6 ns
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5           317.4 ns


--------[ CPU Queen ]---------------------------------------------------------------------------------------------------

    4x Core i7 Extreme 965 HT    3333   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1         30786
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15             30472
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2         21421
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12             20452
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15             19166
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2         18636
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15             16729
    8x Opteron HE 2344      1700   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1         16146
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2         13693
    2x Core 2 Duo E6700     2666   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2         11406
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1         11169
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15              9578
    2x Core Duo T2500       2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15              7793
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15              7717
    2x Athlon64 X2 4200+    2200   Asus M2N-X                                                              nForce520             Dual DDR2-737         5-5-5-18 CR2          7716
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2          7280
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11              7098
    2x Xeon                 3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2-2-2-5               6188
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1           4863
    2x PIII-S               1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2           4857
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15              4210
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1           3851
    Atom 230                1600   Intel D945GCLF                                                          i945GC                DDR2-533 SDRAM        4-4-4-12              3779
    Xeon HT                 3200   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7             3599
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2           3516
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2          3497
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15              3375
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12              3124
    2x PIII-E                733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6               2811
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2          2808
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8             2804
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12              2607
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7             2544
    Duron                   1600   Biostar M7VIQ                                                           KM266 Int.            DDR266 SDRAM          2.5-2-2-6 CR2          2537
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                     2434
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-3-3-7               2218
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6               2210
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1           2031
    2x PIII                  500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?               1927
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11              1900
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6               1723
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                     1624
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2          1560
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                                1461
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6               1349
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6               1188
    2x PII                   333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?               1145
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2           1099
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5                953
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                                 885
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                      873
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5                814
    K6-2                     333   Amptron PM-9100LMR                                                      SiS5597 Ext.          PC66 SDRAM            3-3-3-6                696
    2x PentiumMMX            200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                      664
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6                575
    2x PentiumPro            200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                      534
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5                459
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4                232
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6                200
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6                185


--------[ CPU PhotoWorxx ]----------------------------------------------------------------------------------------------

    4x Core i7 Extreme 965 HT    3333   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1                 35393
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                     25575
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2                 19168
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2                 17431
    2x Core 2 Duo E6700     2666   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2                 11922
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                     11706
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                      9621
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                      8626
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1                  7653
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                      7534
    8x Opteron HE 2344      1700   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1                  6622
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2                  6532
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2                  6419
    2x Athlon64 X2 4200+    2200   Asus M2N-X                                                              nForce520             Dual DDR2-737         5-5-5-18 CR2                  6303
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                      6058
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1                   5645
    2x Core Duo T2500       2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15                      5053
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15                      5027
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                      4621
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                      3844
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2                  3724
    Xeon HT                 3200   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                     3449
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1                   3406
    2x Xeon                 3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2-2-2-5                       3339
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12                      2801
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2                  2780
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2                   2424
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                      2262
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12                      2198
    Atom 230                1600   Intel D945GCLF                                                          i945GC                DDR2-533 SDRAM        4-4-4-12                      2163
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8                     1967
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                             1883
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7                     1854
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1                   1599
    Duron                   1600   Biostar M7VIQ                                                           KM266 Int.            DDR266 SDRAM          2.5-2-2-6 CR2                  1413
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                             1385
    2x PIII-S               1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2                   1299
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2                  1219
    2x PIII-E                733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6                       1138
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                                        1119
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6                       1070
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6                        959
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-3-3-7                        853
    2x PIII                  500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?                        839
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2                    670
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5                        667
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6                        598
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                                         536
    2x PII                   333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?                        531
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                              530
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5                        357
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6                        353
    2x PentiumPro            200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                              327
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5                        297
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6                        270
    K6-2                     333   Amptron PM-9100LMR                                                      SiS5597 Ext.          PC66 SDRAM            3-3-3-6                        254
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6                        173
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4                        148
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6                        147
    2x PentiumMMX            200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                              142


--------[ CPU ZLib ]----------------------------------------------------------------------------------------------------

