--------[ AIDA64 Extreme Edition ]--------------------------------------------------------------------------------------

                                                AIDA64 v1.60.1300/ru
                                        2.7.345-x32
                                      http://www.aida64.com/
                                              
                                             -
                                             
                                   Microsoft Windows 7 Ultimate 6.1.7600 (Win7 RTM)
                                                  2014-01-08
                                                 00:07


--------[   ]----------------------------------------------------------------------------------------

    :
                                           ACPI    x86
                                     Microsoft Windows 7 Ultimate
                                       -
      Internet Explorer                                 9.0.8112.16421
      DirectX                                           DirectX 11.0
                                           -
                                         
                                              -
       /                                       2014-01-08 / 00:07

     :
                                                   TripleCore AMD Athlon II X3 425, 2700 MHz (13.5 x 200)
                                          Asus M4A78  (3 PCI, 2 PCI-E x1, 1 PCI-E x16, 4 DDR2 DIMM, Audio, Gigabit LAN)
                                    AMD 770, AMD K10
                                         3328   (DDR2-800 DDR2 SDRAM)
      DIMM1: Kingmax KLDE88F-B8KU5                      2  DDR2-800 DDR2 SDRAM  (5-5-5-18 @ 400 )  (4-4-4-12 @ 266 )  (3-3-3-9 @ 200 )
      DIMM2: QUM2U-2G800T5R                             2  DDR2-800 DDR2 SDRAM  (5-5-5-18 @ 400 )  (4-5-5-15 @ 333 )  (3-4-4-12 @ 266 )
       BIOS                                          AMI (08/25/10)
                                      (COM1)
                                      (LPT1)

    :
                                            NVIDIA GeForce GTX 550 Ti  (1024 )
                                            NVIDIA GeForce GTX 550 Ti  (1024 )
                                                 BenQ G922HDA  [19" LCD]  (WA900911019)

    :
                                         nVIDIA Unknown @  High Definition Audio (Microsoft) [10DE-0BEE] [NoDB]
                                         Realtek ALC887 @ ATI SB700 - High Definition Audio Controller

     :
       IDE                                       PCI IDE
       IDE                                       PCI IDE
                                      Generic- Compact Flash USB Device
                                      Generic- MS/MS-Pro USB Device
                                      Generic- SD/MMC USB Device
                                      Generic- SM/xD-Picture USB Device
                                      Generic USB Flash Disk USB Device  (1926 , USB)
                                      TOSHIBA MQ01ABD050 USB Device  (465 , USB)
                                      WDC WD5000AAKX-001CA0 ATA Device  (465 , IDE)
                                    PIONEER DVD-RW  DVR-221L ATA Device
                                    TSSTcorp DVD-ROM SH-D163B ATA Device  (16x/48x DVD-ROM)
       SMART                         OK

    :
      C: (NTFS)                                         99899  (65450  )
      D: (NTFS)                                         368.1  (290.7  )
      G: (NTFS)                                         465.8  (99.2  )
                                              931.4  (453.8  )

    :
                                               HID
                                                    HID- 

    :
        IP                                192.168.0.100
        MAC                               90-E6-BA-C0-9C-C4
                                            Realtek RTL8168B/8111B Family PCI-E Gigabit Ethernet NIC (NDIS 6.20)  (192.168.0.100)

     :
                                                 Canon LBP6000/LBP6018
                                                 Fax
                                                 Microsoft XPS Document Writer
                                                   OneNote 2007
       USB1                                   ATI SB700 - OHCI USB Controller
       USB1                                   ATI SB700 - OHCI USB Controller
       USB1                                   ATI SB700 - OHCI USB Controller
       USB1                                   ATI SB700 - OHCI USB Controller
       USB1                                   ATI SB700 - OHCI USB Controller
       USB2                                   ATI SB700 - EHCI USB 2.0 Controller
       USB2                                   ATI SB700 - EHCI USB 2.0 Controller
      USB-                                    USB- 
      USB-                                    USB- 
      USB-                                    USB- 
      USB-                                       USB
      USB-                                       USB
      USB-                                       USB
      USB-                                     USB 

    DMI:
      DMI  BIOS                                American Megatrends Inc.
      DMI  BIOS                                   2301
      DMI                           System manufacturer
      DMI                                        System Product Name
      DMI                                System Version
      DMI                         System Serial Number
      DMI  UUID                                C03445CD-D1FED511-AC4090E6-BAC09CC4
      DMI                    ASUSTeK Computer INC.
      DMI                                 M4A78
      DMI                           Rev X.0x
      DMI                    MF709AG01404734
      DMI                             Chassis Manufacture
      DMI                                    Chassis Version
      DMI                             Chassis Serial Number
      DMI Asset-                                Asset-1234567890
      DMI                                       Desktop Case


--------[   ]----------------------------------------------------------------------------------------------

          
     NetBIOS                 -
      DNS               -
      DNS              
      DNS              -
     NetBIOS                 -
      DNS               -
      DNS              
      DNS              -


--------[ DMI ]---------------------------------------------------------------------------------------------------------

  [ BIOS ]

     BIOS:
                                           American Megatrends Inc.
                                                  2301
                                             08/25/2010
                                                  1024 
                                   Floppy Disk, Hard Disk, CD-ROM, ATAPI ZIP, LS-120
                                             Flash BIOS, Shadow BIOS, Selectable Boot, EDD, BBS
                                 DMI, APM, ACPI, ESCD, PnP
                                   ISA, PCI, USB

     BIOS:
                                                   American Megatrends Inc.
                                     http://www.ami.com/amibios
       BIOS                                   http://www.aida64.com/bios-updates

  [  ]

     :
                                           System manufacturer
                                                 System Product Name
                                                  System Version
                                           System Serial Number
      SKU#                                              To Be Filled By O.E.M.
                                               To Be Filled By O.E.M.
        ID                       C03445CD-D1FED511-AC4090E6-BAC09CC4
                                           

  [   ]

      :
                                           ASUSTeK Computer INC.
                                                 M4A78
                                                  Rev X.0x
                                           MF709AG01404734

      :
                                                   ASUSTeK Computer Inc.
                                     http://www.asus.com/ProductGroup2.aspx?PG_ID=mKyCKlQ4oSEtSu5m
        BIOS                          http://support.asus.com/download/download.aspx?SLanguage=en-us
                                     http://www.aida64.com/driver-updates
       BIOS                                   http://www.aida64.com/bios-updates

  [  ]

     :
                                           Chassis Manufacture
                                                  Chassis Version
                                           Chassis Serial Number
                                            Asset-1234567890
                                                
                                     
                               
                                  
                                   

  [  / AMD Athlon(tm) II X3 425 Processor ]

     :
                                           AMD
                                                  AMD Athlon(tm) II X3 425 Processor
                                           To Be Filled By O.E.M.
                                            To Be Filled By O.E.M.
                                          To Be Filled By O.E.M.
                                          200 
                                     2700 
                                          2700 
                                                     Central Processor
                                       1.5 V
                                                  
                                              AM2
      HTT / CMP                                         0 / 3

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us-en/Processors/ProductInformation/0,,30_118,00.html
                                     http://www.aida64.com/driver-updates

  [ - / L1-Cache ]

     :
                                                     
                                                  
                                             Varies with Memory Address
                                         4-way Set-Associative
                                       384 
                                      384 
        SRAM                           Pipeline Burst
        SRAM                                  Pipeline Burst
                                         Single-bit ECC
                                              L1-Cache

  [ - / L2-Cache ]

     :
                                                     
                                                  
                                             Varies with Memory Address
                                         4-way Set-Associative
                                       1536 
                                      1536 
        SRAM                           Pipeline Burst
        SRAM                                  Pipeline Burst
                                         Single-bit ECC
                                              L2-Cache

  [ - / L3-Cache ]

     :
                                                     
                                                  
                                       0 
                                      0 
                                              L3-Cache

  [   / DIMM0 ]

      :
      -                                       DIMM
                                                     DDR2
                                                     Synchronous
                                                  2048 
                                                800 
                                             64 
                                            64 
                                              DIMM0
                                                    BANK0
                                           Manufacturer0
                                           SerNum0
                                            AssetTagNum0
                                          PartNum0

  [   / DIMM1 ]

      :
      -                                       DIMM
                                                     DDR2
                                                     Synchronous
                                                  2048 
                                                800 
                                             64 
                                            64 
                                              DIMM1
                                                    BANK1
                                           Manufacturer1
                                           SerNum1
                                            AssetTagNum1
                                          PartNum1

  [   / DIMM2 ]

      :
      -                                       DIMM
                                              DIMM2
                                                    BANK2
                                           Manufacturer2
                                           SerNum2
                                            AssetTagNum2
                                          PartNum2

  [   / DIMM3 ]

      :
      -                                       DIMM
                                              DIMM3
                                                    BANK3
                                           Manufacturer3
                                           SerNum3
                                            AssetTagNum3
                                          PartNum3

  [   / PCIE16X ]

      :
                                       PCIE16X
                                                     PCI-E x1
                                           
                                        32-bit
                                                   

  [   / PCIE1X ]

      :
                                       PCIE1X
                                                     PCI-E x1
                                           
                                        32-bit
                                                   

  [   / PCIE1X ]

      :
                                       PCIE1X
                                                     PCI-E x1
                                           
                                        32-bit
                                                   

  [   / PCI1 ]

      :
                                       PCI1
                                                     PCI
                                           
                                        32-bit
                                                   

  [   / PCI2 ]

      :
                                       PCI2
                                                     PCI
                                           
                                        32-bit
                                                   

  [   / PCI3 ]

      :
                                       PCI3
                                                     PCI
                                           
                                        32-bit
                                                   

  [   / PS/2 KB/MS ]

      :
                                                Keyboard Port
                                   PS/2 KB/MS
                                    
                                      PS/2 KB/MS
                                       PS/2

  [   / USB12 ]

      :
                                                USB
                                   USB12
                                    
                                      USB12
                                       USB

  [   / USB34 ]

      :
                                                USB
                                   USB34
                                    
                                      USB34
                                       USB

  [   / USB56 ]

      :
                                                USB
                                   USB56
                                    
                                      USB56
                                       USB

  [   / LPT 1 ]

      :
                                                Parallel Port ECP/EPP
                                   LPT 1
                                    
                                      LPT 1
                                       DB-25 pin male

  [   / COM 1 ]

      :
                                                Serial Port 16550A Compatible
                                   COM 1
                                    
                                      COM 1
                                       DB-9 pin male

  [   / LAN ]

      :
                                                Network Port
                                   LAN
                                    
                                      LAN
                                       RJ-45

  [   / Audio_Line_In ]

      :
                                                Audio Port
                                   Audio_Line_In
                                    
                                      Audio_Line_In
                                       Mini-jack (headphones)

  [   / Audio_Line_Out ]

      :
                                                Audio Port
                                   Audio_Line_Out
                                    
                                      Audio_Line_Out
                                       Mini-jack (headphones)

  [   / Audio_Mic_In ]

      :
                                                Audio Port
                                   Audio_Mic_In
                                    
                                      Audio_Mic_In
                                       Mini-jack (headphones)

  [   / Audio_Center/Sub ]

      :
                                                Audio Port
                                   Audio_Center/Sub
                                    
                                      Audio_Center/Sub
                                       Mini-jack (headphones)

  [   / Audio_Rear ]

      :
                                                Audio Port
                                   Audio_Rear
                                    
                                      Audio_Rear
                                       Mini-jack (headphones)

  [   / Audio_Side ]

      :
                                                Audio Port
                                   Audio_Side
                                    
                                      Audio_Side
                                       Mini-jack (headphones)

  [   / SPDIF OUT2 ]

      :
                                                Audio Port
                                   SPDIF OUT2
                                    
                                      SPDIF OUT2
                                       Mini-jack (headphones)

  [   / ESATA ]

      :
                                                SATA
                                   ESATA
                                    
                                      ESATA
                                       SATA/SAS Plug Receptacle

  [   / PRI IDE ]

      :
                                   PRI IDE
                                    On-Board IDE
                                       

  [   / SB_SATA1 ]

      :
                                   SB_SATA1
                                       

  [   / SB_SATA2 ]

      :
                                   SB_SATA2
                                       

  [   / SB_SATA3 ]

      :
                                   SB_SATA3
                                       

  [   / SB_SATA5 ]

      :
                                   SB_SATA5
                                       

  [   / SB_SATA6 ]

      :
                                   SB_SATA6
                                       

  [   / CPU FAN ]

      :
                                   CPU FAN
                                       

  [   / PWR FAN ]

      :
                                   PWR FAN
                                       

  [   / CHA FAN ]

      :
                                   CHA FAN
                                       

  [   / USB78 ]

      :
                                                USB
                                   USB78
                                    USB
                                       

  [   / USB910 ]

      :
                                                USB
                                   USB910
                                    USB
                                       

  [   / USB1112 ]

      :
                                                USB
                                   USB1112
                                    USB
                                       

  [   / PANEL ]

      :
                                   PANEL
                                       

  [   / SPDIF OUT ]

      :
                                   SPDIF OUT
                                       

  [   / AAFP ]

      :
                                   AAFP
                                       

  [   / CD ]

      :
                                                Audio Port
                                   CD
                                    On-Board Sound Input from CD-ROM
                                       

  [   / To Be Filled By O.E.M. ]

      :
                                                To Be Filled By O.E.M.
                                                  

  [   / To Be Filled By O.E.M. ]

      :
                                                To Be Filled By O.E.M.
                                                     Ethernet
                                                  

  [   / To Be Filled By O.E.M. ]

      :
                                                To Be Filled By O.E.M.
                                                     Sound
                                                  

  [   / To Be Filled By O.E.M. ]

      :
                                                To Be Filled By O.E.M.
                                                  

  [  ]

    :
      OEM String                                        To Be Filled By O.E.M.
      OEM String                                        To Be Filled By O.E.M.
      OEM String                                        To Be Filled By O.E.M.
      OEM String                                        To Be Filled By O.E.M.


--------[  ]------------------------------------------------------------------------------------------------------

     :
                                                   TripleCore AMD Athlon II X3 425
                                             Rana
                                              BL-C2
      Engineering Sample                                
        CPUID                                      AMD Athlon(tm) II X3 425 Processor
       CPUID                                      00100F52h
      CPU VID                                           1.4250 V
        VID                                 1.1750 V

     :
                                               2707.7 MHz  (: 2700 MHz)
                                             13.5x
      CPU FSB                                           200.6 MHz  (: 200 MHz)
       HyperTransport                            2005.7 MHz
                                   2005.7 MHz
                                              401.1 MHz
       DRAM:FSB                              12:6

     :
       L1                                        64  per core
       L1                                      64  per core
       L2                                            512  per core  (On-Die, ECC, Full-Speed)

      :
      ID                                  64-2301-000001-00101111-082510-RX780_SB700$A1236001_BIOS DATE: 08/25/10 15:43:39 VER: 23.01
                                          Asus M4A78  (3 PCI, 2 PCI-E x1, 1 PCI-E x16, 4 DDR2 DIMM, Audio, Gigabit LAN)

       ():
                                    AMD 770, AMD K10
                                          5-5-5-18  (CL-RCD-RP-RAS)
      Command Rate (CR)                                 2T
      DIMM1: Kingmax KLDE88F-B8KU5                      2  DDR2-800 DDR2 SDRAM  (5-5-5-18 @ 400 )  (4-4-4-12 @ 266 )  (3-3-3-9 @ 200 )
      DIMM2: QUM2U-2G800T5R                             2  DDR2-800 DDR2 SDRAM  (5-5-5-18 @ 400 )  (4-5-5-15 @ 333 )  (3-4-4-12 @ 266 )

     BIOS:
        BIOS                               08/25/10
       BIOS                            04/13/12
      DMI  BIOS                                   2301


--------[  ]----------------------------------------------------------------------------------------------

     :
                                  
                                         
                              
                          


--------[   ]----------------------------------------------------------------------------------------------

    Centrino (Carmel)  :
      : Intel Pentium M (Banias/Dothan)                 (TripleCore AMD Athlon II X3 425)
      : Intel i855GM/PM                             (AMD 770, AMD K10)
      WLAN: Intel PRO/Wireless                          
      : Centrino-                     

    Centrino (Sonoma)  :
      : Intel Pentium M (Dothan)                        (TripleCore AMD Athlon II X3 425)
      : Intel i915GM/PM                             (AMD 770, AMD K10)
      WLAN: Intel PRO/Wireless                          
      : Centrino-                     

    Centrino (Napa)  :
      : Intel Core (Yonah) / Core 2 (Merom)             (TripleCore AMD Athlon II X3 425)
      : Intel i945GM/PM                             (AMD 770, AMD K10)
      WLAN: Intel PRO/Wireless 3945                     
      : Centrino-                     

    Centrino (Santa Rosa)  :
      : Intel Core 2 (Merom/Penryn)                     (TripleCore AMD Athlon II X3 425)
      : Intel GM965/PM965                           (AMD 770, AMD K10)
      WLAN: Intel Wireless WiFi Link 4965               
      : Centrino-                     

    Centrino 2 (Montevina)  :
      : Intel Core 2 (Penryn)                           (TripleCore AMD Athlon II X3 425)
      : Intel GM45/GM47/GS45/PM45                   (AMD 770, AMD K10)
      WLAN: Intel WiFi Link 5000 Series                 
      : Centrino 2-                   

    Centrino (Calpella)  :
      : Intel Core i3/i5/i7 (Arrandale/Clarksfield)     (TripleCore AMD Athlon II X3 425)
      : Intel HM55/HM57/PM55                        (AMD 770, AMD K10)
      WLAN: Intel WiFi Link 1000/WiMAX 6000 Series      
      : Centrino-                     


--------[  ]------------------------------------------------------------------------------------------------------

     :
                                              Fintek F71862/863  (ISA 290h)
                                            Driver  (NV-DRV)

    :
                                          40 C  (104 F)
                                                      45 C  (113 F)
       1 /  1                                     36 C  (97 F)
       1 /  2                                     36 C  (97 F)
       1 /  3                                     36 C  (97 F)
      Aux                                               55 C  (131 F)
                                    43 C  (109 F)
      WDC WD5000AAKX-001CA0                             44 C  (111 F)
      TOSHIBA MQ01ABD050                                38 C  (100 F)

    :
                                                      3740 RPM
                                                   1840 RPM
                                    2310 RPM

    :
                                                  1.328 V
      +3.3 V                                            3.120 V
      +12 V                                             14.872 V
      +3.3 V                                      3.392 V
       VBAT                                      3.344 V
                                                  0.950 V
      Debug Info F                                      0191 032F 0FFF
      Debug Info T                                      45 55 40
      Debug Info V                                      C3 A6 A2 00 00 A9 A3 D4 D1
      Debug Info I                                      03 04 10 19 34 (0601)


--------[  ]----------------------------------------------------------------------------------------------------------

     :
                                                   TripleCore AMD Athlon II X3 425, 2700 MHz (13.5 x 200)
                                             Rana
                                              BL-C2
                                        x86, x86-64, MMX, 3DNow!, SSE, SSE2, SSE3, SSE4A
                                         2700 
      ./.                             5.0x / 13.5x
      Engineering Sample                                
       L1                                        64  per core
       L1                                      64  per core
       L2                                            512  per core  (On-Die, ECC, Full-Speed)

    Multi CPU:
      ID                                  ASUS
      CPU #1                                            AMD Athlon(tm) II X3 425 Processor, 2707 
      CPU #2                                            AMD Athlon(tm) II X3 425 Processor, 2707 
      CPU #3                                            AMD Athlon(tm) II X3 425 Processor, 2707 

       :
                                              938 Pin uOPGA
                                          4.00 cm x 4.00 cm
                                       300 .
                                  45 nm, CMOS, Cu, Low-K, DSL SOI, Immersion Lithography
                                         169 mm2
       I/O                                    1.2 V + 2.5 V

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us-en/Processors/ProductInformation/0,,30_118,00.html
                                     http://www.aida64.com/driver-updates

     :
       1 /  1                                     50 %
       1 /  2                                     50 %
       1 /  3                                     25 %


--------[ CPUID ]-------------------------------------------------------------------------------------------------------

     CPUID:
       CPUID                               AuthenticAMD
        CPUID                                      AMD Athlon(tm) II X3 425 Processor
       CPUID                                      00100F52h
        CPUID                          00100F52h
       AMD                                 3996h  (Athlon II X3 425)
                                  D7h  (Socket AM3)
      HTT / CMP                                         0 / 3