    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15               139481 /
    4x Core i7 Extreme 965 HT    3333   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1           112330 /
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                95887 /
    8x Opteron HE 2344      1700   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1            88845 /
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2            80081 /
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2            77167 /
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                69756 /
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                60995 /
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2            58396 /
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1            38059 /
    2x Core 2 Duo E6700     2666   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2            35355 /
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                29844 /
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                29223 /
    2x Athlon64 X2 4200+    2200   Asus M2N-X                                                              nForce520             Dual DDR2-737         5-5-5-18 CR2            25978 /
    2x Xeon                 3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2-2-2-5                 25040 /
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15                23969 /
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2            23852 /
    2x Core Duo T2500       2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15                23789 /
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                16146 /
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1             15860 /
    2x PIII-S               1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2             14669 /
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2             14095 /
    Xeon HT                 3200   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7               13795 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1             12635 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2            11824 /
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8               11343 /
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                10485 /
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12                 9871 /
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                        9775 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                 9261 /
    Atom 230                1600   Intel D945GCLF                                                          i945GC                DDR2-533 SDRAM        4-4-4-12                 8404 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2             8152 /
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7                8110 /
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12                 7935 /
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6                  7435 /
    2x PIII-E                733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6                  7379 /
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-3-3-7                  7343 /
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                        6339 /
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                                   5321 /
    2x PIII                  500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?                  4826 /
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1              4407 /
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2             4140 /
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                                   4002 /
    Duron                   1600   Biostar M7VIQ                                                           KM266 Int.            DDR266 SDRAM          2.5-2-2-6 CR2             3786 /
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6                  3586 /
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6                  3484 /
    2x PII                   333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?                  3070 /
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5                  2288 /
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2              2280 /
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                        2195 /
    2x PentiumPro            200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                        2102 /
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5                  1986 /
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6                  1465 /
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6                  1299 /
    2x PentiumMMX            200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                        1054 /
    K6-2                     333   Amptron PM-9100LMR                                                      SiS5597 Ext.          PC66 SDRAM            3-3-3-6                   774 /
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5                   656 /
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4                   497 /
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6                   474 /
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6                   412 /


--------[ CPU AES ]-----------------------------------------------------------------------------------------------------

    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15             41625
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12             27698
    4x Core i7 Extreme 965 HT    3333   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1         26703
    8x Opteron HE 2344      1700   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1         22599
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2         22435
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2         21658
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15             19896
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2         17358
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15             17320
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2         14802
    2x Core 2 Duo E6700     2666   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2          9969
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11              8970
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15              8443
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1          8339
    2x Core Duo T2500       2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15              7109
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15              6778
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2           6771
    2x Xeon                 3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2-2-2-5               6366
    2x Athlon64 X2 4200+    2200   Asus M2N-X                                                              nForce520             Dual DDR2-737         5-5-5-18 CR2          5757
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2          5444
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15              4811
    Xeon HT                 3200   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7             4107
    2x PIII-S               1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2           3985
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1           3608
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2           3576
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15              2935
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8             2906
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1           2851
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12              2842
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2          2603
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12              2378
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7             2291
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                     2284
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11              2114
    2x PIII-E                733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6               2105
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2          2089
    Duron                   1600   Biostar M7VIQ                                                           KM266 Int.            DDR266 SDRAM          2.5-2-2-6 CR2          2031
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1           1920
    Atom 230                1600   Intel D945GCLF                                                          i945GC                DDR2-533 SDRAM        4-4-4-12              1845
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6               1770
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                                1762
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6               1579
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-3-3-7               1539
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                     1475
    2x PIII                  500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?               1466
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                                1177
    2x PII                   333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?                984
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6                909
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6                857
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5                727
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                      682
    2x PentiumPro            200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                      599
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5                447
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5                401
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6                393
    K6-2                     333   Amptron PM-9100LMR                                                      SiS5597 Ext.          PC66 SDRAM            3-3-3-6                348
    2x PentiumMMX            200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                      313
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6                171
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6                112
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4                107


--------[ FPU Julia ]---------------------------------------------------------------------------------------------------

    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15             19454
    4x Core i7 Extreme 965 HT    3333   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1         14403
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12             13144
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2         10970
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15              9820
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15              8584
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2          8046
    8x Opteron HE 2344      1700   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1          7904
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2          5329
    2x Core 2 Duo E6700     2666   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2          5005
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15              4188
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15              3403
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11              2709
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1          2586
    2x Xeon                 3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2-2-2-5               2063
    2x Athlon64 X2 4200+    2200   Asus M2N-X                                                              nForce520             Dual DDR2-737         5-5-5-18 CR2          1873
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2          1776
    2x Core Duo T2500       2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15              1635
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15              1461
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15              1395
    Xeon HT                 3200   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7             1253
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2           1242
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1           1104
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8              922
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1            900
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2           854
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11               823
    Atom 230                1600   Intel D945GCLF                                                          i945GC                DDR2-533 SDRAM        4-4-4-12               785
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                      779
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2           683
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1            648
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12               645
    2x PIII-S               1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2            617
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12               538
    Duron                   1600   Biostar M7VIQ                                                           KM266 Int.            DDR266 SDRAM          2.5-2-2-6 CR2           534
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                      514
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6                495
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7              474
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6                440
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-3-3-7                398
    2x PIII-E                733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6                363
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                                 309
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2           273
    2x PIII                  500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?                261
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6                227
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5                193
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2            168
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                      121
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6                110
    2x PII                   333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?                100
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6                 78
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                                  73
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5                 62
    2x PentiumPro            200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                       56
    K6-2                     333   Amptron PM-9100LMR                                                      SiS5597 Ext.          PC66 SDRAM            3-3-3-6                 47
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5                 39
    2x PentiumMMX            200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                       39
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4                 16
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6                 11
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6                  6


--------[ FPU Mandel ]--------------------------------------------------------------------------------------------------

    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15              9771
    4x Core i7 Extreme 965 HT    3333   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1          7825
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12              6449
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2          5567
    8x Opteron HE 2344      1700   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1          5494
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2          5051
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15              4870
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15              4254
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2          3749
    2x Core 2 Duo E6700     2666   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2          2492
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15              2150
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11              1771
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15              1698
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1          1544
    2x Xeon                 3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2-2-2-5               1489
    2x Athlon64 X2 4200+    2200   Asus M2N-X                                                              nForce520             Dual DDR2-737         5-5-5-18 CR2          1057
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2          1005
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15               970
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2            847
    Xeon HT                 3200   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7              831
    2x Core Duo T2500       2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15               764
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15               745
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8              683
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1            674
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11               636
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                      590
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1            526
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1            494
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2           486
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6                412
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2           389
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                      388
    2x PIII-S               1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2            340
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12               300
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12               257
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7              252
    Duron                   1600   Biostar M7VIQ                                                           KM266 Int.            DDR266 SDRAM          2.5-2-2-6 CR2           222
    2x PIII-E                733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6                197
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                                 194
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6                192
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-3-3-7                191
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2           145
    Atom 230                1600   Intel D945GCLF                                                          i945GC                DDR2-533 SDRAM        4-4-4-12               143
    2x PIII                  500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?                135
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6                105
    2x PII                   333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?                 91
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6                 87
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5                 85
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2             80
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                                  71
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                       61
    2x PentiumPro            200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                       53
    2x PentiumMMX            200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                       45
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5                 37
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6                 31
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5                 28
    K6-2                     333   Amptron PM-9100LMR                                                      SiS5597 Ext.          PC66 SDRAM            3-3-3-6                 23
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4                 19
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6                  9
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6                  6


--------[ FPU SinJulia ]------------------------------------------------------------------------------------------------

    4x Core i7 Extreme 965 HT    3333   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1          6254
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15              5546
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12              3484
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2          2981
    8x Opteron HE 2344      1700   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1          2970
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2          2619
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15              2497
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15              2178
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2          1922
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1          1429
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11              1289
    2x Core 2 Duo E6700     2666   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2          1248
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15              1122
    2x Athlon64 X2 4200+    2200   Asus M2N-X                                                              nForce520             Dual DDR2-737         5-5-5-18 CR2           982
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2           934
    2x Core Duo T2500       2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15               911
    2x Xeon                 3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2-2-2-5                867
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15               848
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15               693
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1            623
    Xeon HT                 3200   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7              596
    2x PIII-S               1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2            586
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1            492
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2            487
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2           447
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8              394
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15               369
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12               362
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2           358
    Duron                   1600   Biostar M7VIQ                                                           KM266 Int.            DDR266 SDRAM          2.5-2-2-6 CR2           353
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                      340
    2x PIII-E                733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6                325
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6                308
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12               304
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-3-3-7                304
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7              297
    Atom 230                1600   Intel D945GCLF                                                          i945GC                DDR2-533 SDRAM        4-4-4-12               285
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1            284
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11               270
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6                247
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                      231
    2x PIII                  500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?                227
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6                163
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6                155
    2x PII                   333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?                151
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                                 140
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5                131
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                      103
    2x PentiumPro            200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                       91
    2x PentiumMMX            200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                       90
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                                  77
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5                 68
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2            64
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5                 61
    K6-2                     333   Amptron PM-9100LMR                                                      SiS5597 Ext.          PC66 SDRAM            3-3-3-6                 56
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2             49
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4                 37
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6                 30
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6                 24
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6                  8