     :
      64- x86- (AMD64, Intel64)            
      AMD 3DNow!                                        
      AMD 3DNow! Professional                           
      AMD 3DNowPrefetch                                 
      AMD Enhanced 3DNow!                               
      AMD Extended MMX                                  
      AMD FMA4                                           
      AMD MisAligned SSE                                
      AMD SSE4A                                         
      AMD XOP                                            
      Cyrix Extended MMX                                 
      Float-16 Conversion Instructions                   
      IA-64                                              
      IA MMX                                            
      IA SSE                                            
      IA SSE 2                                          
      IA SSE 3                                          
      IA Supplemental SSE 3                              
      IA SSE 4.1                                         
      IA SSE 4.2                                         
      IA AVX                                             
      IA FMA                                             
      IA AES Extensions                                  
      VIA Alternate Instruction Set                      
       CLFLUSH                                
       CMPXCHG8B                              
       CMPXCHG16B                             
       Conditional Move                       
       LZCNT                                  
       MONITOR / MWAIT                        
       MOVBE                                   
       PCLMULQDQ                               
       POPCNT                                 
       RDRAND                                  
       RDTSCP                                 
       SYSCALL / SYSRET                       
       SYSENTER / SYSEXIT                     
       VIA FEMMS                               

     :
      Advanced Cryptography Engine (ACE)                 
      Advanced Cryptography Engine 2 (ACE2)              
         (DEP, NX, EDB)           
          (RNG)         
      PadLock Hash Engine (PHE)                          
      PadLock Montgomery Multiplier (PMM)                
         (PSN)                    

     :
      Automatic Clock Control                            
      Digital Thermometer                               
      Dynamic FSB Frequency Switching                    
      Enhanced Halt State (C1E)                         , 
      Enhanced SpeedStep Technology (EIST, ESS)          
      Frequency ID Control                               
      Hardware P-State Control                          
      LongRun                                            
      LongRun Table Interface                            
      PowerSaver 1.0                                     
      PowerSaver 2.0                                     
      PowerSaver 3.0                                     
      Processor Duty Cycle Control                       
      Software Thermal Control                          
                                               
      Thermal Monitor 1                                  
      Thermal Monitor 2                                  
      Thermal Monitoring                                
      Thermal Trip                                      
      Voltage ID Control                                 

     CPUID:
      1 GB Page Size                                    
      36-bit Page Size Extension                        
      Address Region Registers (ARR)                     
      Core Power Boost                                   
      CPL Qualified Debug Store                          
      Debug Trace Store                                  
      Debugging Extension                               
      Direct Cache Access                                
      Dynamic Acceleration Technology (IDA)              
      Fast Save & Restore                               
      Hyper-Threading Technology (HTT)                   
      Invariant Time Stamp Counter                      
      L1 Context ID                                      
      Local APIC On Chip                                
      Machine Check Architecture (MCA)                  
      Machine Check Exception (MCE)                     
      Memory Configuration Registers (MCR)               
      Memory Type Range Registers (MTRR)                
      Model Specific Registers (MSR)                    
      Nested Paging                                     
      Page Attribute Table (PAT)                        
      Page Global Extension                             
      Page Size Extension (PSE)                         
      Pending Break Event                                
      Physical Address Extension (PAE)                  
      Safer Mode Extensions (SMX)                        
      Secure Virtual Machine Extensions (Pacifica)      
      Self-Snoop                                         
      Time Stamp Counter (TSC)                          
      Turbo Boost                                        
      Virtual Machine Extensions (Vanderpool)            
      Virtual Mode Extension                            
      x2APIC                                             
      XGETBV / XSETBV OS Enabled                         
      XSAVE / XRSTOR / XSETBV / XGETBV Extended States   

    CPUID Registers (CPU #1):
      CPUID 00000000                                    00000005-68747541-444D4163-69746E65
      CPUID 00000001                                    00100F52-00030800-00802009-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000000
      CPUID 80000000                                    8000001B-68747541-444D4163-69746E65
      CPUID 80000001                                    00100F52-10003996-000037FF-EFD3FBFF
      CPUID 80000002                                    20444D41-6C687441-74286E6F-4920296D
      CPUID 80000003                                    33582049-35323420-6F725020-73736563
      CPUID 80000004                                    0000726F-00000000-00000000-00000000
      CPUID 80000005                                    FF30FF10-FF30FF20-40020140-40020140
      CPUID 80000006                                    20800000-42004200-02008140-00000000
      CPUID 80000007                                    00000000-00000000-00000000-000001F9
      CPUID 80000008                                    00003030-00000000-00002002-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00000040-00000000-0000000F
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F0300000-60100000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    0000001F-00000000-00000000-00000000

    CPUID Registers (CPU #2):
      CPUID 00000000                                    00000005-68747541-444D4163-69746E65
      CPUID 00000001                                    00100F52-01030800-00802009-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000000
      CPUID 80000000                                    8000001B-68747541-444D4163-69746E65
      CPUID 80000001                                    00100F52-10003996-000037FF-EFD3FBFF
      CPUID 80000002                                    20444D41-6C687441-74286E6F-4920296D
      CPUID 80000003                                    33582049-35323420-6F725020-73736563
      CPUID 80000004                                    0000726F-00000000-00000000-00000000
      CPUID 80000005                                    FF30FF10-FF30FF20-40020140-40020140
      CPUID 80000006                                    20800000-42004200-02008140-00000000
      CPUID 80000007                                    00000000-00000000-00000000-000001F9
      CPUID 80000008                                    00003030-00000000-00002002-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00000040-00000000-0000000F
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F0300000-60100000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    0000001F-00000000-00000000-00000000

    CPUID Registers (CPU #3):
      CPUID 00000000                                    00000005-68747541-444D4163-69746E65
      CPUID 00000001                                    00100F52-02030800-00802009-178BFBFF
      CPUID 00000002                                    00000000-00000000-00000000-00000000
      CPUID 00000003                                    00000000-00000000-00000000-00000000
      CPUID 00000005                                    00000040-00000040-00000003-00000000
      CPUID 80000000                                    8000001B-68747541-444D4163-69746E65
      CPUID 80000001                                    00100F52-10003996-000037FF-EFD3FBFF
      CPUID 80000002                                    20444D41-6C687441-74286E6F-4920296D
      CPUID 80000003                                    33582049-35323420-6F725020-73736563
      CPUID 80000004                                    0000726F-00000000-00000000-00000000
      CPUID 80000005                                    FF30FF10-FF30FF20-40020140-40020140
      CPUID 80000006                                    20800000-42004200-02008140-00000000
      CPUID 80000007                                    00000000-00000000-00000000-000001F9
      CPUID 80000008                                    00003030-00000000-00002002-00000000
      CPUID 80000009                                    00000000-00000000-00000000-00000000
      CPUID 8000000A                                    00000001-00000040-00000000-0000000F
      CPUID 8000000B                                    00000000-00000000-00000000-00000000
      CPUID 8000000C                                    00000000-00000000-00000000-00000000
      CPUID 8000000D                                    00000000-00000000-00000000-00000000
      CPUID 8000000E                                    00000000-00000000-00000000-00000000
      CPUID 8000000F                                    00000000-00000000-00000000-00000000
      CPUID 80000010                                    00000000-00000000-00000000-00000000
      CPUID 80000011                                    00000000-00000000-00000000-00000000
      CPUID 80000012                                    00000000-00000000-00000000-00000000
      CPUID 80000013                                    00000000-00000000-00000000-00000000
      CPUID 80000014                                    00000000-00000000-00000000-00000000
      CPUID 80000015                                    00000000-00000000-00000000-00000000
      CPUID 80000016                                    00000000-00000000-00000000-00000000
      CPUID 80000017                                    00000000-00000000-00000000-00000000
      CPUID 80000018                                    00000000-00000000-00000000-00000000
      CPUID 80000019                                    F0300000-60100000-00000000-00000000
      CPUID 8000001A                                    00000003-00000000-00000000-00000000
      CPUID 8000001B                                    0000001F-00000000-00000000-00000000

    MSR Registers:
      CPU Clock (Normal)                                2707 MHz
      CPU Clock (TSC)                                   2707 MHz
      CPU Multiplier                                    13.5x
      MSR 0000001B                                      0000-0000-FEE0-0900
      MSR C0010015                                      0000-0000-0100-0010
      MSR C001001F                                      0258-4000-0000-0008
      MSR C0010055                                      0000-0000-0000-0000
      MSR C0010058                                      0000-0000-E000-0021
      MSR C0010061                                      0000-0000-0000-0030
      MSR C0010062                                      0000-0000-0000-0000
      MSR C0010063                                      0000-0000-0000-0000
      MSR C0010064                                      8000-01F7-3C00-140B [13.50x]
      MSR C0010065                                      8000-01CB-3C00-2405 [10.50x]
      MSR C0010066                                      8000-01BB-3C00-344E [7.50x]
      MSR C0010067                                      8000-018A-3C00-4040 [4.00x]
      MSR C0010068                                      0000-0000-0000-0000
      MSR C0010071                                      30B6-0053-3C00-140B [13.50x]
      MSR C0010140                                      0000-0000-0000-0003
      MSR C0010141                                      0000-0000-0000-0004
      MSR C0011023                                      0000-0000-1020-0020


--------[   ]---------------------------------------------------------------------------------------------

      :
      ID                                  64-2301-000001-00101111-082510-RX780_SB700$A1236001_BIOS DATE: 08/25/10 15:43:39 VER: 23.01
                                          Asus M4A78

      FSB:
                                                 AMD K10
                                         200 
                                      200 
       HyperTransport                            2000 
                                   2000 

      :
                                                 Unganged Dual DDR2 SDRAM
                                              128 
       DRAM:FSB                              12:6
                                         400  (DDR)
                                      800 
                                   12800 /

        :
                                         1 Socket AM2+
                                       3 PCI, 2 PCI-E x1, 1 PCI-E x16
                                              4 DDR2 DIMM
                                    Audio, Gigabit LAN
      -                                       ATX
                                   210 mm x 300 mm
                                    AMD770
                                   Q-Fan

      :
                                                   ASUSTeK Computer Inc.
                                     http://www.asus.com/ProductGroup2.aspx?PG_ID=mKyCKlQ4oSEtSu5m
        BIOS                          http://support.asus.com/download/download.aspx?SLanguage=en-us
                                     http://www.aida64.com/driver-updates
       BIOS                                   http://www.aida64.com/bios-updates


--------[  ]------------------------------------------------------------------------------------------------------

     :
                                                   3327 
                                                  1419 
                                                1907 
                                                43 %

       :
                                                   6652 
                                                  1725 
                                                4927 
                                                26 %

     :
                                                   9979 
                                                  3144 
                                                6835 
                                                32 %

     :
                                            C:\pagefile.sys
                                           3327 
      /                           225  / 226 
                                                7 %

    Physical Address Extension (PAE):
                                        
                                        
                                                


--------[ SPD ]---------------------------------------------------------------------------------------------------------

  [ DIMM1: Kingmax KLDE88F-B8KU5 ]

      :
                                               Kingmax KLDE88F-B8KU5
                                           
                                            2  (2 ranks, 8 banks)
                                               Unbuffered DIMM
                                               DDR2 SDRAM
                                          DDR2-800 (400 )
                                            64 bit
                                           SSTL 1.8
                                  
                                       (7.8 us), Self-Refresh

     :
      @ 400                                          5-5-5-18  (CL-RCD-RP-RAS) / 23-51-3-6-3-3  (RC-RFC-RRD-WR-WTR-RTP)
      @ 266                                          4-4-4-12  (CL-RCD-RP-RAS) / 16-34-2-4-2-2  (RC-RFC-RRD-WR-WTR-RTP)
      @ 200                                          3-3-3-9  (CL-RCD-RP-RAS) / 12-26-2-3-2-2  (RC-RFC-RRD-WR-WTR-RTP)

      :
      Analysis Probe                                    
      FET Switch External                               
      Weak Driver                                       

      :
                                                   KINGMAX Technology Inc.
                                     http://www.kingmax.com/en_03_product_list.asp?usn=24

  [ DIMM2: QUM2U-2G800T5R ]

      :
                                               QUM2U-2G800T5R
                                           
                                            2  (2 ranks, 8 banks)
                                               Unbuffered DIMM
                                               DDR2 SDRAM
                                          DDR2-800 (400 )
                                            64 bit
                                           SSTL 1.8
                                  
                                       (7.8 us), Self-Refresh

     :
      @ 400                                          5-5-5-18  (CL-RCD-RP-RAS) / 23-51-3-6-3-3  (RC-RFC-RRD-WR-WTR-RTP)
      @ 333                                          4-5-5-15  (CL-RCD-RP-RAS) / 20-43-3-5-3-3  (RC-RFC-RRD-WR-WTR-RTP)
      @ 266                                          3-4-4-12  (CL-RCD-RP-RAS) / 16-34-2-4-2-2  (RC-RFC-RRD-WR-WTR-RTP)

      :
      Analysis Probe                                    
      FET Switch External                               
      Weak Driver                                       


--------[  ]------------------------------------------------------------------------------------------------------

  [  : AMD RX780 ]

      :
                                            AMD RX780
                                                  00
                                              720 Pin FC-BGA
                                          2.7 cm x 2.7 cm
                                  65 nm
                                   1.1 V

     PCI Express:
      PCI-E 2.0 x16 port #0                              @ x16  (NVIDIA GeForce GTX 550 Ti [10DE-1244] [NoDB],  High Definition Audio (Microsoft) [10DE-0BEE] [NoDB])
      PCI-E 2.0 x1 port #2                               @ x1  (Realtek RTL8168B/8111B PCI-E Gigabit Ethernet Adapter)

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us-en/Processors/DevelopWithAMD/0,,30_2252_873,00.html
                                       http://www.amd.com/us-en/Processors/TechnicalResources/0,,30_182_871_2336,00.html
       BIOS                                   http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates

  [  : AMD K10 IMC ]

      :
                                            AMD K10 IMC
                                DDR2-400, DDR2-533, DDR2-667, DDR2-800, DDR2-1066, DDR3-800, DDR3-1066, DDR3-1333 SDRAM
                                                  00
      Probe Filter                                       

     :
                                                     Dual Channel  (128 )
                                           Dual Channel  (128 ) - Unganged

     :
      CAS Latency (CL)                                  5T
      RAS To CAS Delay (tRCD)                           5T
      RAS Precharge (tRP)                               5T
      RAS Active Time (tRAS)                            18T
      Row Cycle Time (tRC)                              23T
      Command Rate (CR)                                 2T
      RAS To RAS Delay (tRRD)                           3T
      Write Recovery Time (tWR)                         6T
      Write To Read Delay (tWTR)                        3T
      Read To Precharge Delay (tRTP)                    5T
      Four Activate Window Delay (tFAW)                 14T
      Write CAS Latency (tWCL)                          5T
      Refresh Period (tREF)                             7.8 us
      DRAM Drive Strength                               1.0x
      DRAM Data Drive Strength                          1.0x
      Clock Drive Strength                              1.5x
      CKE Drive Strength                                1.5x
      Idle Cycle Limit                                  16

     :
      ECC                                               , 
      ChipKill ECC                                      , 
      RAID                                               
      DRAM Scrub Rate                                   
      L1 Data Cache Scrub Rate                          
      L2 Cache Scrub Rate                               
      L3 Cache Scrub Rate                               

     :
       DRAM #1                                    2   (DDR2-800 DDR2 SDRAM)
       DRAM #2                                    2   (DDR2-800 DDR2 SDRAM)

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us-en/Processors/DevelopWithAMD/0,,30_2252_873,00.html
                                       http://www.amd.com/us-en/Processors/TechnicalResources/0,,30_182_871_2336,00.html
       BIOS                                   http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates

  [  : AMD SB700 ]

      :
                                               AMD SB700
                                                  00
                                              528 Pin FC-BGA
                                          2.1 cm x 2.1 cm
                                  55 nm
                                   1.2 V

    High Definition Audio:
                                               Realtek ALC887
      ID                                          10EC0887h / 10EC0887h
                                            00100202h
                                               Audio
                           44 kHz, 48 kHz, 96 kHz, 192 kHz, 16 , 20 , 24 

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us-en/Processors/DevelopWithAMD/0,,30_2252_873,00.html
                                       http://www.amd.com/us-en/Processors/TechnicalResources/0,,30_182_871_2336,00.html
       BIOS                                   http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates


--------[ BIOS ]--------------------------------------------------------------------------------------------------------

     BIOS:
       BIOS                                          AMI
       BIOS                                       2301
       AGESA                                      3.7.0.0
        BIOS                               08/25/10
       BIOS                            04/13/12

     BIOS (ATK):
      CPU Voltage                                       0.8000 V
      CPU/NB Voltage                                    1.200 V
      CPU Frequency                                     200.00 MHz
      CPU Ratio                                         13.5x

     BIOS:
                                                   American Megatrends Inc.
                                     http://www.ami.com/amibios
       BIOS                                   http://www.aida64.com/bios-updates


--------[ ACPI ]--------------------------------------------------------------------------------------------------------

  [ APIC: Multiple APIC Description Table ]

      ACPI:
       ACPI                                      APIC
                                         Multiple APIC Description Table
                                             CFF80390h
                                           124 
      OEM ID                                            082510
      OEM Table ID                                      APIC1543
      OEM Revision                                      20100825h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h
      Local APIC Address                                FEE00000h

  [ DSDT: Differentiated System Description Table ]

      ACPI:
       ACPI                                      DSDT
                                         Differentiated System Description Table
                                             CFF805D0h
                                           52456 
      OEM ID                                            A1236
      OEM Table ID                                      A1236001
      OEM Revision                                      00000001h
      Creator ID                                        INTL
      Creator Revision                                  20060113h

    nVIDIA SLI:
      SLI Certification                                 
      PCI 0-0-0-0 (Direct I/O)                          1002-5957
      PCI 0-0-0-0 (HAL)                                 1002-5957

  [ FACP: Fixed ACPI Description Table ]

      ACPI:
       ACPI                                      FACP
                                         Fixed ACPI Description Table
                                             CFF80200h
                                           132 
      OEM ID                                            082510
      OEM Table ID                                      FACP1543
      OEM Revision                                      20100825h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h
      SMI Command Port                                  000000B0h
      PM Timer                                          00000808h

  [ FACS: Firmware ACPI Control Structure ]

      ACPI:
       ACPI                                      FACS
                                         Firmware ACPI Control Structure
                                             CFF98000h
                                           64 

  [ HPET: IA-PC High Precision Event Timer Table ]

      ACPI:
       ACPI                                      HPET
                                         IA-PC High Precision Event Timer Table
                                             CFF8F6B0h
                                           56 
      OEM ID                                            082510
      OEM Table ID                                      OEMHPET
      OEM Revision                                      20100825h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h

  [ MCFG: Memory Mapped Configuration Space Base Address Description Table ]

      ACPI:
       ACPI                                      MCFG
                                         Memory Mapped Configuration Space Base Address Description Table
                                             CFF80410h
                                           60 
      OEM ID                                            082510
      OEM Table ID                                      OEMMCFG
      OEM Revision                                      20100825h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h

  [ OEMB: OEM Specific Information Table ]

      ACPI:
       ACPI                                      OEMB
                                         OEM Specific Information Table
                                             CFF98040h
                                           114 
      OEM ID                                            082510
      OEM Table ID                                      OEMB1543
      OEM Revision                                      20100825h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h

  [ RSD PTR: Root System Description Pointer ]

      ACPI:
       ACPI                                      RSD PTR
                                         Root System Description Pointer
                                             000FB850h
                                           20 
      OEM ID                                            ACPIAM
      RSDP Revision                                     0
      RSDT Address                                      CFF80000h

  [ RSDT: Root System Description Table ]

      ACPI:
       ACPI                                      RSDT
                                         Root System Description Table
                                             CFF80000h
                                           68 
      OEM ID                                            _ASUS_
      OEM Table ID                                      Notebook
      OEM Revision                                      20100825h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h
      RSDT Entry #0                                     CFF80200h
      RSDT Entry #1                                     CFF80390h
      RSDT Entry #2                                     CFF80410h
      RSDT Entry #3                                     CFF80450h
      RSDT Entry #4                                     CFF98040h
      RSDT Entry #5                                     CFF8F5D0h
      RSDT Entry #6                                     CFF8F6B0h
      RSDT Entry #7                                     CFF8F6F0h

  [ SLIC: Software Licensing Description Table ]

      ACPI:
       ACPI                                      SLIC
                                         Software Licensing Description Table
                                             CFF80450h
                                           374 
      OEM ID                                            _ASUS_
      OEM Table ID                                      Notebook
      OEM Revision                                      20090827h
      Creator ID                                        MSFT
      Creator Revision                                  00000097h
       SLIC                                       2.1

  [ SRAT: System Resource Affinity Table ]

      ACPI:
       ACPI                                      SRAT
                                         System Resource Affinity Table
                                             CFF8F5D0h
                                           216 
      OEM ID                                            AMD
      OEM Table ID                                      FAM_F_10
      OEM Revision                                      00000002h
      Creator ID                                        AMD
      Creator Revision                                  00000001h

    Processor Local APIC/SAPIC Affinity Structure:
      Local APIC ID                                     0
      Local SAPIC EID                                   0
      Proximity Domain                                  00000000h
                                                  

    Processor Local APIC/SAPIC Affinity Structure:
      Local APIC ID                                     1
      Local SAPIC EID                                   0
      Proximity Domain                                  00000000h
                                                  

    Processor Local APIC/SAPIC Affinity Structure:
      Local APIC ID                                     2
      Local SAPIC EID                                   0
      Proximity Domain                                  00000000h
                                                  

    Memory Affinity Structure:
      Base Address                                      00000000-00000000h
                                                   655360  (640 )
      Proximity Domain                                  00000000h
                                                  

    Memory Affinity Structure:
      Base Address                                      00000000-00100000h
                                                   3488612352  (3327 )
      Proximity Domain                                  00000000h
                                                  

    Memory Affinity Structure:
      Base Address                                      00000001-00000000h
                                                   805306368  (768 )
      Proximity Domain                                  00000000h
                                                  

  [ SSDT: Secondary System Description Table ]

      ACPI:
       ACPI                                      SSDT
                                         Secondary System Description Table
                                             CFF8F6F0h
                                           1650 
      OEM ID                                            A M I
      OEM Table ID                                      POWERNOW
      OEM Revision                                      00000001h
      Creator ID                                        AMD
      Creator Revision                                  00000001h


--------[   ]----------------------------------------------------------------------------------------

      :
                                              Microsoft Windows 7 Ultimate
                                       Vienna
                                                   ()
                                               Multiprocessor Free (32-bit)
                                                6.1.7600 (Win7 RTM)
                                       -
                                       05.01.2014
                                         C:\Windows

     :
                          
                           
      ID                                        00426-292-0000007-85677
                                            D4F6K-QK3RD-TMVMJ-BBMRX-3MBMV
        (WPA)                            ( : 28)

     :
                                           -
                                         
                                              -
                                             471  (0 ., 0 , 7 , 51 )

     :
      Common Controls                                   6.16
      Internet Explorer                                 9.0.8112.16421
      Windows Mail                                      6.1.7600.16385 (win7_rtm.090713-1255)
      Windows Media Player                              12.0.7600.16385 (win7_rtm.090713-1255)
      Windows Messenger                                 -
      MSN Messenger                                     -
      Internet Information Services (IIS)               -
      .NET Framework                                    4.0.30319.18408 built by: FX451RTMGREL
      Novell Client                                     -
      DirectX                                           DirectX 11.0
      OpenGL                                            6.1.7600.16385 (win7_rtm.090713-1255)
      ASPI                                              -

      :
                                        
       DBCS                                       
                                        
                                     
                                             
                                         
                                         
                                      
                                      


--------[  ]----------------------------------------------------------------------------------------------------

    aida64.exe               C:\Users\\Desktop\11\AIDA64Portable\App\AIDA64Extreme\aida64.exe  32         37420          30700 
    AIDA64ExtremePortable.exe  C:\Users\\Desktop\11\AIDA64Portable\AIDA64ExtremePortable.exe    32          8372          35388 
    avpui.exe                C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avpui.exe          32          4096          68240 
    BlueScreenView.exe       C:\Users\\Desktop\11\Trash\ \BlueScreenView.exe        32          7044           2952 
    CNABCSWK.EXE             C:\Windows\system32\spool\DRIVERS\W32X86\3\CNABCSWK.EXE                       32          8296           3272 
    CNAP2LAK.EXE             C:\Windows\System32\spool\drivers\w32x86\3\CNAP2LAK.EXE                       32          4240           1092 
    CNAP2RPK.EXE             C:\Windows\system32\spool\DRIVERS\W32X86\3\CNAP2RPK.EXE                       32          4936           2456 
    Dwm.exe                  C:\Windows\system32\Dwm.exe                                                   32         28972          30368 
    Explorer.EXE             C:\Windows\Explorer.EXE                                                       32         48236          36456 
    firefox.exe              C:\Program Files\Mozilla Firefox\firefox.exe                                  32           211            188 
    GrooveMonitor.exe        D:\\Microsoft Office\Office12\GrooveMonitor.exe                      32          6704           1944 
    NvBackend.exe            C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe                 32         12964           9136 
    NvTmru.exe               C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe             32          6332           2656 
    nvtray.exe               C:\Program Files\NVIDIA Corporation\Display\nvtray.exe                        32          9140           3168 
    praetorian.exe           C:\Users\\AppData\Local\Yandex\Updater\praetorian.exe            32          7176           1952 
    RtkNGUI.exe              C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe                                32          8144          12044 
    SearchFilterHost.exe     C:\Windows\system32\SearchFilterHost.exe                                      32          4640           1696 
    sidebar.exe              C:\Program Files\Windows Sidebar\sidebar.exe                                  32         48172          51228 
    taskhost.exe             C:\Windows\system32\taskhost.exe                                              32          7524           7300 
    WerFault.exe             C:\Windows\System32\WerFault.exe                                              32          9000           2128 


--------[   ]------------------------------------------------------------------------------------------

    1394ohci         1394 OHCI Compliant Host Controller                                     1394ohci.sys          6.1.7600.16385                        
    ACPI              Microsoft ACPI                                                  ACPI.sys              6.1.7600.16385                        
    AcpiPmi          ACPI Power Meter Driver                                                 acpipmi.sys           6.1.7600.16385                        
    adgnetworktdi    adgnetworktdi                                                           adgnetworktdi.sys     5.7.0.12                              
    adp94xx          adp94xx                                                                 adp94xx.sys           1.6.6.4                               
    adpahci          adpahci                                                                 adpahci.sys           1.6.6.1                               
    adpu320          adpu320                                                                 adpu320.sys           7.2.0.0                               
    AFD              Ancillary Function Driver for Winsock                                   afd.sys               6.1.7600.16802                        
    agp440           Intel AGP Bus Filter                                                    agp440.sys            6.1.7600.16385                        
    aic78xx          aic78xx                                                                 djsvs.sys             6.0.0.0                               
    AIDA64Driver     FinalWire AIDA64 Kernel Driver                                          kerneld.x32                                                 
    aliide           aliide                                                                  aliide.sys            1.2.0.0                               
    amdagp           AMD AGP Bus Filter Driver                                               amdagp.sys            6.1.7600.16385                        
    amdide           amdide                                                                  amdide.sys            6.1.7600.16385                        
    AmdK8            AMD K8 Processor Driver                                                 amdk8.sys             6.1.7600.16385                        
    AmdPPM             AMD                                                  amdppm.sys            6.1.7600.16385                        
    amdsata          amdsata                                                                 amdsata.sys           1.1.2.4                               
    amdsbs           amdsbs                                                                  amdsbs.sys            3.6.1540.127                          
    amdxata          amdxata                                                                 amdxata.sys           1.1.2.4                               
    AODDriver4.2.0   AODDriver4.2.0                                                          AODDriver2.sys        4.2.0.0                               
    AppID             AppID                                                           appid.sys             6.1.7600.16385                        
    arc              arc                                                                     arc.sys               5.2.0.10384                           
    arcsas           arcsas                                                                  arcsas.sys            5.2.0.16119                           
    AsyncMac            RAS                                       asyncmac.sys          6.1.7600.16385                        
    atapi             IDE                                                               atapi.sys             6.1.7600.16385                        
    b06bdrv          Broadcom NetXtreme II VBD                                               bxvbdx.sys            4.8.2.0                               
    b57nd60x         Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0                          b57nd60x.sys          10.100.4.0                            
    Beep             Beep                                                                                                                                
    blbdrive         blbdrive                                                                blbdrive.sys          6.1.7600.16385                        
    bowser                                                           bowser.sys            6.1.7600.16385             
    BrFiltLo         Brother USB Mass-Storage Lower Filter Driver                            BrFiltLo.sys          1.10.0.2                              
    BrFiltUp         Brother USB Mass-Storage Upper Filter Driver                            BrFiltUp.sys          1.4.0.1                               
    Brserid          Brother MFC Serial Port Interface Driver (WDM)                          Brserid.sys           1.0.1.6                               
    BrSerWdm         Brother WDM Serial driver                                               BrSerWdm.sys          1.0.0.20                              
    BrUsbMdm         Brother MFC USB Fax Only Modem                                          BrUsbMdm.sys          1.0.0.12                              
    BrUsbSer         Brother MFC USB Serial WDM Driver                                       BrUsbSer.sys          1.0.1.3                               
    BTHMODEM         Bluetooth Serial Communications Driver                                  bthmodem.sys          6.1.7600.16385                        
    cdfs             CD/DVD File System Reader                                               cdfs.sys              6.1.7600.16385             
    cdrom             CD-ROM                                                 cdrom.sys             6.1.7600.16385                        
    circlass         Consumer IR Devices                                                     circlass.sys          6.1.7600.16385                        
    CLFS               (CLFS)                                                     CLFS.sys              6.1.7600.16385                        
    CmBatt           Microsoft ACPI Control Method Battery Driver                            CmBatt.sys            6.1.7600.16385                        
    cmdide           cmdide                                                                  cmdide.sys            2.0.7.0                               
    CNG              CNG                                                                     cng.sys               6.1.7600.17035                        
    Compbatt         Compbatt                                                                compbatt.sys          6.1.7600.16385                        
    CompositeBus                                          CompositeBus.sys      6.1.7600.16385                        
    crcdisk          Crcdisk Filter Driver                                                   crcdisk.sys           6.1.7600.16385                        
    CSC                                                               csc.sys               6.1.7600.16385                        
    DfsC             DFS Namespace Client Driver                                             dfsc.sys              6.1.7600.16804             
    discache         System Attribute Cache                                                  discache.sys          6.1.7600.16385                        
    Disk                                                                         disk.sys              6.1.7600.16385                        
    drmkaud                                                 drmkaud.sys           6.1.7600.16385                        
    DXGKrnl          LDDM Graphics Subsystem                                                 dxgkrnl.sys           6.1.7600.16748                        
    ebdrv            Broadcom NetXtreme II 10 GigE VBD                                       evbdx.sys             4.8.13.0                              
    elxstor          elxstor                                                                 elxstor.sys           5.2.10.211                            
    ErrDev           Microsoft Hardware Error Device Driver                                  errdev.sys            6.1.7600.16385                        
    exfat            exFAT File System Driver                                                                                                 
    fastfat          FAT12/16/32 File System Driver                                                                                           
    fdc              Floppy Disk Controller Driver                                           fdc.sys               6.1.7600.16385                        
    FileInfo         File Information FS MiniFilter                                          fileinfo.sys          6.1.7600.16385             
    Filetrace        Filetrace                                                               filetrace.sys         6.1.7600.16385             
    flpydisk         Floppy Disk Driver                                                      flpydisk.sys          6.1.7600.16385                        
    FltMgr                                                                  fltmgr.sys            6.1.7600.16385             
    FsDepends        File System Dependency Minifilter                                       FsDepends.sys         6.1.7600.16385             
    fvevol               Bitlocker                              fvevol.sys            6.1.7600.16385                        
    gagp30kx         Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms             gagp30kx.sys          6.1.7600.16385                        
    hcw85cir         Hauppauge Consumer Infrared Receiver                                    hcw85cir.sys          1.31.27127.0                          
    HdAudAddService    UAA   High Definition Audio (Microsoft),  1.1  HdAudio.sys           6.1.7600.16385                        
    HDAudBus            UAA  High Definition Audio (Microsoft)              HDAudBus.sys          6.1.7600.16385                        
    HidBatt          HID UPS Battery Driver                                                  HidBatt.sys           6.1.7600.16385                        
    HidBth           Microsoft Bluetooth HID Miniport                                        hidbth.sys            6.1.7600.16385                        
    HidIr            Microsoft Infrared HID Driver                                           hidir.sys             6.1.7600.16385                        
    HidUsb             HID Microsoft                                            hidusb.sys            6.1.7600.16385                        
    HpSAMD           HpSAMD                                                                  HpSAMD.sys            6.12.4.32                             
    HTTP             HTTP                                                                    HTTP.sys              6.1.7600.16385                        
    hwpolicy         Hardware Policy Driver                                                  hwpolicy.sys          6.1.7600.16385                        
    i8042prt         i8042 Keyboard and PS/2 Mouse Port Driver                               i8042prt.sys          6.1.7600.16385                        
    iaStorV          iaStorV                                                                 iaStorV.sys           8.6.2.1012                            
    iirsp            iirsp                                                                   iirsp.sys             5.4.22.0                              
    IntcAzAudAddService  Service for Realtek HD Audio (WDM)                                      RTKVHDA.sys           6.0.1.7083                            
    intelide         intelide                                                                intelide.sys          6.1.7600.16385                        
    intelppm         Intel Processor Driver                                                  intelppm.sys          6.1.7600.16385                        
    IpFilterDriver     IP-                                              ipfltdrv.sys          6.1.7600.16385                        
    IPMIDRV          IPMIDRV                                                                 IPMIDrv.sys           6.1.7600.16385                        
    IPNAT            IP Network Address Translator                                           ipnat.sys             6.1.7600.16385                        
    IRENUM           IR Bus Enumerator                                                       irenum.sys            6.1.7600.16385                        
    isapnp           isapnp                                                                  isapnp.sys            6.1.7600.16385                        
    iScsiPrt         iScsiPort Driver                                                        msiscsi.sys           6.1.7600.16385                        
    kbdclass                                                          kbdclass.sys          6.1.7600.16385                        
    kbdhid             HID                                                  kbdhid.sys            6.1.7600.16385                        
    kl1              kl1                                                                     kl1.sys               6.8.0.35                              
    klflt            klflt                                                                   klflt.sys             1.3.0.51                              
    KLIF             Kaspersky Lab Driver                                                    klif.sys              8.13.0.372                 
    KLIM6            Kaspersky Anti-Virus NDIS 6 Filter                                      klim6.sys             8.0.0.71                              
    klkbdflt         Kaspersky Lab KLKBDFLT                                                  klkbdflt.sys          8.10.0.39                             
    klmouflt         Kaspersky Lab KLMOUFLT                                                  klmouflt.sys          8.10.0.41                             
    klpd             klpd                                                                    klpd.sys              1.0.0.22                              
    kltdi            kltdi                                                                   kltdi.sys             1.5.0.26                              
    kneps            kneps                                                                   kneps.sys             5.5.0.65                              
    KSecDD           KSecDD                                                                  ksecdd.sys            6.1.7600.17035                        
    KSecPkg          KSecPkg                                                                 ksecpkg.sys           6.1.7600.17035                        
    lltdio           Link-Layer Topology Discovery Mapper I/O Driver                         lltdio.sys            6.1.7600.16385                        
    LSI_FC           LSI_FC                                                                  lsi_fc.sys            1.28.3.52                             
    LSI_SAS          LSI_SAS                                                                 lsi_sas.sys           1.28.3.52                             
    LSI_SAS2         LSI_SAS2                                                                lsi_sas2.sys          2.0.2.71                              
    LSI_SCSI         LSI_SCSI                                                                lsi_scsi.sys          1.28.3.67                             
    luafv                                            luafv.sys             6.1.7600.16385             
    megasas          megasas                                                                 megasas.sys           4.5.1.32                              
    MegaSR           MegaSR                                                                  MegaSR.sys            13.5.409.2009                         
    Modem            Modem                                                                   modem.sys             6.1.7600.16385                        
    monitor          Microsoft Monitor Class Function Driver Service                         monitor.sys           6.1.7600.16385                        
    mouclass                                                                mouclass.sys          6.1.7600.16385                        
    mouhid             HID                                                        mouhid.sys            6.1.7600.16385                        
    mountmgr                                                        mountmgr.sys          6.1.7600.16385                        
    mpio             mpio                                                                    mpio.sys              6.1.7600.16385                        
    mpsdrv              Windows                                 mpsdrv.sys            6.1.7600.16385                        
    MRxDAV              WebDav                                 mrxdav.sys            6.1.7600.16385             
    mrxsmb              - SMB                              mrxsmb.sys            6.1.7600.16808             
    mrxsmb10         - SMB 1.x                                            mrxsmb10.sys          6.1.7600.16847             
    mrxsmb20         - SMB 2.0                                            mrxsmb20.sys          6.1.7600.16808             
    msahci           msahci                                                                  msahci.sys            6.1.7600.16385                        
    msdsm            msdsm                                                                   msdsm.sys             6.1.7600.16385                        
    Msfs             Msfs                                                                                                                     
    mshidkmdf        Pass-through HID to KMDF Filter Driver                                  mshidkmdf.sys         6.1.7600.16385                        
    MSICDSetup       MSICDSetup                                                              CDriver.sys                                                 
    msisadrv         msisadrv                                                                msisadrv.sys          6.1.7600.16385                        
    MSKSSRV             Microsoft                                   MSKSSRV.sys           6.1.7600.16385                        
    MSPCLOCK            Microsoft                               MSPCLOCK.sys          6.1.7600.16385                        
    MSPQM                Microsoft                     MSPQM.sys             6.1.7600.16385                        
    MsRPC            MsRPC                                                                                                                               
    mssmbios         Microsoft System Management BIOS                                 mssmbios.sys          6.1.7600.16385                        
    MSTEE              Tee/Sink-to-Sink Microsoft                      MSTEE.sys             6.1.7600.16385                        
    MTConfig         Microsoft Input Configuration Driver                                    MTConfig.sys          6.1.7600.16385                        
    Mup              Mup                                                                     mup.sys               6.1.7600.16385             
    NativeWifiP      NativeWiFi Filter                                                       nwifi.sys             6.1.7600.16385                        
    NDIS               NDIS                                                  ndis.sys              6.1.7600.16385                        
    NdisCap          NDIS Capture LightWeight Filter                                         ndiscap.sys           6.1.7600.16385                        
    NdisTapi         NDIS- TAPI                                      ndistapi.sys          6.1.7600.16385                        
    Ndisuio          NDIS Usermode I/O Protocol                                              ndisuio.sys           6.1.7600.16385                        
    NdisWan          NDIS- WAN                                       ndiswan.sys           6.1.7600.16385                        
    NDProxy          NDIS Proxy                                                                                                                          
    NetBIOS          NetBIOS Interface                                                       netbios.sys           6.1.7600.16385             
    NetBT            NetBT                                                                   netbt.sys             6.1.7600.16385                        
    nfrd960          nfrd960                                                                 nfrd960.sys           7.10.0.0                              
    Npfs             Npfs                                                                                                                     
    nsiproxy         NSI proxy service driver.                                               nsiproxy.sys          6.1.7600.16385                        
    Ntfs             Ntfs                                                                                                                     
    Null             Null                                                                                                                                
    nv_agp           NVIDIA nForce AGP Bus Filter                                            nv_agp.sys            6.1.7600.16385                        
    NVHDA            Service for NVIDIA High Definition Audio Driver                         nvhda32v.sys          1.3.26.4                              
    nvlddmkm         nvlddmkm                                                                nvlddmkm.sys          9.18.13.3182                          
    nvraid           nvraid                                                                  nvraid.sys            10.6.0.16                             
    nvstor           nvstor                                                                  nvstor.sys            10.6.0.16                             
    nvvad_WaveExtensible  NVIDIA Virtual Audio Device (Wave Extensible) (WDM)                     nvvad32v.sys          1.2.19.0                              
    ohci1394         1394 OHCI Compliant Host Controller (Legacy)                            ohci1394.sys          6.1.7600.16385                        
    Parport                                                         parport.sys           6.1.7600.16385                        
    partmgr                                                                 partmgr.sys           6.1.7600.16979                        
    Parvdm           Parvdm                                                                  parvdm.sys            6.1.7600.16385                        
    pci               PCI                                                         pci.sys               6.1.7600.16385                        
    pciide           pciide                                                                  pciide.sys            6.1.7600.16385                        
    pcmcia           pcmcia                                                                  pcmcia.sys            6.1.7600.16385                        
    pcw              Performance Counters for Windows Driver                                 pcw.sys               6.1.7600.16385                        
    PEAUTH           PEAUTH                                                                  peauth.sys            6.1.7600.16385                        
    PnkBstrK         PnkBstrK                                                                PnkBstrK.sys                                                
    PptpMiniport     - WAN (PPTP)                                                    raspptp.sys           6.1.7600.16385                        
    Processor        Processor Driver                                                        processr.sys          6.1.7600.16385                        
    Psched             QoS                                                 pacer.sys             6.1.7600.16385                        
    ql2300           ql2300                                                                  ql2300.sys            9.1.8.6                               
    ql40xx           ql40xx                                                                  ql40xx.sys            2.1.3.20                              
    QWAVEdrv          QWAVE                                                           qwavedrv.sys          6.1.7600.16385                        
    RasAcd           Remote Access Auto Connection Driver                                    rasacd.sys            6.1.7600.16385                        
    RasAgileVpn      WAN Miniport (IKEv2)                                                    AgileVpn.sys          6.1.7600.16385                        
    Rasl2tp          - WAN (L2TP)                                                    rasl2tp.sys           6.1.7600.16385                        
    RasPppoe          PPPOE                                          raspppoe.sys          6.1.7600.16385                        
    RasSstp          - WAN (SSTP)                                                    rassstp.sys           6.1.7600.16385                        
    rdbss                                               rdbss.sys             6.1.7600.16385             
    rdpbus           Remote Desktop Device Redirector Bus Driver                             rdpbus.sys            6.1.7600.16385                        
    RDPCDD           RDPCDD                                                                  RDPCDD.sys            6.1.7600.16385                        
    RDPDR            Terminal Server Device Redirector Driver                                rdpdr.sys             6.1.7600.16385                        
    RDPENCDD         RDP Encoder Mirror Driver                                               rdpencdd.sys          6.1.7600.16385                        
    RDPREFMP         Reflector Display Driver used to gain access to graphics data           rdprefmp.sys          6.1.7600.16385                        
    RDPWD            RDP Winstation Driver                                                                                                               
    rdyboost         ReadyBoost                                                              rdyboost.sys          6.1.7600.16385                        
    rspndr           Link-Layer Topology Discovery Responder                                 rspndr.sys            6.1.7600.16385                        
    RTCore32         RTCore32                                                                RTCore32.sys                                                
    RTL8167           Realtek 8167 NT                                                 Rt86win7.sys          7.2.1125.2008                         
    s3cap            s3cap                                                                   vms3cap.sys           6.1.7600.16385                        
    sbp2port         sbp2port                                                                sbp2port.sys          6.1.7600.16385                        
    scfilter           -  PnP                                  scfilter.sys          6.1.7600.16385                        
    secdrv           Security Driver                                                                                                                     
    Serenum            Serenum                                                 serenum.sys           6.1.7600.16385                        
    Serial                                                      serial.sys            6.1.7600.16385                        
    sermouse         Serial Mouse Driver                                                     sermouse.sys          6.1.7600.16385                        
    sffdisk          SFF Storage Class Driver                                                sffdisk.sys           6.1.7600.16385                        
    sffp_mmc         SFF Storage Protocol Driver for MMC                                     sffp_mmc.sys          6.1.7600.16385                        
    sffp_sd          SFF Storage Protocol Driver for SDBus                                   sffp_sd.sys           6.1.7600.16385                        
    sfloppy          High-Capacity Floppy Disk Drive                                         sfloppy.sys           6.1.7600.16385                        
    sisagp           SIS AGP Bus Filter                                                      sisagp.sys            6.1.7600.16385                        
    SiSRaid2         SiSRaid2                                                                SiSRaid2.sys          5.1.1039.2600                         
    SiSRaid4         SiSRaid4                                                                sisraid4.sys          5.1.1039.3600                         
    Smb                TCP/IP  TCP/IPv6 ( SMB)                        smb.sys               6.1.7600.16385                        
    spldr            Security Processor Loader Driver                                                                                                    
    srv                Server SMB 1.xxx                                        srv.sys               6.1.7600.16806             
    srv2               Server SMB 2.xxx                                        srv2.sys              6.1.7600.16806             
    srvnet           srvnet                                                                  srvnet.sys            6.1.7600.16806             
    stexstor         stexstor                                                                stexstor.sys          5.0.1.1                               
    storflt                                   vmstorfl.sys          6.1.7600.16385                        
    storvsc          storvsc                                                                 storvsc.sys           6.1.7600.16385                        
    swenum                                                             swenum.sys            6.1.7600.16385                        
    Tcpip              TCP/IP                                                tcpip.sys             6.1.7600.17206                        
    TCPIP6           Microsoft IPv6 Protocol Driver                                          tcpip.sys             6.1.7600.17206                        
    tcpipreg         TCP/IP Registry Compatibility                                           tcpipreg.sys          6.1.7600.16385                        
    TDPIPE           TDPIPE                                                                  tdpipe.sys            6.1.7600.16385                        
    TDTCP            TDTCP                                                                   tdtcp.sys             6.1.7600.16963                        
    tdx                NetIO Legacy TDI                                      tdx.sys               6.1.7600.16385                        
    TermDD                                                         termdd.sys            6.1.7600.16385                        
    tssecsrv         Remote Desktop Services Security Filter Driver                          tssecsrv.sys          6.1.7600.16385                        
    tunnel                Microsoft                        tunnel.sys            6.1.7600.16385                        
    uagp35           Microsoft AGPv3.5 Filter                                                uagp35.sys            6.1.7600.16385                        
    udfs             udfs                                                                    udfs.sys              6.1.7600.16385             
    uliagpkx         Uli AGP Bus Filter                                                      uliagpkx.sys          6.1.7600.16385                        
    umbus            UMBus                                               umbus.sys             6.1.7600.16385                        
    UmPass           Microsoft UMPass Driver                                                 umpass.sys            6.1.7600.16385                        
    usbccgp              USB (Microsoft)         usbccgp.sys           6.1.7600.16385                        
    usbcir           eHome Infrared Receiver (USBCIR)                                        usbcir.sys            6.1.7600.16385                        
    usbehci            Microsoft USB 2.0  -       usbehci.sys           6.1.7600.16385                        
    usbhub             USB- ()                      usbhub.sys            6.1.7600.16385                        
    usbohci            Microsoft USB  -              usbohci.sys           6.1.7600.16385                        
    usbprint           Microsoft USB                                           usbprint.sys          6.1.7600.16385                        
    USBSTOR              USB                                  USBSTOR.SYS           6.1.7600.16385                        
    usbuhci          Microsoft USB Universal Host Controller Miniport Driver                 usbuhci.sys           6.1.7600.16385                        
    vdrvroot             ()                   vdrvroot.sys          6.1.7600.16385                        
    vga              vga                                                                     vgapnp.sys            6.1.7600.16385                        
    VgaSave          VgaSave                                                                 vga.sys               6.1.7600.16385                        
    vhdmp            vhdmp                                                                   vhdmp.sys             6.1.7600.16385                        
    viaagp           VIA AGP Bus Filter                                                      viaagp.sys            6.1.7600.16385                        
    ViaC7            VIA C7 Processor Driver                                                 viac7.sys             6.1.7600.16385                        
    viaide           viaide                                                                  viaide.sys            6.0.6000.170                          
    vmbus             VMBus                                                              vmbus.sys             6.1.7600.16385                        
    VMBusHID         VMBusHID                                                                VMBusHID.sys          6.1.7600.16385                        
    volmgr                                                             volmgr.sys            6.1.7600.16385                        
    volmgrx                                                        volmgrx.sys           6.1.7600.16385                        
    volsnap                                                         volsnap.sys           6.1.7600.16385                        
    vsmraid          vsmraid                                                                 vsmraid.sys           6.0.6000.6210                         
    vwifibus           Virtual WiFi                                               vwifibus.sys          6.1.7600.16385                        
    WacomPen         Wacom Serial Pen HID Driver                                             wacompen.sys          6.1.7600.16385                        
    WANARP              IP ARP                                       wanarp.sys            6.1.7600.16385                        
    Wanarpv6            IPv6 ARP                                     wanarp.sys            6.1.7600.16385                        
    Wd               Wd                                                                      wd.sys                6.1.7600.16385                        
    Wdf01000         Kernel Mode Driver Frameworks service                                   Wdf01000.sys          1.9.7600.16385                        
    WfpLwf           WFP Lightweight Filter                                                  wfplwf.sys            6.1.7600.16385                        
    WIMMount         WIMMount                                                                wimmount.sys          6.1.7600.16385             
    WinUsb           WinUsb                                                                  WinUsb.sys            6.1.7600.16385                        
    WmiAcpi          Microsoft Windows Management Interface for ACPI                         wmiacpi.sys           6.1.7600.16385                        
    ws2ifsl           WinSock IFS                                                     ws2ifsl.sys           6.1.7600.16385                        
    WudfPf           User Mode Driver Frameworks Platform Driver                             WudfPf.sys            6.1.7600.16385                        
    WUDFRd           WUDFRd                                                                  WUDFRd.sys            6.1.7600.16385                        