--------[ Debug - PCI ]-------------------------------------------------------------------------------------------------

    B00 D00 F00:  nVIDIA MCP65 - Host Bridge (HyperTransport)
                  
      Offset 000:  DE 10 44 04  06 00 B0 00  A1 00 00 05  00 00 00 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 49 82 
      Offset 030:  00 00 00 00  44 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  43 10 49 82  08 DC E0 01  22 00 11 11  D0 00 00 00 
      Offset 050:  23 06 7F 00  03 00 00 00  00 00 03 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  06 15 00 00 
      Offset 070:  44 44 44 00  D0 09 00 00  11 00 00 00  11 11 88 00 
      Offset 080:  12 88 88 00  FA 00 64 0D  03 00 00 00  7F 00 00 00 
      Offset 090:  70 00 00 80  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  01 01 01 01  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  80 00 0F 0F  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  08 00 01 A8 
      Offset 0E0:  00 00 E0 FE  00 00 00 00  00 00 80 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D01 F00:  nVIDIA nForce 520 (MCP65S) - LPC Bridge
                  
      Offset 000:  DE 10 41 04  0F 00 A0 20  A2 00 01 06  00 00 80 00 
      Offset 010:  01 09 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 49 82 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  FF 00 00 00 
      Offset 040:  43 10 49 82  00 00 D0 FE  FA 3E FF 00  FA 3E FF 00 
      Offset 050:  FA 3E FF 00  00 5A 62 02  00 00 00 05  1F 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  10 00 FF FF  C5 80 00 00  00 00 05 19  00 00 00 60 
      Offset 080:  09 D0 00 D0  02 18 00 00  F0 00 00 01  FF 00 00 00 
      Offset 090:  FF 7F 00 00  00 00 00 00  21 97 0A 68  ED BC 00 00 
      Offset 0A0:  00 00 10 91  00 00 00 00  30 0A 37 0A  00 00 00 00 
      Offset 0B0:  00 00 00 00  30 02 AF 02  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 02 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  10 00 00 00  00 00 00 00 

    B00 D01 F01:  nVIDIA MCP65 - SMBus Controller
                  
      Offset 000:  DE 10 46 04  01 00 B0 00  A1 00 05 0C  00 00 80 00 
      Offset 010:  01 DC 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  01 06 00 00  01 07 00 00  00 00 00 00  43 10 49 82 
      Offset 030:  00 00 00 00  44 00 00 00  00 00 00 00  0A 01 00 00 
      Offset 040:  43 10 49 82  01 00 02 C0  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  01 05 00 00  01 08 00 00  01 0D 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 C8 FE  00 00 00 00  01 11 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  D4 30 80 00  01 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  40 00 40 01  10 00 00 00  05 00 00 00  00 00 00 00 
      Offset 0E0:  88 10 04 00  04 40 00 07  80 12 02 00  41 44 44 11 
      Offset 0F0:  02 FF 1E BF  01 00 00 80  10 00 00 00  00 00 00 00 

    B00 D01 F02:  nVIDIA MCP65 - Shape/Trim
                  
      Offset 000:  DE 10 45 04  00 04 A0 00  A1 00 00 05  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 49 82 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  43 10 49 82  00 00 00 00  10 02 80 10  10 00 10 10 
      Offset 050:  10 10 10 10  00 00 00 00  00 00 00 00  10 42 00 00 
      Offset 060:  69 0C 21 06  43 98 31 0C  C7 0C 63 0C  62 00 00 04 
      Offset 070:  20 00 20 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  01 00 00 04  42 00 01 00 
      Offset 090:  00 00 01 18  06 00 00 00  00 00 70 00  20 01 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  40 0C 50 06  40 18 20 0C 
      Offset 0B0:  00 98 11 00  00 04 00 00  00 00 00 02  00 04 10 00 
      Offset 0C0:  01 84 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D02 F00:  nVIDIA MCP65 - OHCI USB 1.1 Controller
                  
      Offset 000:  DE 10 54 04  06 00 B0 00  A1 10 03 0C  00 00 80 00 
      Offset 010:  00 F0 FF DB  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 49 82 
      Offset 030:  00 00 00 00  44 00 00 00  00 00 00 00  16 01 03 01 
      Offset 040:  43 10 49 82  01 00 02 FE  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  1D 47 40 00  10 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D02 F01:  nVIDIA MCP65 - EHCI USB 2.0 Controller
                  
      Offset 000:  DE 10 55 04  06 00 B0 00  A1 20 03 0C  00 00 80 00 
      Offset 010:  00 EC FF DB  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 49 82 
      Offset 030:  00 00 00 00  44 00 00 00  00 00 00 00  15 02 03 01 
      Offset 040:  43 10 49 82  0A 80 98 20  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  20 20 01 00  00 60 18 85  03 3C 0A 01  00 00 00 00 
      Offset 070:  00 00 08 05  00 10 20 80  89 3D B6 22  77 25 F4 00 
      Offset 080:  01 00 02 FE  00 00 00 00  00 00 00 00  15 16 00 00 
      Offset 090:  00 01 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  01 00 00 00  00 20 00 C0  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 11 22 33  44 00 00 00  FF 03 00 00  00 00 00 00 
      Offset 0C0:  10 10 2D 0D  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  10 00 00 00  00 00 00 00 

    B00 D06 F00:  nVIDIA MCP65 - LAN Controller
                  
      Offset 000:  DE 10 50 04  06 00 B0 00  A1 00 00 02  00 00 00 00 
      Offset 010:  00 D0 FF DB  01 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 49 82 
      Offset 030:  00 00 00 00  44 00 00 00  00 00 00 00  14 01 01 14 
      Offset 040:  43 10 49 82  01 50 02 FE  00 01 00 00  06 00 00 20 
      Offset 050:  05 6C 86 01  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  FF 00 00 00  08 00 03 A8 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  04 00 00 00  02 01 00 00  03 A0 18 40 

    B00 D07 F00:  nVIDIA MCP65 - High Definition Audio Controller
                  
      Offset 000:  DE 10 4A 04  06 00 B0 00  A1 00 03 04  00 00 80 00 
      Offset 010:  00 40 FF DB  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 86 82 
      Offset 030:  00 00 00 00  44 00 00 00  00 00 00 00  17 02 02 05 
      Offset 040:  43 10 86 82  01 50 02 C0  00 00 00 00  01 01 0F 00 
      Offset 050:  05 6C 80 01  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  0F 00 00 00  08 00 03 A8 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 47  00 29 00 00  00 00 00 00 

    B00 D08 F00:  nVIDIA MCP65 - PCI-PCI Bridge
                  
      Offset 000:  DE 10 49 04  07 04 B0 00  A1 01 04 06  00 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 01 01 40  F0 00 80 22 
      Offset 020:  F0 FF 00 00  F0 FF 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  B8 00 00 00  00 00 00 00  00 00 02 02 
      Offset 040:  00 00 73 07  01 00 02 00  07 00 00 00  00 00 4C 00 
      Offset 050:  00 00 00 00  00 00 00 00  FF 1F FF 1F  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 06 00 00  00 00 00 00  00 00 00 00  08 00 01 A8 
      Offset 090:  00 00 E0 FE  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  04 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  FF FF 00 00  0D 8C 00 00  DE 10 84 CB 
      Offset 0C0:  DE 10 84 CB  07 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D09 F00:  nVIDIA MCP65 - Parallel ATA Controller
                  