--------[  ]------------------------------------------------------------------------------------------------------

    Adguard Service                    Adguard Service                                                         AdguardSvc.exe        5.8.1008.5204                  LocalSystem
    AdobeFlashPlayerUpdateSvc          Adobe Flash Player Update Service                                       FlashPlayerUpdateService.exe  11.9.900.170                   LocalSystem
    AeLookupSvc                                                              svchost.exe           6.1.7600.16385                       localSystem
    ALG                                                                             alg.exe               6.1.7600.16385                 NT AUTHORITY\LocalService
    AMD FUEL Service                   AMD FUEL Service                                                        Program                                              LocalSystem
    AppIDSvc                                                                            svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    Appinfo                                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    AppMgmt                                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    aspnet_state                         ASP.NET                                                aspnet_state.exe      4.0.30319.18408                NT AUTHORITY\NetworkService
    AudioEndpointBuilder                   Windows Audio                        svchost.exe           6.1.7600.16385                       LocalSystem
    Audiosrv                           Windows Audio                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    AVP                                Kaspersky Anti-Virus Service                                            avp.exe               14.0.0.4764                    LocalSystem
    AxInstSV                            ActiveX (AxInstSV)                                           svchost.exe           6.1.7600.16385                       LocalSystem
    BDESVC                                BitLocker                                      svchost.exe           6.1.7600.16385                       localSystem
    BFE                                                                                 svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    BITS                                   (BITS)                         svchost.exe           6.1.7600.16385                       LocalSystem
    Browser                                                                                  svchost.exe           6.1.7600.16385                       LocalSystem
    bthserv                              Bluetooth                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    CertPropSvc                                                                      svchost.exe           6.1.7600.16385                       LocalSystem
    clr_optimization_v2.0.50727_32     Microsoft .NET Framework NGEN v2.0.50727_X86                            mscorsvw.exe          2.0.50727.4927                 LocalSystem
    clr_optimization_v4.0.30319_32     Microsoft .NET Framework NGEN v4.0.30319_X86                            mscorsvw.exe          4.0.30319.18408                LocalSystem
    COMSysApp                            COM+                                               dllhost.exe           6.1.7600.16385                 LocalSystem
    CryptSvc                                                                                 svchost.exe           6.1.7600.16385                       NT Authority\NetworkService
    CscService                                                                                  svchost.exe           6.1.7600.16385                       LocalSystem
    DcomLaunch                            DCOM-                                   svchost.exe           6.1.7600.16385                       LocalSystem
    defragsvc                                                                               svchost.exe           6.1.7600.16385                 localSystem
    Dhcp                               DHCP-                                                             svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    Dnscache                           DNS-                                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    dot3svc                                                                              svchost.exe           6.1.7600.16385                       localSystem
    DPS                                                                               svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    EapHost                                (EAP)                         svchost.exe           6.1.7600.16385                       localSystem
    EFS                                   (EFS)                                      lsass.exe             6.1.7600.16915                       LocalSystem
    ehRecvr                              Windows Media Center                                    ehRecvr.exe           6.1.7600.16385                 NT AUTHORITY\networkService
    ehSched                              Windows Media Center                                ehsched.exe           6.1.7600.16385                 NT AUTHORITY\networkService
    eventlog                             Windows                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    EventSystem                          COM+                                                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Fax                                                                                                    fxssvc.exe            6.1.7600.16385                 NT AUTHORITY\NetworkService
    fdPHost                                                                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    FDResPub                                                               svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    FontCache                             Windows                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    FontCache3.0.0.0                     Windows Presentation Foundation 3.0.0.0                     PresentationFontCache.exe  3.0.6920.4902                  NT Authority\LocalService
    gpsvc                                                                               svchost.exe           6.1.7600.16385                       LocalSystem
    Guard.Mail.ru                      Guard.Mail.ru                                                           GuardMailRu.exe       1.0.0.620                      LocalSystem
    hidserv                              HID-                                                svchost.exe           6.1.7600.16385                       LocalSystem
    hkmsvc                                                      svchost.exe           6.1.7600.16385                       localSystem
    HomeGroupListener                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    HomeGroupProvider                                                                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    idsvc                              Windows CardSpace                                                       infocard.exe          3.0.4506.4926                        LocalSystem
    IISExpressSVC                      IIS Express service                                                     IISexpressSVC.exe     5.0.0.0                        LocalSystem
    IKEEXT                               IPsec        IP     svchost.exe           6.1.7600.16385                       LocalSystem
    IPBusEnum                           IP- PnP-X                                              svchost.exe           6.1.7600.16385                       LocalSystem
    iphlpsvc                             IP                                               svchost.exe           6.1.7600.16385                       LocalSystem
    KeyIso                               CNG                                                     lsass.exe             6.1.7600.16915                       LocalSystem
    KtmRm                              KtmRm                            svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    LanmanServer                                                                                         svchost.exe           6.1.7600.16385                       LocalSystem
    LanmanWorkstation                                                                            svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    lansweeperservice                  Lansweeper Server                                                       Lansweeperservice.exe  5.1.0.27                       LocalSystem
    lltdsvc                                                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    lmhosts                              NetBIOS  TCP/IP                                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Mcx2Svc                              Media Center                                      svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    Microsoft Office Groove Audit Service  Microsoft Office Groove Audit Service                                   GrooveAuditService.exe  12.0.4518.1014                 NT AUTHORITY\LocalService
    MMCSS                                                                         svchost.exe           6.1.7600.16385                       LocalSystem
    MozillaMaintenance                 Mozilla Maintenance Service                                             maintenanceservice.exe  26.0.0.5087                    LocalSystem
    MpsSvc                              Windows                                                      svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    MSDTC                                                                   msdtc.exe             2001.12.8530.16385                NT AUTHORITY\NetworkService
    MSiSCSI                               iSCSI                                      svchost.exe           6.1.7600.16385                       LocalSystem
    msiserver                           Windows                                                      msiexec.exe           5.0.7600.16385                 LocalSystem
    napagent                                                                         svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    Netlogon                                                                                lsass.exe             6.1.7600.16915                       LocalSystem
    Netman                                                                                   svchost.exe           6.1.7600.16385                       LocalSystem
    NetMsmqActivator                     Net.Msmq                                         SMSvcHost.exe         4.0.30319.18408                      NT AUTHORITY\NetworkService
    NetPipeActivator                     Net.Pipe                                         SMSvcHost.exe         4.0.30319.18408                      NT AUTHORITY\LocalService
    netprofm                                                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    NetTcpActivator                      Net.Tcp                                          SMSvcHost.exe         4.0.30319.18408                      NT AUTHORITY\LocalService
    NetTcpPortSharing                       Net.Tcp                                  SMSvcHost.exe         4.0.30319.18408                      NT AUTHORITY\LocalService
    NlaSvc                                                                     svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    nsi                                                                          svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    NvNetworkService                   NVIDIA Network Service                                                  NvNetworkService.exe  1.0.0.1                        LocalSystem
    NvStreamSvc                        NVIDIA Streamer Service                                                 nvstreamsvc.exe       1.6.85.0                       LocalSystem
    nvsvc                              NVIDIA Display Driver Service                                           nvvsvc.exe            8.17.13.3182                   LocalSystem
    odserv                             Microsoft Office Diagnostics Service                                    ODSERV.EXE            12.0.4518.1014                 LocalSystem
    ose                                Office Source Engine                                                    OSE.EXE               12.0.4518.1014                 LocalSystem
    p2pimsvc                                                            svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    p2psvc                                                                         svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PcaSvc                                                               svchost.exe           6.1.7600.16385                       LocalSystem
    PeerDistSvc                        BranchCache                                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    pla                                                                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PlugPlay                           Plug-and-Play                                                           svchost.exe           6.1.7600.16385                       LocalSystem
    PnkBstrA                           PnkBstrA                                                                PnkBstrA.exe                                         LocalSystem
    PnkBstrB                           PnkBstrB                                                                PnkBstrB.exe                                         LocalSystem
    PNRPAutoReg                            PNRP                                 svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PNRPsvc                             PNRP                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PolicyAgent                          IPsec                                                    svchost.exe           6.1.7600.16385                       NT Authority\NetworkService
    Power                                                                                               svchost.exe           6.1.7600.16385                       LocalSystem
    ProfSvc                                                                         svchost.exe           6.1.7600.16385                       LocalSystem
    ProtectedStorage                                                                        lsass.exe             6.1.7600.16915                       LocalSystem
    QWAVE                              Quality Windows Audio Video Experience                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    RasAuto                                                 svchost.exe           6.1.7600.16385                       localSystem
    RasMan                                                                svchost.exe           6.1.7600.16385                       localSystem
    RemoteAccess                                                                  svchost.exe           6.1.7600.16385                       localSystem
    RemoteRegistry                                                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    RpcEptMapper                          RPC                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    RpcLocator                             (RPC)                                locator.exe           6.1.7600.16385                 NT AUTHORITY\NetworkService
    RpcSs                                 (RPC)                                          svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    SamSs                                                                   lsass.exe             6.1.7600.16915                       LocalSystem
    SCardSvr                           -                                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Schedule                                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    SCPolicySvc                          -                                            svchost.exe           6.1.7600.16385                       LocalSystem
    SDRSVC                              Windows                                                       svchost.exe           6.1.7600.16385                 localSystem
    seclogon                                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    SENS                                                                    svchost.exe           6.1.7600.16385                       LocalSystem
    SensrSvc                                                                       svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    SessionEnv                                                           svchost.exe           6.1.7600.16385                       localSystem
    SharedAccess                             (ICS)                            svchost.exe           6.1.7600.16385                       LocalSystem
    ShellHWDetection                                                            svchost.exe           6.1.7600.16385                       LocalSystem
    SNMPTRAP                            SNMP                                                            snmptrap.exe          6.1.7600.16385                 NT AUTHORITY\LocalService
    Spooler                                                                                     spoolsv.exe           6.1.7600.16661                 LocalSystem
    sppsvc                                                                        sppsvc.exe            6.1.7600.16385                 NT AUTHORITY\NetworkService
    sppuinotify                          SPP                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    SSDPSRV                             SSDP                                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    SstpSvc                             SSTP                                                             svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    Steam Client Service               Steam Client Service                                                    SteamService.exe      2.4.35.50                      LocalSystem
    Stereo Service                     NVIDIA Stereoscopic 3D Driver Service                                   nvSCPAPISvr.exe       7.17.13.3182                   LocalSystem
    StiSvc                                Windows (WIA)                               svchost.exe           6.1.7600.16385                 NT Authority\LocalService
    swprv                                  (Microsoft)                  svchost.exe           6.1.7600.16385                 LocalSystem
    SysMain                            Superfetch                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    TabletInputService                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    TapiSrv                                                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    TBS                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    TermService                                                                    svchost.exe           6.1.7600.16385                       NT Authority\NetworkService
    Themes                                                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    THREADORDER                                                                       svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    TrkWks                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    TrustedInstaller                     Windows                                              TrustedInstaller.exe  6.1.7600.16385                 localSystem
    UI0Detect                                                                     UI0Detect.exe         6.1.7600.16385                 LocalSystem
    UmRdpService                                svchost.exe           6.1.7600.16385                       localSystem
    upnphost                             PNP-                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    UxSms                                                           svchost.exe           6.1.7600.16385                       localSystem
    VaultSvc                                                                             lsass.exe             6.1.7600.16915                       LocalSystem
    vds                                                                                         vds.exe               6.1.7600.16385                 LocalSystem
    VSS                                                                                  vssvc.exe             6.1.7600.16385                 LocalSystem
    W32Time                              Windows                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WatAdminSvc                           Windows                                     WatAdminSvc.exe       7.1.7600.16395                 LocalSystem
    wbengine                                                                wbengine.exe          6.1.7600.16385                 localSystem
    WbioSrvc                             Windows                                           svchost.exe           6.1.7600.16385                       LocalSystem
    wcncsvc                              Windows -                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WcsPlugInService                     Windows (WCS)                                          svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WdiServiceHost                                                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WdiSystemHost                                                                        svchost.exe           6.1.7600.16385                       LocalSystem
    WebClient                          -                                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Wecsvc                               Windows                                                 svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    wercplsupport                          "     "  svchost.exe           6.1.7600.16385                       localSystem
    WerSvc                                Windows                                       svchost.exe           6.1.7600.16385                       localSystem
    WinDefend                           Windows                                                        svchost.exe           6.1.7600.16385                       LocalSystem
    WinHttpAutoProxySvc                   - WinHTTP                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Winmgmt                              Windows                                       svchost.exe           6.1.7600.16385                       localSystem
    WinRM                                 Windows (WS-Management)                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    Wlansvc                              WLAN                                               svchost.exe           6.1.7600.16385                       LocalSystem
    wmiApSrv                           WMI Performance Adapter                                                 WmiApSrv.exe          6.1.7600.16385                 localSystem
    WMPNetworkSvc                           Windows Media               wmpnetwk.exe          12.0.7600.16385                NT AUTHORITY\NetworkService
    WPCSvc                             Parental Controls                                                       svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    WPDBusEnum                                                           svchost.exe           6.1.7600.16385                       LocalSystem
    wscsvc                                                                         svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WSearch                            Windows Search                                                          SearchIndexer.exe     7.0.7600.16385                 LocalSystem
    wuauserv                             Windows                                                svchost.exe           6.1.7600.16385                       LocalSystem
    wudfsvc                            Windows Driver Foundation - User-mode Driver Framework                  svchost.exe           6.1.7600.16385                       LocalSystem
    WwanSvc                             WWAN                                                      svchost.exe           6.1.7600.16385                       NT Authority\LocalService


--------[  AX ]----------------------------------------------------------------------------------------------------

    bdaplgin.ax                6.1.7600.16385              Microsoft BDA Device Control Plug-in for MPEG2 based networks.
    g711codc.ax                6.1.7600.16385              Intel G711 CODEC
    iac25_32.ax                2.0.5.53                      Indeo audio
    ir41_32.ax                 4.51.16.3                   Intel Indeo Video 4.5
    ivfsrc.ax                  5.10.2.51                    Intel Indeo video IVF  5.10
    ksproxy.ax                 6.1.7600.16385              WDM Streaming ActiveMovie Proxy
    kstvtune.ax                6.1.7600.16385               - WDM
    kswdmcap.ax                6.1.7600.16385                WDM
    ksxbar.ax                  6.1.7600.16385              WDM Streaming Crossbar
    mpeg2data.ax               6.6.7600.16867              Microsoft MPEG-2 Section and Table Acquisition Module
    mpg2splt.ax                6.6.7600.16724              DirectShow MPEG-2 Splitter.
    msdvbnp.ax                 6.6.7600.16867              Microsoft Network Provider for MPEG2 based networks.
    msnp.ax                    6.6.7600.16867              Microsoft Network Provider for MPEG2 based networks.
    psisrndr.ax                6.6.7600.16867              Microsoft Transport Information Filter for MPEG2 based networks.
    vbicodec.ax                6.6.7600.16385              Microsoft VBI Codec
    vbisurf.ax                 6.1.7600.16385              VBI Surface Allocator Filter
    vidcap.ax                  6.1.7600.16385              Video Capture Interface Server
    wstpager.ax                6.6.7600.16385              Microsoft Teletext Server