      Offset 000:  DE 10 48 04  05 00 B0 00  A1 8A 01 01  00 00 00 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  A1 FF 00 00  00 00 00 00  00 00 00 00  43 10 49 82 
      Offset 030:  00 00 00 00  44 00 00 00  00 00 00 00  00 00 03 01 
      Offset 040:  43 10 49 82  01 00 02 00  00 00 00 00  00 00 00 00 
      Offset 050:  02 F0 01 00  00 00 00 00  A8 A8 A8 A8  FF 00 FF FF 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 01 01 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  10 00 00 00  00 00 00 00 

    B00 D0A F00:  nVIDIA MCP65 - SATA Controller
                  
      Offset 000:  DE 10 5D 04  07 00 B0 00  A1 85 01 01  00 00 80 00 
      Offset 010:  81 0F 00 00  01 0F 00 00  81 0E 00 00  01 0E 00 00 
      Offset 020:  81 C4 00 00  00 20 FF DB  00 00 00 00  43 10 49 82 
      Offset 030:  00 00 00 00  44 00 00 00  00 00 00 00  15 01 03 01 
      Offset 040:  43 10 49 82  01 B0 02 00  00 00 00 00  00 00 00 00 
      Offset 050:  0F 68 38 60  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  60 AC 00 0F  00 0F 06 42  00 00 00 00 
      Offset 070:  2C 78 C4 40  00 00 00 00  03 A0 18 40  20 00 20 00 
      Offset 080:  00 00 00 C0  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  5D 04 01 01 
      Offset 0A0:  6E 5A 00 66  00 00 00 00  00 00 00 00  33 31 00 02 
      Offset 0B0:  05 CC 86 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  08 00 03 A8 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 40 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 3F 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 01 1E 00  00 00 00 00 

    B00 D0B F00:  nVIDIA MCP65 - PCI Express Root Port (x2)
                  
      Offset 000:  DE 10 5B 04  04 04 10 00  A1 00 04 06  10 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 02 02 00  F1 01 00 00 
      Offset 020:  F0 FF 00 00  F1 FF 01 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  40 00 00 00  00 00 00 00  00 00 02 00 
      Offset 040:  0D 48 00 00  DE 10 00 00  01 50 02 F8  00 00 00 00 
      Offset 050:  05 60 93 00  0C 30 E0 FE  00 00 00 00  82 49 00 00 
      Offset 060:  08 80 01 A8  00 00 E0 FE  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  10 00 41 01  01 80 00 00  10 20 00 00  21 3C 11 03 
      Offset 090:  00 00 21 10  00 00 00 00  C0 01 00 00  08 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D0C F00:  nVIDIA MCP65 - PCI Express Root Port (x2)
                  
      Offset 000:  DE 10 5A 04  04 04 10 00  A1 00 04 06  10 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 03 03 00  F1 01 00 00 
      Offset 020:  F0 FF 00 00  F1 FF 01 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  40 00 00 00  00 00 00 00  00 00 02 00 
      Offset 040:  0D 48 00 00  DE 10 00 00  01 50 02 F8  00 00 00 00 
      Offset 050:  05 60 93 00  0C 30 E0 FE  00 00 00 00  72 49 00 00 
      Offset 060:  08 80 01 A8  00 00 E0 FE  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  10 00 41 01  01 80 00 00  10 20 00 00  11 3C 11 02 
      Offset 090:  00 00 21 10  00 00 00 00  C0 01 00 00  08 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D0D F00:  nVIDIA MCP65 - PCI Express Root Port (x16)
                  
      Offset 000:  DE 10 58 04  07 04 10 00  A1 00 04 06  10 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 04 04 00  E1 E1 00 00 
      Offset 020:  00 DC F0 DF  01 C0 F1 CF  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  40 00 00 00  00 00 00 00  00 00 1A 00 
      Offset 040:  0D 48 00 00  DE 10 00 00  01 50 02 F8  00 00 00 00 
      Offset 050:  05 60 93 00  0C 30 E0 FE  00 00 00 00  92 49 00 00 
      Offset 060:  08 80 01 A8  00 00 E0 FE  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  10 00 41 01  01 80 00 00  10 28 00 00  01 3D 11 00 
      Offset 090:  40 00 01 31  00 00 00 00  C0 01 48 01  08 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D0E F00:  nVIDIA MCP65 - PCI Express Root Port (x8)
                  