--------[  DLL ]---------------------------------------------------------------------------------------------------

    aaclient.dll               6.1.7600.17233                  
    accessibilitycpl.dll       6.1.7600.16385                 
    acctres.dll                6.1.7600.16385                     (Microsoft)
    acledit.dll                6.1.7600.16385                 ACL
    aclui.dll                  6.1.7600.16385                
    acpiservicevna.dll                                     
    acppage.dll                6.1.7600.16385                  ""
    acproxy.dll                6.1.7600.16385               DLL  AUTOCHK
    actioncenter.dll           6.1.7600.16385               
    actioncentercpl.dll        6.1.7600.16385                 
    actionqueue.dll            6.1.7600.16385              Unattend Action Queue Generator / Executor
    activeds.dll               6.1.7600.16385               DLL   AD
    actxprxy.dll               6.1.7600.16385              ActiveX Interface Marshaling Library
    admparse.dll               9.0.8112.16421              IEAK Global Policy Template Parser
    admtmpl.dll                6.1.7600.16385               " "
    adprovider.dll             6.1.7600.16385               DLL adprovider
    adsldp.dll                 6.1.7600.16385              ADs LDAP Provider DLL
    adsldpc.dll                6.1.7600.16385               DLL  LDAP AD
    adsmsext.dll               6.1.7600.16385              ADs LDAP Provider DLL
    adsnt.dll                  6.1.7600.16385               DLL    Windows NT
    adtschema.dll              6.1.7600.16385                 
    advapi32.dll               6.1.7600.16385                API Windows 32
    advpack.dll                8.0.7600.16385              ADVPACK
    aecache.dll                6.1.7600.16385              AECache Sysprep Plugin
    aeevts.dll                 6.1.7600.16385                  
    aeinv.dll                  6.1.7600.16385              Application Experience Program Inventory Component
    aelupsvc.dll               6.1.7600.16385                 
    aepdu.dll                  6.1.7600.16385                   
    aepic.dll                  6.1.7600.16385              Application Experience Program Cache
    aertacap.dll               2.9.32.0                    Capture Noise Filters (32-bit)
    aertaren.dll               1.0.32.11                   Render Noise Filters (32-bit)
    alttab.dll                 6.1.7600.16385              Windows Shell Alt Tab
    amstream.dll               6.6.7600.16385              DirectShow Runtime.
    amxread.dll                6.1.7600.16385              API Tracing Manifest Read Library
    apds.dll                   6.1.7600.16385                  Microsoft
    apilogen.dll               6.1.7600.16385                 API
    api-ms-win-core-console-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-datetime-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-debug-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-delayload-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-errorhandling-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-fibers-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-file-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-handle-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-heap-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-interlocked-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-io-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-libraryloader-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-localization-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-localregistry-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-memory-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-misc-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-namedpipe-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-processenvironment-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-processthreads-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-profile-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-rtlsupport-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-string-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-synch-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-sysinfo-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-threadpool-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-util-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-core-xstate-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-security-base-l1-1-0.dll  6.1.7600.17206              ApiSet Stub DLL
    api-ms-win-security-lsalookup-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-security-sddl-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-core-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-management-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-management-l2-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-winsvc-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    apircl.dll                 6.1.7600.16385              Microsoft InfoTech IR Local DLL
    apisetschema.dll           6.1.7600.16385              ApiSet Schema DLL
    apphelp.dll                6.1.7600.16481                 
    apphlpdm.dll               6.1.7600.16385                 
    appidapi.dll               6.1.7600.16385               API-  
    appidpolicyengineapi.dll   6.1.7600.16385              AppId Policy Engine API Module
    appidsvc.dll               6.1.7600.16385                
    appinfo.dll                6.1.7600.16385                 
    appmgmts.dll               6.1.7600.16385                
    appmgr.dll                 6.1.7600.16385                 
    apss.dll                   6.1.7600.16385              Microsoft InfoTech Storage System Library
    asferror.dll               12.0.7600.16385               ASF
    aspnet_counters.dll        4.0.30319.18408             Microsoft ASP.NET Performance Counter Shim DLL
    asycfilt.dll               6.1.7600.16544              
    atl.dll                    3.5.2284.0                  ATL Module for Windows XP (Unicode)
    atl100.dll                 10.0.40219.1                ATL Module for Windows
    atl110.dll                 11.0.50727.1                ATL Module for Windows
    atmfd.dll                  5.1.2.237                   Windows NT OpenType/Type 1 Font Driver
    atmlib.dll                 5.1.2.237                   Windows NT OpenType/Type 1 API Library.
    audiodev.dll               6.1.7600.16385                   
    audioeng.dll               6.1.7600.16385              Audio Engine
    audiokse.dll               6.1.7600.16385              Audio Ks Endpoint
    audiolibvc.dll                                         
    audioses.dll               6.1.7600.16385                
    audiosrv.dll               6.1.7600.16385               Windows Audio
    auditcse.dll               6.1.7600.16385              CSE   Windows
    auditnativesnapin.dll      6.1.7600.16385                    
    auditpolicygpinterop.dll   6.1.7600.16385                 
    auditpolmsg.dll            6.1.7600.16385                MMC  
    authfwcfg.dll              6.1.7600.16385               Windows      
    authfwgp.dll               6.1.7600.16385               Windows c      
    authfwsnapin.dll           6.1.7600.16385              Microsoft.WindowsFirewall.SnapIn
    authfwwizfwk.dll           6.1.7600.16385              Wizard Framework
    authui.dll                 6.1.7600.16385                
    authz.dll                  6.1.7600.16385              Authorization Framework
    autoplay.dll               6.1.7600.16385               ( )
    auxiliarydisplayapi.dll    6.1.7600.16385              Microsoft Windows SideShow API
    auxiliarydisplayclassinstaller.dll  6.1.7600.16385                 Microsoft Windows SideShow -  
    auxiliarydisplaycpl.dll    6.1.7600.16385                Microsoft Windows SideShow
    auxiliarydisplaydriverlib.dll  6.1.7600.16385              Microsoft Windows SideShow class extension component
    auxiliarydisplayservices.dll  6.1.7600.16385               Microsoft Windows SideShow
    avicap.dll                 1.15.0.1                    AVI Capture DLL
    avicap32.dll               6.1.7600.16385                 AVI
    avifil32.dll               6.1.7600.16490                 AVI
    avifile.dll                4.90.0.3000                 Microsoft AVI File support library
    avrt.dll                   6.1.7600.16385              Multimedia Realtime Runtime
    axinstsv.dll               6.1.7600.16385                ActiveX
    azroles.dll                6.1.7600.16385              azroles Module
    azroleui.dll               6.1.7600.16385               
    azsqlext.dll               6.1.7600.16385              AzMan Sql Audit Extended Stored Procedures Dll
    basecsp.dll                6.1.7600.16385                 - (Microsoft)
    basesrv.dll                6.1.7600.16385              Windows NT BASE API Server DLL
    batmeter.dll               6.1.7600.16385              Battery Meter Helper DLL
    batt.dll                   6.1.7600.16385                
    bcdprov.dll                6.1.7600.16385              Boot Configuration Data WMI Provider
    bcdsrv.dll                 6.1.7600.16385              Boot Configuration Data COM Server
    bcrypt.dll                 6.1.7600.16385              Windows Cryptographic Primitives Library
    bcryptprimitives.dll       6.1.7600.16385              Windows Cryptographic Primitives Library
    bdehdcfglib.dll            6.1.7600.16385                  Windows BitLocker
    bderepair.dll              6.1.7600.16385              BitLocker Drive Encryption: Drive Repair Tool
    bdesvc.dll                 6.1.7600.16385               BDE
    bdeui.dll                  6.1.7600.16385              Windows BitLocker Drive Encryption User Interface
    bfe.dll                    6.1.7600.16385                
    bidispl.dll                6.1.7600.16385              Bidispl DLL
    biocpl.dll                 6.1.7600.16385                - 
    biocredprov.dll            6.1.7600.16385                 WinBio
    bitsigd.dll                7.5.7600.16385              Background Intelligent Transfer Service IGD Support
    bitsperf.dll               7.5.7600.16385              Perfmon Counter Access
    bitsprx2.dll               7.5.7600.16385              Background Intelligent Transfer Service Proxy
    bitsprx3.dll               7.5.7600.16385              Background Intelligent Transfer Service 2.0 Proxy
    bitsprx4.dll               7.5.7600.16385              Background Intelligent Transfer Service 2.5 Proxy
    bitsprx5.dll               7.5.7600.16385              Background Intelligent Transfer Service 3.0 Proxy
    bitsprx6.dll               7.5.7600.16385              Background Intelligent Transfer Service 4.0 Proxy
    blackbox.dll               11.0.7600.16385             BlackBox DLL
    blb_ps.dll                 6.1.7600.16385              Microsoft Block Level Backup proxy/stub
    blbevents.dll              6.1.7600.16385               Blb
    blbres.dll                 6.1.7600.16385                     
    bootres.dll                6.1.7600.16385                
    bootstr.dll                6.1.7600.16385              Boot String Resource Library
    bootvid.dll                6.1.7600.16385              VGA Boot Driver
    brcoinst.dll               1.0.0.20                    Brother Multi Function CoInstaller
    brdgcfg.dll                6.1.7600.16385              NWLink IPX Notify Object
    bridgeres.dll              6.1.7600.16385               
    browcli.dll                6.1.7600.16385              Browser Service Client DLL
    browser.dll                6.1.7600.16385               DLL   
    browseui.dll               6.1.7600.16385              Shell Browser UI Library
    bthci.dll                  6.1.7600.16385                Bluetooth
    bthmtpcontexthandler.dll   6.1.7600.16385                 Bluetooth MTP
    bthpanapi.dll              6.1.7600.16385              bthpanapi
    bthpancontexthandler.dll   1.0.0.1                       Bthpan
    bthserv.dll                6.1.7600.16385                Bluetooth
    btpanui.dll                6.1.7600.16385                Bluetooth   
    bwcontexthandler.dll       1.0.0.1                      ContextH
    bwunpairelevated.dll       6.1.7600.16385              BWUnpairElevated Proxy Dll
    c_g18030.dll               6.1.7600.16385              GB18030 DBCS-Unicode Conversion DLL
    c_is2022.dll               6.1.7600.16385              ISO-2022 Code Page Translation DLL
    c_iscii.dll                6.1.7600.16385              ISCII Code Page Translation DLL
    cabinet.dll                6.1.7600.16385              Microsoft Cabinet File API
    cabview.dll                6.1.7600.16500                 CAB-
    capiprovider.dll           6.1.7600.16385               DLL capiprovider
    capisp.dll                 6.1.7600.16385              Sysprep cleanup dll for CAPI
    cardgames.dll              1.0.0.1                     CardGames Resources
    catsrv.dll                 2001.12.8530.16385          COM+ Configuration Catalog Server
    catsrvps.dll               2001.12.8530.16385          COM+ Configuration Catalog Server Proxy/Stub
    catsrvut.dll               2001.12.8530.16385          COM+ Configuration Catalog Server Utilities
    cca.dll                    6.6.7600.16385              CCA DirectShow Filter.
    cdd.dll                    6.1.7600.16748              Canonical Display Driver
    cdosys.dll                 6.6.7600.16385              Microsoft CDO for Windows Library
    certcli.dll                6.1.7600.16385                 Microsoft Active Directory
    certcredprovider.dll       6.1.7600.16385                 
    certenc.dll                6.1.7600.16385              Active Directory Certificate Services Encoding
    certenroll.dll             6.1.7600.16418                  Active Directory Microsoft
    certenrollui.dll           6.1.7600.16385                  X509
    certmgr.dll                6.1.7600.16385                
    certpoleng.dll             6.1.7600.16385                
    certprop.dll               6.1.7600.16385                 -
    cewmdm.dll                 12.0.7600.16385               Windows CE WMDM
    cfgbkend.dll               6.1.7600.16385              Configuration Backend Interface
    cfgmgr32.dll               6.1.7600.16385              Configuration Manager DLL
    chkwudrv.dll               6.1.7600.16385                    Windows
    chsbrkr.dll                6.1.7600.16385              Simplified Chinese Word Breaker
    chtbrkr.dll                6.1.7600.16385              Chinese Traditional Word Breaker
    chxreadingstringime.dll    6.1.7600.16385              CHxReadingStringIME
    ci.dll                     6.1.7600.16385              Code Integrity Module
    cic.dll                    6.1.7600.16385                CIC - MMC   
    circoinst.dll              6.1.7600.16385              USB Consumer IR Driver coinstaller for eHome
    clb.dll                    6.1.7600.16385                
    clbcatq.dll                2001.12.8530.16385          COM+ Configuration Catalog
    clfsw32.dll                6.1.7600.16385              Common Log Marshalling Win32 DLL
    cliconfg.dll               6.1.7600.16385              SQL Client Configuration Utility DLL
    clusapi.dll                6.1.7600.16385               API 
    cmcfg32.dll                7.2.7600.16385                  Microsoft
    cmdial32.dll               7.2.7600.16385               
    cmicryptinstall.dll        6.1.7600.16385              Installers for cryptographic elements of CMI objects
    cmifw.dll                  6.1.7600.16385              Windows Firewall rule configuration plug-in
    cmipnpinstall.dll          6.1.7600.16385              PNP plugin installer for CMI
    cmlua.dll                  7.2.7600.16385                API   
    cmnclim.dll                6.1.7600.16385                
    cmpbk32.dll                7.2.7600.16385              Microsoft Connection Manager Phonebook
    cmstplua.dll               7.2.7600.16385                API      
    cmutil.dll                 7.2.7600.16385                  (Microsoft)
    cnabcemk.dll               4.7.8.3                     Canon Advanced Printing Technology Engine Manager
    cnap2lmk.dll               4.7.0.8                     Canon Advanced Printing Technology Language Monitor
    cngaudit.dll               6.1.7600.16385              Windows Cryptographic Next Generation audit library
    cngprovider.dll            6.1.7600.16385               DLL cngprovider
    cnvfat.dll                 6.1.7600.16385              FAT File System Conversion Utility DLL
    cofiredm.dll               6.1.7600.16385                  
    colbact.dll                2001.12.8530.16385          COM+
    colorcnv.dll               6.1.7600.16385              Windows Media Color Conversion
    colorui.dll                6.1.7600.16385                 
    comcat.dll                 6.1.7600.16385              Microsoft Component Category Manager Library
    comctl32.dll               5.82.7600.16661                  
    comdlg32.dll               6.1.7600.16385                 
    commdlg.dll                3.10.0.103                  Common Dialogs libraries
    compobj.dll                2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    compstui.dll               6.1.7600.16385                   
    comrepl.dll                2001.12.8530.16385          COM+
    comres.dll                 2001.12.8530.16385           COM+
    comsnap.dll                2001.12.8530.16385          COM+ Explorer MMC Snapin
    comsvcs.dll                2001.12.8530.16385          COM+ Services
    comuid.dll                 2001.12.8530.16385          COM+ Explorer UI
    coneqmsapoguilibrary.dll   1.0.0.4                     CONEQ Media Suite APO GUI Library
    connect.dll                6.1.7600.16385               
    console.dll                6.1.7600.16385                 
    correngine.dll             6.1.7600.16385              Correlation Engine
    cpfilters.dll              6.6.7600.16724               PTFilter & Encypter/Decrypter Tagger Filters.
    credssp.dll                6.1.7600.16385              Credential Delegation Security Package
    credui.dll                 6.1.7600.16385                 
    crppresentation.dll        6.1.7600.16385              Conference Room Projector : Presentation
    crtdll.dll                 4.0.1183.1                  Microsoft C Runtime Library
    crypt32.dll                6.1.7600.17035              API32 
    cryptbase.dll              6.1.7600.16385              Base cryptographic API DLL
    cryptdlg.dll               6.1.7600.16385                
    cryptdll.dll               6.1.7600.16385              Cryptography Manager
    cryptext.dll               6.1.7600.16385                
    cryptnet.dll               6.1.7600.17035              Crypto Network Related API
    cryptsp.dll                6.1.7600.16385              Cryptographic Service Provider API
    cryptsvc.dll               6.1.7600.17035               
    cryptui.dll                6.1.7600.16385                
    cryptxml.dll               6.1.7600.16385              API- XML DigSig
    cscapi.dll                 6.1.7600.16385              Offline Files Win32 API
    cscdll.dll                 6.1.7600.16385              Offline Files Temporary Shim
    cscmig.dll                 6.1.7600.16385                   (Microsoft)
    cscobj.dll                 6.1.7600.16385               COM-   CSC API
    cscsvc.dll                 6.1.7600.16385              DLL  CSC
    cscui.dll                  6.1.7600.16385                  
    csrsrv.dll                 6.1.7600.17273                -
    ctl3d32.dll                2.31.0.0                    Ctl3D 3D Windows Controls
    ctl3dv2.dll                2.99.0.0                    Ctl3D 3D Windows NT(WOW) Controls
    d2d1.dll                   6.1.7600.16972              Microsoft D2D Library
    d3d10.dll                  6.1.7600.16385              Direct3D 10 Runtime
    d3d10_1.dll                6.1.7600.16972              Direct3D 10.1 Runtime
    d3d10_1core.dll            6.1.7600.16972              Direct3D 10.1 Runtime
    d3d10core.dll              6.1.7600.16385              Direct3D 10 Runtime
    d3d10level9.dll            6.1.7600.16385              Direct3D 10 to Direct3D9 Translation Runtime
    d3d10warp.dll              6.1.7600.16972              Direct3D 10 Rasterizer
    d3d11.dll                  6.1.7600.16385              Direct3D 11 Runtime
    d3d8.dll                   6.1.7600.16385              Microsoft Direct3D
    d3d8thk.dll                6.1.7600.16385              Microsoft Direct3D OS Thunk Layer
    d3d9.dll                   6.1.7600.16385              Direct3D 9 Runtime
    d3dcompiler_33.dll         9.18.904.15                 Microsoft Direct3D
    d3dcompiler_34.dll         9.19.949.46                 Microsoft Direct3D
    d3dcompiler_35.dll         9.19.949.1104               Microsoft Direct3D
    d3dcompiler_36.dll         9.19.949.2111               Microsoft Direct3D
    d3dcompiler_37.dll         9.22.949.2248               Microsoft Direct3D
    d3dcompiler_38.dll         9.23.949.2378               Microsoft Direct3D
    d3dcompiler_39.dll         9.24.949.2307               Microsoft Direct3D
    d3dcompiler_40.dll         9.24.950.2656               Direct3D HLSL Compiler
    d3dcompiler_41.dll         9.26.952.2844               Direct3D HLSL Compiler
    d3dcompiler_42.dll         9.27.952.3022               Direct3D HLSL Compiler
    d3dcompiler_43.dll         9.29.952.3111               Direct3D HLSL Compiler
    d3dcsx_42.dll              9.27.952.3022               Direct3D 10.1 Extensions
    d3dcsx_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dim.dll                  6.1.7600.16385              Microsoft Direct3D
    d3dim700.dll               6.1.7600.16385              Microsoft Direct3D
    d3dramp.dll                6.1.7600.16385              Microsoft Direct3D
    d3dx10.dll                 9.16.843.0                  Microsoft Direct3D
    d3dx10_33.dll              9.18.904.21                 Microsoft Direct3D
    d3dx10_34.dll              9.19.949.46                 Microsoft Direct3D
    d3dx10_35.dll              9.19.949.1104               Microsoft Direct3D
    d3dx10_36.dll              9.19.949.2009               Microsoft Direct3D
    d3dx10_37.dll              9.19.949.2187               Microsoft Direct3D
    d3dx10_38.dll              9.23.949.2378               Microsoft Direct3D
    d3dx10_39.dll              9.24.949.2307               Microsoft Direct3D
    d3dx10_40.dll              9.24.950.2656               Direct3D 10.1 Extensions
    d3dx10_41.dll              9.26.952.2844               Direct3D 10.1 Extensions
    d3dx10_42.dll              9.27.952.3001               Direct3D 10.1 Extensions
    d3dx10_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dx11_42.dll              9.27.952.3022               Direct3D 10.1 Extensions
    d3dx11_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dx9_24.dll               9.5.132.0                   Microsoft DirectX for Windows
    d3dx9_25.dll               9.6.168.0                   Microsoft DirectX for Windows
    d3dx9_26.dll               9.7.239.0                   Microsoft DirectX for Windows
    d3dx9_27.dll               9.8.299.0                   Microsoft DirectX for Windows
    d3dx9_28.dll               9.10.455.0                  Microsoft DirectX for Windows
    d3dx9_29.dll               9.11.519.0                  Microsoft DirectX for Windows
    d3dx9_30.dll               9.12.589.0                  Microsoft DirectX for Windows
    d3dx9_31.dll               9.15.779.0                  Microsoft DirectX for Windows
    d3dx9_32.dll               9.16.843.0                  Microsoft DirectX for Windows
    d3dx9_33.dll               9.18.904.15                 Microsoft DirectX for Windows
    d3dx9_34.dll               9.19.949.46                 Microsoft DirectX for Windows
    d3dx9_35.dll               9.19.949.1104               Microsoft DirectX for Windows
    d3dx9_36.dll               9.19.949.2111               Microsoft DirectX for Windows
    d3dx9_37.dll               9.22.949.2248               Microsoft DirectX for Windows
    d3dx9_38.dll               9.23.949.2378               Microsoft DirectX for Windows
    d3dx9_39.dll               9.24.949.2307               Microsoft DirectX for Windows
    d3dx9_40.dll               9.24.950.2656               Direct3D 9 Extensions
    d3dx9_41.dll               9.26.952.2844               Direct3D 9 Extensions
    d3dx9_42.dll               9.27.952.3001               Direct3D 9 Extensions
    d3dx9_43.dll               9.29.952.3111               Direct3D 9 Extensions
    d3dxof.dll                 6.1.7600.16385              DirectX Files DLL
    dataclen.dll               6.1.7600.16385                 Windows
    davclnt.dll                6.1.7600.16385              Web DAV Client DLL
    davhlpr.dll                6.1.7600.16385              DAV Helper DLL
    dbgeng.dll                 6.1.7600.16385              Windows Symbolic Debugger Engine
    dbghelp.dll                6.1.7600.16385              Windows Image Helper
    dbnetlib.dll               6.1.7600.16385              Winsock Oriented Net DLL for SQL Clients
    dbnmpntw.dll               6.1.7600.16385              Named Pipes Net DLL for SQL Clients
    dciman32.dll               6.1.7600.16385              DCI Manager
    ddaclsys.dll               6.1.7600.16385              SysPrep module for Reseting Data Drive ACL 
    ddeml.dll                  3.50.0.103                  DDE Management library
    ddoiproxy.dll              6.1.7600.16385              DDOI Interface Proxy
    ddores.dll                 6.1.7600.16385                  
    ddpa32.dll                 7.5.1.1                     Dolby Digital Plus API x86
    ddpd32a.dll                7.5.1.1                     Dolby Digital Plus COM DLL x86
    ddpo32a.dll                7.5.1.1                     Dolby Digital Plus APO x86
    ddpp32a.dll                7.5.1.1                     Dolby DS1PC Control Panel x86
    ddraw.dll                  6.1.7600.16385              Microsoft DirectDraw
    ddrawex.dll                6.1.7600.16385              Direct Draw Ex
    defaultlocationcpl.dll     6.1.7600.16385               :   
    defragproxy.dll            6.1.7600.16385              Microsoft Disk Defragmenter Proxy Library
    defragsvc.dll              6.1.7600.16385              \ 
    deskadp.dll                6.1.7600.16385                 
    deskmon.dll                6.1.7600.16385                
    deskperf.dll               6.1.7600.16385                
    devenum.dll                6.6.7600.16385               .
    devicecenter.dll           6.1.7600.16385                
    devicedisplaystatusmanager.dll  6.1.7600.16385              Device Display Status Manager
    devicemetadataparsers.dll  6.1.7600.16385              Common Device Metadata parsers
    devicepairing.dll          6.1.7600.16385               ,   
    devicepairingfolder.dll    6.1.7600.16385                 
    devicepairinghandler.dll   6.1.7600.16385              Device Pairing Handler Dll
    devicepairingproxy.dll     6.1.7600.16385              Device Pairing Proxy Dll
    deviceuxres.dll            6.1.7600.16385              Windows Device User Experience Resource File
    devmgr.dll                 6.1.7600.16385                 
    devobj.dll                 6.1.7600.16385              Device Information Set DLL
    devrtl.dll                 6.1.7600.16385              Device Management Run Time Library
    dfdts.dll                  6.1.7600.16385                  (Windows)
    dfscli.dll                 6.1.7600.16385              Windows NT Distributed File System Client DLL
    dfshim.dll                 4.0.31106.0                     ClickOnce