      Offset 000:  DE 10 59 04  04 04 10 00  A1 00 04 06  10 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 05 05 00  F1 01 00 00 
      Offset 020:  F0 FF 00 00  F1 FF 01 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  40 00 00 00  00 00 00 00  00 00 02 00 
      Offset 040:  0D 48 00 00  DE 10 00 00  01 50 02 F8  00 00 00 00 
      Offset 050:  05 60 93 00  0C 30 E0 FE  00 00 00 00  62 49 00 00 
      Offset 060:  08 80 01 A8  00 00 E0 FE  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  10 00 41 01  01 80 00 00  10 20 00 00  11 3C 11 01 
      Offset 090:  00 00 81 10  00 00 00 00  C0 01 00 00  08 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F00:  AMD Hammer - HyperTransport Technology Configuration
                  
      Offset 000:  22 10 00 11  00 00 10 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  80 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  01 01 01 00  01 01 01 00  01 01 01 00  01 01 01 00 
      Offset 050:  01 01 01 00  01 01 01 00  01 01 01 00  01 01 01 00 
      Offset 060:  00 00 01 00  E4 00 00 00  20 C8 2E 0F  0C 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  08 00 01 21  20 00 11 11  22 06 75 80  02 00 00 00 
      Offset 090:  68 01 61 01  00 00 FF 00  07 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F01:  AMD Hammer - Address Map
                  
      Offset 000:  22 10 01 11  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  03 00 00 00  00 00 7F 00  00 00 00 00  01 00 00 00 
      Offset 050:  00 00 00 00  02 00 00 00  00 00 00 00  03 00 00 00 
      Offset 060:  00 00 00 00  04 00 00 00  00 00 00 00  05 00 00 00 
      Offset 070:  00 00 00 00  06 00 00 00  00 00 00 00  07 00 00 00 
      Offset 080:  03 00 E0 00  80 FF EF 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  03 0A 00 00  00 0B 00 00  03 00 80 00  00 0B FE 00 
      Offset 0C0:  13 10 00 00  00 F0 FF 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  03 00 00 FF  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F02:  AMD Hammer - DRAM Controller
                  
      Offset 000:  22 10 02 11  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  01 00 00 00  01 00 40 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  E0 3F 38 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  46 00 00 00  00 00 00 00 
      Offset 080:  02 00 00 00  00 00 00 00  24 F2 7D 5D  20 13 12 00 
      Offset 090:  10 08 01 00  6B 80 10 B4  21 00 00 80  18 18 15 16 
      Offset 0A0:  EB 02 00 5D  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  D8 13 65 62  17 00 00 00  1F BF 08 00  F1 FD 6A 38 
      Offset 0C0:  00 00 02 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  58 CC 0A E4  28 26 25 1C  78 C8 60 00  C9 28 05 08 
      Offset 0E0:  7B 45 BA E8  82 14 16 06  3A 6C 21 C3  6A CC 08 4C 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F03:  AMD Hammer - Miscellaneous Control
                  
      Offset 000:  22 10 03 11  00 00 10 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  F0 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  FF 3B 04 00  40 00 50 0A  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 C8 
      Offset 060:  F0 00 00 00  01 62 1F 00  00 00 00 00  00 00 00 00 
      Offset 070:  11 01 02 51  22 30 00 50  00 1B 00 08  2E 22 00 00 
      Offset 080:  00 00 07 23  13 21 13 21  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  38 00 00 00  00 40 01 02  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  01 A7 0D 00  00 00 A0 00  25 26 26 00 
      Offset 0E0:  00 00 00 00  20 1A 4F 00  19 17 00 00  00 00 00 00 
      Offset 0F0:  0F 00 10 00  00 00 00 00  00 00 00 00  B2 0F 04 00 