    dfsshlex.dll               6.1.7600.16385                   DFS
    dhcpcmonitor.dll           6.1.7600.16385               (DLL)   DHCP
    dhcpcore.dll               6.1.7600.16385               DHCP-
    dhcpcore6.dll              6.1.7600.16385               DHCPv6
    dhcpcsvc.dll               6.1.7600.16385               DHCP-
    dhcpcsvc6.dll              6.1.7600.16385               DHCPv6
    dhcpqec.dll                6.1.7600.16385                   Microsoft DHCP
    dhcpsapi.dll               6.1.7600.16385               API  DHCP-c
    diagcpl.dll                6.1.7600.16385                -  
    diagperf.dll               6.1.7600.16385                 (Microsoft)
    difxapi.dll                2.1.0.0                     Driver Install Frameworks for API library module
    dimsjob.dll                6.1.7600.16385               DLL  DIMS
    dimsroam.dll               6.1.7600.16385               DLL  DIMS  
    dinput.dll                 6.1.7600.16385              Microsoft DirectInput
    dinput8.dll                6.1.7600.16385              Microsoft DirectInput
    directdb.dll               6.1.7600.16385              Microsoft Direct Database API
    diskcopy.dll               6.1.7600.16385              Windows DiskCopy
    dispci.dll                 6.1.7600.16385                 (Microsoft)
    dispex.dll                 5.8.7600.16385              Microsoft  DispEx
    display.dll                6.1.7600.16385                
    dmband.dll                 6.1.7600.16385              Microsoft DirectMusic Band
    dmcompos.dll               6.1.7600.16385              Microsoft DirectMusic Composer
    dmdlgs.dll                 6.1.7600.16385              Disk Management Snap-in Dialogs
    dmdskmgr.dll               6.1.7600.16385              Disk Management Snap-in Support Library
    dmdskres.dll               6.1.7600.16385                 
    dmdskres2.dll              6.1.7600.16385                 
    dmime.dll                  6.1.7600.16385              Microsoft DirectMusic Interactive Engine
    dmintf.dll                 6.1.7600.16385              Disk Management DCOM Interface Stub
    dmloader.dll               6.1.7600.16385              Microsoft DirectMusic Loader
    dmocx.dll                  6.1.7600.16385              TreeView OCX
    dmrc.dll                   6.1.7600.16385              Windows MRC
    dmscript.dll               6.1.7600.16385              Microsoft DirectMusic Scripting
    dmstyle.dll                6.1.7600.16385              Microsoft DirectMusic Style Engline
    dmsynth.dll                6.1.7600.16385              Microsoft DirectMusic Software Synthesizer
    dmusic.dll                 6.1.7600.16385                Microsoft DirectMusic
    dmutil.dll                 6.1.7600.16385                 
    dmvdsitf.dll               6.1.7600.16385              Disk Management Snap-in Support Library
    dnsapi.dll                 6.1.7600.16772                API DNS-
    dnscmmc.dll                6.1.7600.16385               DLL  DNS  MMC
    dnsext.dll                 6.1.7600.16385              DNS extension DLL
    dnshc.dll                  6.1.7600.16385                DNS
    dnsrslvr.dll               6.1.7600.16772                 DNS
    docprop.dll                6.1.7600.16385                OLE
    documentperformanceevents.dll  6.1.7600.16385                   
    dot3api.dll                6.1.7600.16385              802.3 Autoconfiguration API
    dot3cfg.dll                6.1.7600.16385               Netsh  802.3
    dot3dlg.dll                6.1.7600.16385                UI  802.3
    dot3gpclnt.dll             6.1.7600.16385                   802.3
    dot3gpui.dll               6.1.7600.16385               "   802.3"
    dot3hc.dll                 6.1.7600.16385                 Dot3
    dot3msm.dll                6.1.7600.16385                   802.3
    dot3svc.dll                6.1.7600.16385               
    dot3ui.dll                 6.1.7600.16385                802.3
    dpapiprovider.dll          6.1.7600.16385               DLL dpapiprovider
    dplayx.dll                 6.1.7600.16385              Microsoft DirectPlay
    dpmodemx.dll               6.1.7600.16385                      DirectPlay
    dpnaddr.dll                6.1.7600.16385              Microsoft DirectPlay8 Address
    dpnathlp.dll               6.1.7600.16385              Microsoft DirectPlay NAT Helper UPnP
    dpnet.dll                  6.1.7600.17157              Microsoft DirectPlay
    dpnhpast.dll               6.1.7600.16385              Microsoft DirectPlay NAT Helper PAST
    dpnhupnp.dll               6.1.7600.16385              Microsoft DirectPlay NAT Helper UPNP
    dpnlobby.dll               6.1.7600.16385              Microsoft DirectPlay8 Lobby
    dps.dll                    6.1.7600.16385                 WDI
    dpwsockx.dll               6.1.7600.16385                  TCP/IP  IPX  DirectPlay
    dpx.dll                    6.1.7600.16385              Microsoft(R) Delta Package Expander
    drmmgrtn.dll               11.0.7600.16385             DRM Migration DLL
    drmv2clt.dll               11.0.7600.16385             DRMv2 Client DLL
    drprov.dll                 6.1.7600.16385                   ,        ()
    drt.dll                    6.1.7600.16385                
    drtprov.dll                6.1.7600.16385              Distributed Routing Table Providers
    drttransport.dll           6.1.7600.16385              Distributed Routing Table Transport Provider
    drvstore.dll               6.1.7600.16385              Driver Store API
    ds16gt.dll                 3.510.3711.0                Microsoft ODBC Driver Setup Generic Thunk
    ds32gt.dll                 6.1.7600.16385              ODBC Driver Setup Generic Thunk
    dsauth.dll                 6.1.7600.16385              DS Authorization for Services
    dsdmo.dll                  6.1.7600.16385              DirectSound Effects
    dshowrdpfilter.dll         1.0.0.0                           ()
    dskquota.dll               6.1.7600.16385               DLL    Windows
    dskquoui.dll               6.1.7600.16385               DLL   
    dsound.dll                 6.1.7600.16385              DirectSound
    dsprop.dll                 6.1.7600.16385                Active Directory
    dsquery.dll                6.1.7600.16385                 
    dsrole.dll                 6.1.7600.16385              DS Role Client DLL
    dssec.dll                  6.1.7600.16385                 
    dssenh.dll                 6.1.7600.16385              Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider
    dsuiext.dll                6.1.7600.16385                 
    dswave.dll                 6.1.7600.16385              Microsoft DirectMusic Wave
    dtsbassenhancementdll.dll  1.0.0.1                     DTS Bass Enhancement COM DLL
    dtsboostdll.dll            1.0.0.1                     DTS Boost COM DLL
    dtsgaincompensatordll.dll  1.0.0.1                     DTS Gain Compensator COM DLL
    dtsgfxapo.dll              1.0.0.3                     DTS GFX APO
    dtsgfxapons.dll            1.0.0.3                     DTS GFX APO
    dtsh.dll                   6.1.7600.16385               API     
    dtslfxapo.dll              1.0.0.3                     DTS LFX APO
    dtslimiterdll.dll          1.0.0.1                     DTS Limiter COM DLL
    dtsneopcdll.dll            1.0.0.1                     DTS NEO:PC COM DLL
    dtss2headphonedll.dll      1.0.0.1                     DTS Surround Sensation Headphone COM DLL
    dtss2speakerdll.dll        1.0.0.1                     DTS Surround Sensation Speaker COM DLL
    dtssymmetrydll.dll         1.0.0.1                     DTS Symmetry COM DLL
    dtsu2pgfx32.dll            2.1.1.0                     DTS GFX APO
    dtsu2plfx32.dll            2.1.1.0                     DTS LFX APO
    dtsu2prec32.dll            2.1.1.0                     DTS LFX APO
    dtsvoiceclaritydll.dll     1.0.0.1                     DTS Voice Clarity COM DLL
    dui70.dll                  6.1.7600.16385               DirectUI Windows
    duser.dll                  6.1.7600.16385              Windows DirectUser Engine
    dwmapi.dll                 6.1.7600.16385               API     ()
    dwmcore.dll                6.1.7600.16385                Microsoft DWM
    dwmredir.dll               6.1.7600.16385                    Microsoft
    dwrite.dll                 6.1.7600.16972               Microsoft DirectX Typography
    dxdiagn.dll                6.1.7600.16385                Microsoft DirectX
    dxgi.dll                   6.1.7600.16385              DirectX Graphics Infrastructure
    dxmasf.dll                 12.0.7600.16385             Microsoft Windows Media Component Removal File.
    dxp.dll                    6.1.7600.16385                 Device Stage
    dxpps.dll                  6.1.7600.16385              Device Experience Platform Proxy\Stub DLL
    dxptaskringtone.dll        6.1.7600.16385                 Microsoft
    dxptasksync.dll            6.1.7600.16385               Microsoft Windows DXP
    dxtmsft.dll                9.0.8112.16421              DirectX Media -- Image DirectX Transforms
    dxtrans.dll                9.0.8112.16421              DirectX Media -- DirectX Transform Core
    dxva2.dll                  6.1.7600.16385              DirectX Video Acceleration 2.0 DLL
    eapp3hst.dll               6.1.7600.16385              Microsoft ThirdPartyEapDispatcher
    eappcfg.dll                6.1.7600.16385                EAP
    eappgnui.dll               6.1.7600.16385                 EAP
    eapphost.dll               6.1.7600.16385                 EAPHost 
    eappprxy.dll               6.1.7600.16385              Microsoft EAPHost Peer Client DLL
    eapqec.dll                 6.1.7600.16385                   Microsoft EAP
    eapsvc.dll                 6.1.7600.16385               Microsoft EAPHost
    efsadu.dll                 6.1.7600.16385                
    efscore.dll                6.1.7600.16385              EFS Core Library
    efslsaext.dll              6.1.7600.16385              LSA extension for EFS
    efssvc.dll                 6.1.7600.16385               EFS
    efsutil.dll                6.1.7600.16385              EFS Utility Library
    ehstorapi.dll              6.1.7600.16385              Windows Enhanced Storage API
    ehstorpwdmgr.dll           6.1.7600.16385                Windows Enhanced Storage
    ehstorshell.dll            6.1.7600.16385               DLL   Windows Enhanced Storage
    els.dll                    6.1.7600.16385                
    elscore.dll                6.1.7600.16385               DLL   Els
    elslad.dll                 6.1.7600.16385              ELS Language Detection
    elstrans.dll               6.1.7600.16385              ELS Transliteration Service
    encapi.dll                 6.1.7600.16385              Encoder API
    encdec.dll                 6.6.7600.16899                XDS     .
    encdump.dll                5.0.1.1                     Media Foundation Crash Dump Encryption DLL 
    energy.dll                 6.1.7600.16385                
    eqossnap.dll               6.1.7600.16385                EQoS
    es.dll                     2001.12.8530.16385          COM+
    esent.dll                  6.1.7600.16385                  ESE  Microsoft(R) Windows(R)
    esentprf.dll               6.1.7600.16385              Extensible Storage Engine Performance Monitoring Library for Microsoft(R) Windows(R)
    eventcls.dll               6.1.7600.16385              Microsoft Volume Shadow Copy Service event class
    evr.dll                    6.1.7600.16385                DLL   
    explorerframe.dll          6.1.7600.16623              ExplorerFrame
    expsrv.dll                 6.0.72.9589                 Visual Basic for Applications Runtime - Expression Service
    f3ahvoas.dll               6.1.7600.16385              JP Japanese Keyboard Layout for Fujitsu FMV oyayubi-shift keyboard
    faultrep.dll               6.1.7600.16385                     Windows
    fdbth.dll                  6.1.7600.16385              Function Discovery Bluetooth Provider Dll
    fdbthproxy.dll             6.1.7600.16385              Bluetooth Provider Proxy Dll
    fde.dll                    6.1.7600.16385                 
    fdeploy.dll                6.1.7600.16385                  
    fdphost.dll                6.1.7600.16385                  
    fdpnp.dll                  6.1.7600.16385              Pnp Provider Dll
    fdprint.dll                6.1.7600.16385               DLL    
    fdproxy.dll                6.1.7600.16385              Function Discovery Proxy Dll
    fdrespub.dll               6.1.7600.16385                  
    fdssdp.dll                 6.1.7600.16385              Function Discovery SSDP Provider Dll
    fdwcn.dll                  6.1.7600.16385              Windows Connect Now - Config Function Discovery Provider DLL
    fdwnet.dll                 6.1.7600.16385              Function Discovery WNet Provider Dll
    fdwsd.dll                  6.1.7600.16385              Function Discovery WS Discovery Provider Dll
    feclient.dll               6.1.7600.16385              Windows NT File Encryption Client Interfaces
    ff_vfw.dll                 1.3.4515.0                  ffdshow VFW
    filemgmt.dll               6.1.7600.16385                 
    findnetprinters.dll        6.1.7600.16385              Find Network Printers COM Component
    firewallapi.dll            6.1.7600.16385              API  Windows
    firewallcontrolpanel.dll   6.1.7600.16385                -  Windows
    fltlib.dll                 6.1.7600.16385               
    fm20.dll                   12.0.4518.1014              Microsoft Forms DLL
    fm20enu.dll                12.0.4518.1014              Microsoft Forms International DLL
    fmapo.dll                  50.5.4.72                   Fortemedia SAMSoft sAPO
    fmifs.dll                  6.1.7600.16385              FM IFS Utility DLL
    fms.dll                    1.1.6000.16384                
    fntcache.dll               6.1.7600.16699                 Windows
    fontext.dll                6.1.7600.16385                Windows
    fontsub.dll                6.1.7600.16444              Font Subsetting DLL
    fphc.dll                   6.1.7600.16385               Filtering Platform Helper
    framebuf.dll               6.1.7600.16385              Framebuffer Display Driver
    framedyn.dll               6.1.7600.16385              WMI SDK Provider Framework
    framedynos.dll             6.1.7600.16385              WMI SDK Provider Framework
    fthsvc.dll                 6.1.7600.16385                  Microsoft Windows
    fundisc.dll                6.1.7600.16385              DLL  
    fveapi.dll                 6.1.7600.16385              Windows BitLocker Drive Encryption API
    fveapibase.dll             6.1.7600.16385              Windows BitLocker Drive Encryption Base API
    fvecerts.dll               6.1.7600.16385              BitLocker Certificates Library
    fvecpl.dll                 6.1.7600.16385                  BitLocker
    fverecover.dll             6.1.7600.16385                   Windows BitLocker
    fveui.dll                  6.1.7600.16385                 BitLocker
    fvewiz.dll                 6.1.7600.16385                 BitLocker
    fwcfg.dll                  6.1.7600.16385                  Windows
    fwpuclnt.dll               6.1.7600.16385              API   FWP/IPsec
    fwremotesvr.dll            6.1.7600.16385              Windows Firewall Remote APIs Server
    fxsapi.dll                 6.1.7600.16385              Microsoft  Fax API Support DLL
    fxscom.dll                 6.1.7600.16385              Microsoft Fax Server COM Client Interface
    fxscomex.dll               6.1.7600.16385              Microsoft Fax Server Extended COM Client Interface
    fxscompose.dll             6.1.7600.16385              Compose Form
    fxscomposeres.dll          6.1.7600.16385               
    fxsevent.dll               6.1.7600.16385               DLL    Microsoft Fax
    fxsext32.dll               6.1.7600.16385              Microsoft  Fax Exchange Command Extension
    fxsmon.dll                 6.1.7600.16385              Microsoft  Fax Print Monitor
    fxsresm.dll                6.1.7600.16385               DLL   (Microsoft)
    fxsroute.dll               6.1.7600.16385              Microsoft  Fax Routing DLL
    fxsst.dll                  6.1.7600.16385              Fax Service
    fxst30.dll                 6.1.7600.16385              Microsoft  Fax T30 Protocol Service Provider
    fxstiff.dll                6.1.7600.16385              Microsoft  Fax TIFF library
    fxsutility.dll             6.1.7600.16385               (DLL)  
    fxsxp32.dll                6.1.7600.16385              Microsoft  Fax Transport Provider
    gacinstall.dll             6.1.7600.16385              Installers for CLR and other managed code
    gameux.dll                 6.1.7600.16385               
    gameuxlegacygdfs.dll       1.0.0.1                     Legacy GDF resource DLL
    gcdef.dll                  6.1.7600.16385                   
    gdi32.dll                  6.1.7600.16385              GDI Client DLL
    getuname.dll               6.1.7600.16385                   UCE
    glmf32.dll                 6.1.7600.16385              OpenGL Metafiling DLL
    glu32.dll                  6.1.7600.16385                OpenGL
    gpapi.dll                  6.1.7600.16385                API  
    gpedit.dll                 6.1.7600.16385              GPEdit
    gpprefcl.dll               6.1.7600.16385                 
    gpprnext.dll               6.1.7600.16385                 
    gpscript.dll               6.1.7600.16385                
    gpsvc.dll                  6.1.7600.16385                
    gptext.dll                 6.1.7600.16385              GPTExt
    groupinghc.dll             6.1.7600.16385                
    hal.dll                    6.1.7600.16385              Hardware Abstraction Layer DLL
    halacpi.dll                6.1.7600.16385              Hardware Abstraction Layer DLL
    halmacpi.dll               6.1.7600.16385              Hardware Abstraction Layer DLL
    hbaapi.dll                 6.1.7600.16385              HBA API data interface dll for HBA_API_Rev_2-18_2002MAR1.doc
    hcproviders.dll            6.1.7600.16385                
    helppaneproxy.dll          6.1.7600.16385              Microsoft Help Proxy
    hgcpl.dll                  6.1.7600.16385                 
    hgprint.dll                6.1.7600.16385              HomeGroup Printing Support
    hhsetup.dll                6.1.7600.16385              Microsoft HTML Help
    hid.dll                    6.1.7600.16385                HID
    hidserv.dll                6.1.7600.16385               HID
    hlink.dll                  6.1.7600.16385               Microsoft Office 2000
    hnetcfg.dll                6.1.7600.16385                 
    hnetmon.dll                6.1.7600.16385              DLL   
    hotplug.dll                6.1.7600.16385                 
    hotstartuseragent.dll      6.1.7600.16385                Windows HotStart (Microsoft)
    httpapi.dll                6.1.7600.16385              HTTP Protocol Stack API
    htui.dll                   6.1.7600.16385                  
    ias.dll                    6.1.7600.16385                 (NPS)
    iasacct.dll                6.1.7600.16385                NPS
    iasads.dll                 6.1.7600.16385                Active Directory NPS
    iasdatastore.dll           6.1.7600.16385              NPS Datastore server
    iashlpr.dll                6.1.7600.16385                NPS
    iasmigplugin.dll           6.1.7600.16385              NPS Migration DLL
    iasnap.dll                 6.1.7600.16385              NPS NAP Provider
    iaspolcy.dll               6.1.7600.16385              NPS Pipeline
    iasrad.dll                 6.1.7600.16385                RADIUS NPS
    iasrecst.dll               6.1.7600.16385              NPS XML Datastore Access
    iassam.dll                 6.1.7600.16385              NPS NT SAM Provider
    iassdo.dll                 6.1.7600.16385               SDO NPS
    iassvcs.dll                6.1.7600.16385                NPS
    icaapi.dll                 6.1.7600.16385              DLL Interface to TermDD Device Driver
    icardie.dll                9.0.8112.16421              Microsoft Information Card IE Helper
    icardres.dll               3.0.4506.4926               Windows CardSpace
    iccoinstall.dll            6.1.7600.16385              Hyper-V Integration Components Coinstaller
    iccvid.dll                 1.10.0.13                    Cinepak
    icfupgd.dll                6.1.7600.16385              Windows Firewal ICF Settings Upgrade
    icm32.dll                  6.1.7600.16385              Microsoft Color Management Module (CMM)
    icmp.dll                   6.1.7600.16385              ICMP DLL
    icmui.dll                  6.1.7600.16385                  
    iconcodecservice.dll       6.1.7600.16385              Converts a PNG part of the icon to a legacy bmp icon
    icsigd.dll                 6.1.7600.16385                 
    idlisten.dll               6.1.7600.16385               
    idndl.dll                  6.1.7600.16385              Downlevel DLL
    idstore.dll                6.1.7600.16385              Identity Store
    ieadvpack.dll              9.0.8112.16421              ADVPACK
    ieakeng.dll                9.0.8112.16421                  Internet Explorer
    ieaksie.dll                9.0.8112.16421                 Internet Explorer   
    ieakui.dll                 9.0.8112.16421                UI DLL Microsoft IEAK
    ieapfltr.dll               9.0.8112.16421              Microsoft SmartScreen Filter
    iedkcs32.dll               18.0.8112.16421               IEAK
    ieframe.dll                9.0.8112.16526              -
    iepeers.dll                9.0.8112.16421              Peer- Internet Explorer
    iernonce.dll               9.0.8112.16421                RunOnce   
    iertutil.dll               9.0.8112.16526              Run time utility for Internet Explorer
    iesetup.dll                9.0.8112.16421                IOD
    iesysprep.dll              9.0.8112.16421              IE Sysprep Provider
    ieui.dll                   9.0.8112.16526                 Internet Explorer
    ifmon.dll                  6.1.7600.16385                IF
    ifsutil.dll                6.1.7600.16385              IFS Utility DLL
    ifsutilx.dll               6.1.7600.16385              IFS Utility Extension DLL
    igddiag.dll                6.1.7600.16385                IGD
    ikeext.dll                 6.1.7600.16385                IKE
    imagehlp.dll               6.1.7600.16970              Windows NT Image Helper
    imageres.dll               6.1.7600.16385              Windows Image Resource
    imagesp1.dll               6.1.7600.16385              Windows SP1 Image Resource
    imapi.dll                  6.1.7600.16385               Image Mastering API
    imapi2.dll                 6.1.7600.16385              IMAPI  2
    imapi2fs.dll               6.1.7600.16385              Image Mastering File System Imaging API v2
    imgutil.dll                9.0.8112.16421              IE plugin image decoder support DLL
    imjp10k.dll                10.1.7600.16385             Microsoft IME
    imm32.dll                  6.1.7600.16385              Multi-User Windows IMM32 API Client DLL
    inetcomm.dll               6.1.7600.16807              Microsoft Internet Messaging API Resources
    inetmib1.dll               6.1.7600.16385              Microsoft MIB-II subagent
    inetpp.dll                 6.1.7600.16385               DLL Internet Print Provider
    inetppui.dll               6.1.7600.16385               DLL    
    inetres.dll                6.1.7600.16385               API  
    infocardapi.dll            3.0.4506.4926               Microsoft InfoCards
    inked.dll                  6.1.7600.16385              Microsoft Tablet PC InkEdit Control
    input.dll                  6.1.7600.16385               DLL  
    inseng.dll                 9.0.8112.16421               
    iologmsg.dll               6.1.7600.16385                /
    ipbusenum.dll              6.1.7600.16385              PnP-X IP Bus Enumerator DLL
    ipbusenumproxy.dll         6.1.7600.16385              Associated Device Presence Proxy Dll
    iphlpapi.dll               6.1.7600.16385              IP Helper API
    iphlpsvc.dll               6.1.7600.16385                   IPv6   IPv4.
    ipnathlp.dll               6.1.7600.16385                 Microsoft NAT
    iprop.dll                  6.1.7600.16385              OLE PropertySet Implementation
    iprtprio.dll               6.1.7600.16385              IP Routing Protocol Priority DLL
    iprtrmgr.dll               6.1.7600.16385               IP-
    ipsecsnp.dll               6.1.7600.16385                 IP-
    ipsecsvc.dll               6.1.7600.16385              Windows IPsec SPD Server DLL
    ipsmsnap.dll               6.1.7600.16385                IP-
    ir32_32.dll                3.24.15.3                   32-  Intel Indeo(R) Video R3.2
    ir41_qc.dll                4.30.62.2                   Intel Indeo Video Interactive Quick Compressor
    ir41_qcx.dll               4.30.62.2                   Intel Indeo Video Interactive Quick Compressor
    ir50_32.dll                5.2562.15.55                Intel Indeo video 5.10
    ir50_qc.dll                5.0.63.48                   Intel Indeo video 5.10 Quick Compressor
    ir50_qcx.dll               5.0.63.48                   Intel Indeo video 5.10 Quick Compressor
    irclass.dll                6.1.7600.16385                 
    irmon.dll                  6.1.7600.16385                
    iscsicpl.dll               5.2.3790.1830                   iSCSI
    iscsidsc.dll               6.1.7600.16385              API-  iSCSI
    iscsied.dll                6.1.7600.16385              iSCSI Extension DLL
    iscsiexe.dll               6.1.7600.16385                iSCSI
    iscsilog.dll               6.1.7600.16385               DLL   iSCSI
    iscsium.dll                6.1.7600.16385              iSCSI Discovery api
    iscsiwmi.dll               6.1.7600.16385              MS iSCSI Initiator WMI Provider
    itircl.dll                 6.1.7600.16385              Microsoft InfoTech IR Local DLL
    itss.dll                   6.1.7600.16385              Microsoft InfoTech Storage System Library
    itvdata.dll                6.6.7600.16385              iTV Data Filters.
    iyuv_32.dll                6.1.7600.16490              Intel Indeo(R) Video YUV 
    jnwmon.dll                 0.3.7600.16385                  Windows
    jscript.dll                5.8.7601.17026              Microsoft (R) JScript
    jscript9.dll               9.0.8112.16526              Microsoft  JScript
    jsproxy.dll                9.0.8112.16526              JScript Proxy Auto-Configuration
    kaaport.dll                4.1105.6000.53              Knowles HD Audio APO
    kbd101.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for 101
    kbd101a.dll                6.1.7600.16385              KO Hangeul Keyboard Layout for 101 (Type A)
    kbd101b.dll                6.1.7600.16385              KO Hangeul Keyboard Layout for 101(Type B)
    kbd101c.dll                6.1.7600.16385              KO Hangeul Keyboard Layout for 101(Type C)
    kbd103.dll                 6.1.7600.16385              KO Hangeul Keyboard Layout for 103
    kbd106.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for 106
    kbd106n.dll                6.1.7600.16385              JP Japanese Keyboard Layout for 106
    kbda1.dll                  6.1.7600.16385              Arabic_English_101 Keyboard Layout
    kbda2.dll                  6.1.7600.16385              Arabic_2 Keyboard Layout
    kbda3.dll                  6.1.7600.16385              Arabic_French_102 Keyboard Layout
    kbdal.dll                  6.1.7600.16385              Albania Keyboard Layout
    kbdarme.dll                6.1.7600.16385              Eastern Armenian Keyboard Layout