    B04 D00 F00:  nVIDIA GeForce 8600 GT Video Adapter
                  
      Offset 000:  DE 10 02 04  07 00 10 00  A1 00 00 03  10 00 00 00 
      Offset 010:  00 00 00 DF  0C 00 00 C0  00 00 00 00  04 00 00 DC 
      Offset 020:  00 00 00 00  01 EC 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  60 00 00 00  00 00 00 00  12 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 00 00 00  01 00 00 00  CE D6 23 00  00 00 00 00 
      Offset 060:  01 68 02 00  00 00 00 00  05 78 80 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  10 00 01 00  E0 84 00 00 
      Offset 080:  10 29 00 00  01 31 01 00  40 00 01 11  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  02 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    ISA-0D00:     nVIDIA CK8/CK8-04/MCP2/MCP04/MCP5x/MCP6x/MCP7x NVA
                  
      Offset 00:  00 00 00 00  3F 82 C6 E1  51 A8 E6 21  02 14 00 91 
      Offset 10:  02 1F C0 A1  02 1F C0 A1  00 00 00 00  00 00 00 08 
      Offset 20:  0A 18 C0 B1  0B 38 C0 A1  04 1B 00 80  01 10 C0 B1 
      Offset 30:  42 91 E8 00  8E 8E 40 00  02 1F C0 A1  18 32 E6 A1 
      Offset 40:  00 00 00 00  47 00 41 C9  01 02 00 00  00 00 00 00 
      Offset 50:  32 18 C0 A1  05 10 00 00  01 14 C8 B1  00 00 00 00 
      Offset 60:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 70:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 80:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 90:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset B0:  00 00 00 00  49 00 41 C9  01 02 00 00  00 00 00 00 
      Offset C0:  00 00 00 00  4C 00 57 C9  01 02 00 00  00 01 00 80 
      Offset D0:  02 10 02 91  02 0C 01 91  02 10 01 91  02 14 01 91 
      Offset E0:  02 0C 00 91  02 10 00 91  02 14 00 91  02 18 40 91 
      Offset F0:  02 1C 40 91  01 1C 40 91  00 00 00 00  00 00 00 00 

    ISA-DC00:     nVIDIA MCP55/MCP6x/MCP7x THERM
                  
      Offset 00:  08 00 00 00  CC 59 32 00  90 18 5E 1A  2E 00 00 01 
      Offset 10:  00 04 00 C0  00 00 00 00  05 00 00 00  00 00 00 00 
      Offset 20:  00 00 00 00  00 00 00 00  28 3C 28 3C  00 00 00 00 
      Offset 30:  00 00 00 00  00 01 00 00  00 00 00 00  00 00 00 00 


--------[ Debug - Video BIOS ]------------------------------------------------------------------------------------------

    C000:0000  U.h.K7400.L.w.VIDEO ......Y...IBM VGA Compatible........06/20/07
    C000:0040  ..................<..................."....a..h.PMIDl.o.......
    C000:0080  .....3^QM...|................1..................................
    C000:00C0  ....................................HWEAPCIR............h.......
    C000:0100  NVIDIA GeForce 8600GT VGA BIOS..................................
    C000:0140  .................Version 60.84.54.00.R3 ...Copyright (C) 1996-20
    C000:0180  06 NVIDIA Corp..........G84 Board - p403h02 ...............Chip 
    C000:01C0  Rev   ..........................................................
    C000:0200  BIT......F2...p.B...t.C.....D.....A.....I.....L.....M.....N.....
    C000:0240  P.....S.....T.....U.....V.....c.....x.....i.&........T.`........
    C000:0280  ..........\\.........R06..Vg..TR..S.S.S.SpT.T.S.....T.dR..q.*...
    C000:02C0  ............!.......B......PQ..k.(.5..5#..#.........;l;......T.`
    C000:0300  ...?...-...05/20/07.................P...........0.'.!.!.6.B.@.W.
    C000:0340  .. .P...........0.'.!.!.,.w.(...1.>.....5.>.8.D.\...G.....J.....
    C000:0380  ....Q.Q.a...0.9.....=...>.>.<.>.>.>...a.>.'.S.f.4.4.4.6...v.4.n.
    C000:03C0  P...q.4.X.t.*...;.x...z...................!.!.....$.%.&.....>...


--------[ Debug - Unknown ]---------------------------------------------------------------------------------------------

    Optical         PIONEER DVD-RW  DVR-219L ATA Device


------------------------------------------------------------------------------------------------------------------------

The names of actual companies and products mentioned herein may be the trademarks of their respective owners.