    kbdarmw.dll                6.1.7600.16385              Western Armenian Keyboard Layout
    kbdax2.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for AX2
    kbdaze.dll                 6.1.7600.16385              Azerbaijan_Cyrillic Keyboard Layout
    kbdazel.dll                6.1.7600.16385              Azeri-Latin Keyboard Layout
    kbdbash.dll                6.1.7600.16385              Bashkir Keyboard Layout
    kbdbe.dll                  6.1.7600.16385              Belgian Keyboard Layout
    kbdbene.dll                6.1.7600.16385              Belgian Dutch Keyboard Layout
    kbdbgph.dll                6.1.7600.16385              Bulgarian Phonetic Keyboard Layout
    kbdbgph1.dll               6.1.7600.16385              Bulgarian (Phonetic Traditional) Keyboard Layout
    kbdbhc.dll                 6.1.7600.16385              Bosnian (Cyrillic) Keyboard Layout
    kbdblr.dll                 6.1.7600.16385              Belarusian Keyboard Layout
    kbdbr.dll                  6.1.7600.16385              Brazilian Keyboard Layout
    kbdbu.dll                  6.1.7600.16385              Bulgarian (Typewriter) Keyboard Layout
    kbdbulg.dll                6.1.7600.16385              Bulgarian Keyboard Layout
    kbdca.dll                  6.1.7600.16385              Canadian Multilingual Keyboard Layout
    kbdcan.dll                 6.1.7600.16385              Canadian Multilingual Standard Keyboard Layout
    kbdcr.dll                  6.1.7600.16385              Croatian/Slovenian Keyboard Layout
    kbdcz.dll                  6.1.7600.16385              Czech Keyboard Layout
    kbdcz1.dll                 6.1.7600.16385              Czech_101 Keyboard Layout
    kbdcz2.dll                 6.1.7600.16385              Czech_Programmer's Keyboard Layout
    kbdda.dll                  6.1.7600.16385              Danish Keyboard Layout
    kbddiv1.dll                6.1.7600.16385              Divehi Phonetic Keyboard Layout
    kbddiv2.dll                6.1.7600.16385              Divehi Typewriter Keyboard Layout
    kbddv.dll                  6.1.7600.16385              Dvorak US English Keyboard Layout
    kbdes.dll                  6.1.7600.16385              Spanish Alernate Keyboard Layout
    kbdest.dll                 6.1.7600.16385              Estonia Keyboard Layout
    kbdfa.dll                  6.1.7600.16385              Persian Keyboard Layout
    kbdfc.dll                  6.1.7600.16385              Canadian French Keyboard Layout
    kbdfi.dll                  6.1.7600.16385              Finnish Keyboard Layout
    kbdfi1.dll                 6.1.7600.16385              Finnish-Swedish with Sami Keyboard Layout
    kbdfo.dll                  6.1.7600.16385              F?roese Keyboard Layout
    kbdfr.dll                  6.1.7600.16385              French Keyboard Layout
    kbdgae.dll                 6.1.7600.16385              Gaelic Keyboard Layout
    kbdgeo.dll                 6.1.7600.16385              Georgian Keyboard Layout
    kbdgeoer.dll               6.1.7600.16385              Georgian (Ergonomic) Keyboard Layout
    kbdgeoqw.dll               6.1.7600.16385              Georgian (QWERTY) Keyboard Layout
    kbdgkl.dll                 6.1.7600.16385              Greek_Latin Keyboard Layout
    kbdgr.dll                  6.1.7600.16385              German Keyboard Layout
    kbdgr1.dll                 6.1.7600.16385              German_IBM Keyboard Layout
    kbdgrlnd.dll               6.1.7600.16385              Greenlandic Keyboard Layout
    kbdhau.dll                 6.1.7600.16385              Hausa Keyboard Layout
    kbdhe.dll                  6.1.7600.16385              Greek Keyboard Layout
    kbdhe220.dll               6.1.7600.16385              Greek IBM 220 Keyboard Layout
    kbdhe319.dll               6.1.7600.16385              Greek IBM 319 Keyboard Layout
    kbdheb.dll                 6.1.7600.16385              KBDHEB Keyboard Layout
    kbdhela2.dll               6.1.7600.16385              Greek IBM 220 Latin Keyboard Layout
    kbdhela3.dll               6.1.7600.16385              Greek IBM 319 Latin Keyboard Layout
    kbdhept.dll                6.1.7600.16385              Greek_Polytonic Keyboard Layout
    kbdhu.dll                  6.1.7600.16385              Hungarian Keyboard Layout
    kbdhu1.dll                 6.1.7600.16385              Hungarian 101-key Keyboard Layout
    kbdibm02.dll               6.1.7600.16385              JP Japanese Keyboard Layout for IBM 5576-002/003
    kbdibo.dll                 6.1.7600.16385              Igbo Keyboard Layout
    kbdic.dll                  6.1.7600.16385              Icelandic Keyboard Layout
    kbdinasa.dll               6.1.7600.16385              Assamese (Inscript) Keyboard Layout
    kbdinbe1.dll               6.1.7600.16385              Bengali - Inscript (Legacy) Keyboard Layout
    kbdinbe2.dll               6.1.7600.16385              Bengali (Inscript) Keyboard Layout
    kbdinben.dll               6.1.7600.16385              Bengali Keyboard Layout
    kbdindev.dll               6.1.7600.16385              Devanagari Keyboard Layout
    kbdinguj.dll               6.1.7600.16385              Gujarati Keyboard Layout
    kbdinhin.dll               6.1.7600.16385              Hindi Keyboard Layout
    kbdinkan.dll               6.1.7600.16385              Kannada Keyboard Layout
    kbdinmal.dll               6.1.7600.16385              Malayalam Keyboard Layout Keyboard Layout
    kbdinmar.dll               6.1.7600.16385              Marathi Keyboard Layout
    kbdinori.dll               6.1.7600.16385              Oriya Keyboard Layout
    kbdinpun.dll               6.1.7600.16385              Punjabi/Gurmukhi Keyboard Layout
    kbdintam.dll               6.1.7600.16385              Tamil Keyboard Layout
    kbdintel.dll               6.1.7600.16385              Telugu Keyboard Layout
    kbdinuk2.dll               6.1.7600.16385              Inuktitut Naqittaut Keyboard Layout
    kbdir.dll                  6.1.7600.16385              Irish Keyboard Layout
    kbdit.dll                  6.1.7600.16385              Italian Keyboard Layout
    kbdit142.dll               6.1.7600.16385              Italian 142 Keyboard Layout
    kbdiulat.dll               6.1.7600.16385              Inuktitut Latin Keyboard Layout
    kbdjpn.dll                 6.1.7600.16385              JP Japanese Keyboard Layout Stub driver
    kbdkaz.dll                 6.1.7600.16385              Kazak_Cyrillic Keyboard Layout
    kbdkhmr.dll                6.1.7600.16385              Cambodian Standard Keyboard Layout
    kbdkor.dll                 6.1.7600.16385              KO Hangeul Keyboard Layout Stub driver
    kbdkyr.dll                 6.1.7600.16385              Kyrgyz Keyboard Layout
    kbdla.dll                  6.1.7600.16385              Latin-American Spanish Keyboard Layout
    kbdlao.dll                 6.1.7600.16385              Lao Standard Keyboard Layout
    kbdlk41a.dll               6.1.7600.16385              DEC LK411-AJ Keyboard Layout
    kbdlt.dll                  6.1.7600.16385              Lithuania Keyboard Layout
    kbdlt1.dll                 6.1.7600.16385              Lithuanian Keyboard Layout
    kbdlt2.dll                 6.1.7600.16385              Lithuanian Standard Keyboard Layout
    kbdlv.dll                  6.1.7600.16385              Latvia Keyboard Layout
    kbdlv1.dll                 6.1.7600.16385              Latvia-QWERTY Keyboard Layout
    kbdmac.dll                 6.1.7600.16385              Macedonian (FYROM) Keyboard Layout
    kbdmacst.dll               6.1.7600.16385              Macedonian (FYROM) - Standard Keyboard Layout
    kbdmaori.dll               6.1.7600.16385              Maori Keyboard Layout
    kbdmlt47.dll               6.1.7600.16385              Maltese 47-key Keyboard Layout
    kbdmlt48.dll               6.1.7600.16385              Maltese 48-key Keyboard Layout
    kbdmon.dll                 6.1.7600.16385              Mongolian Keyboard Layout
    kbdmonmo.dll               6.1.7600.16385              Mongolian (Mongolian Script) Keyboard Layout
    kbdne.dll                  6.1.7600.16385              Dutch Keyboard Layout
    kbdnec.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for (NEC PC-9800)
    kbdnec95.dll               6.1.7600.16385              JP Japanese Keyboard Layout for (NEC PC-9800 Windows 95)
    kbdnecat.dll               6.1.7600.16385              JP Japanese Keyboard Layout for (NEC PC-9800 on PC98-NX)
    kbdnecnt.dll               6.1.7600.16385              JP Japanese NEC PC-9800 Keyboard Layout
    kbdnepr.dll                6.1.7600.16385              Nepali Keyboard Layout
    kbdno.dll                  6.1.7600.16385              Norwegian Keyboard Layout
    kbdno1.dll                 6.1.7600.16385              Norwegian with Sami Keyboard Layout
    kbdnso.dll                 6.1.7600.16385              Sesotho sa Leboa Keyboard Layout
    kbdpash.dll                6.1.7600.16385              Pashto (Afghanistan) Keyboard Layout
    kbdpl.dll                  6.1.7600.16385              Polish Keyboard Layout
    kbdpl1.dll                 6.1.7600.16385              Polish Programmer's Keyboard Layout
    kbdpo.dll                  6.1.7600.16385              Portuguese Keyboard Layout
    kbdro.dll                  6.1.7600.16385              Romanian (Legacy) Keyboard Layout
    kbdropr.dll                6.1.7600.16385              Romanian (Programmers) Keyboard Layout
    kbdrost.dll                6.1.7600.16385              Romanian (Standard) Keyboard Layout
    kbdru.dll                  6.1.7600.16385              Russian Keyboard Layout
    kbdru1.dll                 6.1.7600.16385              Russia(Typewriter) Keyboard Layout
    kbdsf.dll                  6.1.7600.16385              Swiss French Keyboard Layout
    kbdsg.dll                  6.1.7600.16385              Swiss German Keyboard Layout
    kbdsl.dll                  6.1.7600.16385              Slovak Keyboard Layout
    kbdsl1.dll                 6.1.7600.16385              Slovak(QWERTY) Keyboard Layout
    kbdsmsfi.dll               6.1.7600.16385              Sami Extended Finland-Sweden Keyboard Layout
    kbdsmsno.dll               6.1.7600.16385              Sami Extended Norway Keyboard Layout
    kbdsn1.dll                 6.1.7600.16385              Sinhala Keyboard Layout
    kbdsorex.dll               6.1.7600.16385              Sorbian Extended Keyboard Layout
    kbdsors1.dll               6.1.7600.16385              Sorbian Standard Keyboard Layout
    kbdsorst.dll               6.1.7600.16385              Sorbian Standard (Legacy) Keyboard Layout
    kbdsp.dll                  6.1.7600.16385              Spanish Keyboard Layout
    kbdsw.dll                  6.1.7600.16385              Swedish Keyboard Layout
    kbdsw09.dll                6.1.7600.16385              Sinhala - Wij 9 Keyboard Layout
    kbdsyr1.dll                6.1.7600.16385              Syriac Standard Keyboard Layout
    kbdsyr2.dll                6.1.7600.16385              Syriac Phoenetic Keyboard Layout
    kbdtajik.dll               6.1.7600.16385              Tajik Keyboard Layout
    kbdtat.dll                 6.1.7600.16385              Tatar_Cyrillic Keyboard Layout
    kbdth0.dll                 6.1.7600.16385              Thai Kedmanee Keyboard Layout
    kbdth1.dll                 6.1.7600.16385              Thai Pattachote Keyboard Layout
    kbdth2.dll                 6.1.7600.16385              Thai Kedmanee (non-ShiftLock) Keyboard Layout
    kbdth3.dll                 6.1.7600.16385              Thai Pattachote (non-ShiftLock) Keyboard Layout
    kbdtiprc.dll               6.1.7600.16385              Tibetan (PRC) Keyboard Layout
    kbdtuf.dll                 6.1.7600.16385              Turkish F Keyboard Layout
    kbdtuq.dll                 6.1.7600.16385              Turkish Q Keyboard Layout
    kbdturme.dll               6.1.7600.16385              Turkmen Keyboard Layout
    kbdughr.dll                6.1.7600.16385              Uyghur (Legacy) Keyboard Layout
    kbdughr1.dll               6.1.7600.16385              Uyghur Keyboard Layout
    kbduk.dll                  6.1.7600.16385              United Kingdom Keyboard Layout
    kbdukx.dll                 6.1.7600.16385              United Kingdom Extended Keyboard Layout
    kbdur.dll                  6.1.7600.16385              Ukrainian Keyboard Layout
    kbdur1.dll                 6.1.7600.16385              Ukrainian (Enhanced) Keyboard Layout
    kbdurdu.dll                6.1.7600.16385              Urdu Keyboard Layout
    kbdus.dll                  6.1.7600.16385              United States Keyboard Layout
    kbdusa.dll                 6.1.7600.16385              US IBM Arabic 238_L Keyboard Layout
    kbdusl.dll                 6.1.7600.16385              Dvorak Left-Hand US English Keyboard Layout
    kbdusr.dll                 6.1.7600.16385              Dvorak Right-Hand US English Keyboard Layout
    kbdusx.dll                 6.1.7600.16385              US Multinational Keyboard Layout
    kbduzb.dll                 6.1.7600.16385              Uzbek_Cyrillic Keyboard Layout
    kbdvntc.dll                6.1.7600.16385              Vietnamese Keyboard Layout
    kbdwol.dll                 6.1.7600.16385              Wolof Keyboard Layout
    kbdyak.dll                 6.1.7600.16385              Yakut - Russia Keyboard Layout
    kbdyba.dll                 6.1.7600.16385              Yoruba Keyboard Layout
    kbdycc.dll                 6.1.7600.16385              Serbian (Cyrillic) Keyboard Layout
    kbdycl.dll                 6.1.7600.16385              Serbian (Latin) Keyboard Layout
    kd1394.dll                 6.1.7600.16385              1394 Kernel Debugger
    kdcom.dll                  6.1.7600.16385              Serial Kernel Debugger
    kdusb.dll                  6.1.7600.16385              USB 2.0 Kernel Debugger
    kerberos.dll               6.1.7600.17095                Kerberos
    kernel32.dll               6.1.7600.17206                Windows NT BASE API
    kernelbase.dll             6.1.7600.17206                Windows NT BASE API
    kernelceip.dll             6.1.7600.16385                CEIP 
    keyiso.dll                 6.1.7600.16385                 CNG
    keymgr.dll                 6.1.7600.16385                  
    klfphc.dll                 1.0.0.12                    Filtering Platform Helper Class
    kmsvc.dll                  6.1.7600.16385                
    korwbrkr.dll               6.1.7600.16385              korwbrkr
    ksuser.dll                 6.1.7600.16385              User CSA Library
    ktmw32.dll                 6.1.7600.16385              Windows KTM Win32 Client DLL
    l2gpstore.dll              6.1.7600.16385              Policy Storage dll
    l2nacp.dll                 6.1.7600.16385                 Onex Windows
    l2sechc.dll                6.1.7600.16385                    2
    lagarith.dll               1.3.27.0                    Lagarith
    langcleanupsysprepaction.dll  6.1.7600.16385              Language cleanup Sysprep action
    laprxy.dll                 12.0.7600.16385             Windows Media Logagent Proxy
    licmgr10.dll               9.0.8112.16421               (DLL)    Microsoft
    linkinfo.dll               6.1.7600.16385              Windows Volume Tracking
    listsvc.dll                6.1.7600.16385                Windows
    lltdapi.dll                6.1.7600.16385              Link-Layer Topology Mapper API
    lltdres.dll                6.1.7600.16385                 
    lltdsvc.dll                6.1.7600.16385              Link-Layer Topology Mapper Service
    lmhsvc.dll                 6.1.7600.16385               DLL   TCPIP NetBios
    loadperf.dll               6.1.7600.16385                  
    localsec.dll               6.1.7600.16385               MMC "   "
    localspl.dll               6.1.7600.17023                 
    localui.dll                6.1.7600.16385                
    locationapi.dll            6.1.7600.16385              Microsoft Windows Location API
    loghours.dll               6.1.7600.16385               
    logoncli.dll               6.1.7600.16385              Net Logon Client DLL
    lpk.dll                    6.1.7600.16385              Language Pack
    lpksetupproxyserv.dll      6.1.7600.16385              COM proxy server for lpksetup.exe
    lsasrv.dll                 6.1.7600.16915               DLL  LSA
    lsmproxy.dll               6.1.7600.16385              LSM interfaces proxy Dll
    luainstall.dll             6.1.7600.16385              Lua manifest install
    lz32.dll                   6.1.7600.16385              LZ Expand/Compress API DLL
    lzexpand.dll               3.10.0.103                  Windows file expansion library
    magnification.dll          6.1.7600.16385               API  ()
    mapi32.dll                 1.0.2536.0                   MAPI 1.0  Windows NT
    mapistub.dll               1.0.2536.0                   MAPI 1.0  Windows NT
    maxxaudioapo.dll           1.2.2.0                     MaxxAudio APO
    maxxaudioapo20.dll         2.2.9.0                     MaxxAudio APO
    maxxaudioapo30.dll         3.6.0.0                     MaxxAudio APO
    maxxaudioapo40.dll         4.4.0.0                     MaxxAudio APO
    maxxaudioapo50.dll         5.3.1.0                     MaxxAudio APO
    maxxaudioaposhell.dll      4.12.5.0                    MaxxAudio APO Shell
    maxxaudioeq.dll            4.1.0.0                     
    maxxaudiorealtek.dll       4.5.1.0                     
    maxxaudiorealtek2.dll      5.2.16.0                    Waves Realtek App
    maxxaudiovna.dll           1.7.2.0                     
    maxxaudiovnn.dll           1.3.1.0                     
    maxxspeechapo.dll          1.1.1.0                     MaxxSpeech APO
    maxxvoiceapo20.dll         2.4.0.0                     MaxxVoice APO
    maxxvolumesdapo.dll        3.6.0.0                     MaxxVolumeSD APO
    mcewmdrmndbootstrap.dll    1.3.2297.0                  Windows Media Center WMDRM-ND Receiver Bridge Bootstrap DLL
    mciavi32.dll               6.1.7600.16490               MCI Video  Windows
    mcicda.dll                 6.1.7600.16385               MCI   cdaudio
    mciqtz32.dll               6.6.7600.16385               MCI DirectShow
    mciseq.dll                 6.1.7600.16385               MCI   MIDI
    mciwave.dll                6.1.7600.16385               MCI   
    mcmde.dll                  12.0.7600.16385             MCMDE DLL
    mcsrchph.dll               1.0.0.1                     Windows Media Center Search Protocol Handler
    mctres.dll                 6.1.7600.16385                MCT
    mcupdate_authenticamd.dll  6.1.7600.16385              AMD Microcode Update Library
    mcupdate_genuineintel.dll  6.1.7600.16385              Intel Microcode Update Library
    mcx2svc.dll                6.1.7600.16385              Media Center Extender Service
    mcxdriv.dll                6.1.7600.16385                Media Center
    mdminst.dll                6.1.7600.16385               
    mediametadatahandler.dll   6.1.7600.16385              Media Metadata Handler
    memdiag.dll                6.1.7600.16385                 
    mf.dll                     12.0.7600.16597               
    mf3216.dll                 6.1.7600.16385              32-bit to 16-bit Metafile Conversion DLL
    mfaacenc.dll               6.1.7600.16385              Media Foundation AAC Encoder
    mfc100.dll                 10.0.40219.1                MFCDLL Shared Library - Retail Version
    mfc100chs.dll              10.0.40219.1                MFC Language Specific Resources
    mfc100cht.dll              10.0.40219.1                MFC Language Specific Resources
    mfc100deu.dll              10.0.40219.1                MFC Language Specific Resources
    mfc100enu.dll              10.0.40219.1                MFC Language Specific Resources
    mfc100esn.dll              10.0.40219.1                MFC Language Specific Resources
    mfc100fra.dll              10.0.40219.1                MFC Language Specific Resources
    mfc100ita.dll              10.0.40219.1                MFC Language Specific Resources
    mfc100jpn.dll              10.0.40219.1                MFC Language Specific Resources
    mfc100kor.dll              10.0.40219.1                MFC Language Specific Resources
    mfc100rus.dll              10.0.40219.1                MFC Language Specific Resources
    mfc100u.dll                10.0.40219.1                MFCDLL Shared Library - Retail Version
    mfc110.dll                 11.0.50727.1                MFCDLL Shared Library - Retail Version
    mfc110chs.dll              11.0.50727.1                MFC Language Specific Resources
    mfc110cht.dll              11.0.50727.1                MFC Language Specific Resources
    mfc110deu.dll              11.0.50727.1                MFC Language Specific Resources
    mfc110enu.dll              11.0.50727.1                MFC Language Specific Resources
    mfc110esn.dll              11.0.50727.1                MFC Language Specific Resources
    mfc110fra.dll              11.0.50727.1                MFC Language Specific Resources
    mfc110ita.dll              11.0.50727.1                MFC Language Specific Resources
    mfc110jpn.dll              11.0.50727.1                MFC Language Specific Resources
    mfc110kor.dll              11.0.50727.1                MFC Language Specific Resources
    mfc110rus.dll              11.0.50727.1                MFC Language Specific Resources
    mfc110u.dll                11.0.50727.1                MFCDLL Shared Library - Retail Version
    mfc40.dll                  4.1.0.6151                    MFCDLL -  
    mfc40u.dll                 4.1.0.6151                    MFCDLL -  
    mfc42.dll                  6.6.8064.0                    MFCDLL -  
    mfc42u.dll                 6.6.8064.0                    MFCDLL -  
    mfcm100.dll                10.0.40219.1                MFC Managed Library - Retail Version
    mfcm100u.dll               10.0.40219.1                MFC Managed Library - Retail Version
    mfcm110.dll                11.0.50727.1                MFC Managed Library - Retail Version
    mfcm110u.dll               11.0.50727.1                MFC Managed Library - Retail Version
    mfcsubs.dll                2001.12.8530.16385          COM+
    mfds.dll                   12.0.7600.16385             Media Foundation Direct Show wrapper DLL
    mfdvdec.dll                6.1.7600.16385              Media Foundation DV Decoder
    mferror.dll                12.0.7600.16385                
    mfh264enc.dll              6.1.7600.16385              Media Foundation H264 Encoder
    mfmjpegdec.dll             6.1.7600.16385              Media Foundation MJPEG Decoder
    mfplat.dll                 12.0.7600.16385             Media Foundation Platform DLL
    mfplay.dll                 12.0.7600.16385             Media Foundation Playback API DLL
    mfps.dll                   12.0.7600.16385             Media Foundation Proxy DLL
    mfreadwrite.dll            12.0.7600.16597             Media Foundation ReadWrite DLL
    mfvdsp.dll                 6.1.7600.16385              Windows Media Foundation Video DSP Components
    mfwmaaec.dll               6.1.7600.16385              Windows Media Audio AEC for Media Foundation
    mgmtapi.dll                6.1.7600.16385              Microsoft SNMP Manager API (uses WinSNMP)
    microsoft-windows-hal-events.dll  6.1.7600.16385              Microsoft-Windows-HAL-Events Resources
    microsoft-windows-kernel-power-events.dll  6.1.7600.16385              Microsoft-Windows-Kernel-Power-Events Resources
    microsoft-windows-kernel-processor-power-events.dll  6.1.7600.16385              Microsoft-Windows-Kernel-Processor-Power-Events Resources
    midimap.dll                6.1.7600.16385              Microsoft MIDI Mapper
    migisol.dll                6.1.7600.16385              Migration System Isolation Layer
    miguiresource.dll          6.1.7600.16385               MIG wini32
    mimefilt.dll               2008.0.7600.16385            MIME
    miss_apo.dll               1.5.0.16020                 Sony MISS APO(32bit)
    mlang.dll                  6.1.7600.16385               DLL  
    mmcbase.dll                6.1.7600.16385                DLL MMC
    mmci.dll                   6.1.7600.16385                
    mmcico.dll                 6.1.7600.16385              Media class co-installer
    mmcndmgr.dll               6.1.7600.16385                 MMC
    mmcshext.dll               6.1.7600.16385              MMC Shell Extension DLL
    mmcss.dll                  6.1.7600.16385                 
    mmdevapi.dll               6.1.7600.16385              MMDevice API
    mmres.dll                  6.1.7600.16385               
    mmsystem.dll               3.10.0.103                  System APIs for Multimedia
    modemui.dll                6.1.7600.16385                Windows
    montr_ci.dll               6.1.7600.16385                 (Microsoft)
    moricons.dll               6.1.7600.16385              Windows NT Setup Icon Resources Library
    mp3dmod.dll                6.1.7600.16385              Microsoft MP3 Decoder DMO
    mp43decd.dll               6.1.7600.16385              Windows Media MPEG-4 Video Decoder
    mp4sdecd.dll               6.1.7600.16385              Windows Media MPEG-4 S Video Decoder
    mpg4decd.dll               6.1.7600.16385              Windows Media MPEG-4 Video Decoder
    mpr.dll                    6.1.7600.16385                   
    mprapi.dll                 6.1.7600.16385              Windows NT MP Router Administration DLL
    mprddm.dll                 6.1.7600.16385                  
    mprdim.dll                 6.1.7600.16385                
    mprmsg.dll                 6.1.7600.16385               (DLL)    
    mpssvc.dll                 6.1.7600.16385                (Microsoft)
    msaatext.dll               2.0.10413.0                 Active Accessibility text support
    msac3enc.dll               6.1.7600.16385              Microsoft AC-3 Encoder
    msacm.dll                  3.50.0.9                    Microsoft Audio Compression Manager
    msacm32.dll                6.1.7600.16385                 Microsoft
    msadce.dll                 6.1.7600.16385              OLE DB Cursor Engine
    msadcer.dll                6.1.7600.16385              OLE DB Cursor Engine Resources
    msadcf.dll                 6.1.7600.16385              Remote Data Services Data Factory
    msadcfr.dll                6.1.7600.16385              Remote Data Services Data Factory Resources
    msadco.dll                 6.1.7600.16688              Remote Data Services Data Control
    msadcor.dll                6.1.7600.16385              Remote Data Services Data Control Resources
    msadcs.dll                 6.1.7600.16385              Remote Data Services ISAPI Library
    msadds.dll                 6.1.7600.16385              OLE DB Data Shape Provider
    msaddsr.dll                6.1.7600.16385               OLE DB Data Shape Provider Resources
    msader15.dll               6.1.7600.16385              ActiveX Data Objects Resources
    msado15.dll                6.1.7600.17036              ActiveX Data Objects
    msadomd.dll                6.1.7600.16688              ActiveX Data Objects (Multi-Dimensional)
    msador15.dll               6.1.7600.16385              Microsoft ActiveX Data Objects Recordset
    msadox.dll                 6.1.7600.16688              ActiveX Data Objects Extensions
    msadrh15.dll               6.1.7600.16385              ActiveX Data Objects Rowset Helper
    msafd.dll                  6.1.7600.16385              Microsoft Windows Sockets 2.0 Service Provider
    msasn1.dll                 6.1.7600.16415              ASN.1 Runtime APIs
    msaudite.dll               6.1.7600.16385                 
    mscandui.dll               6.1.7600.16385                MSCANDUI
    mscat32.dll                6.1.7600.16385              MSCAT32 Forwarder DLL
    msclmd.dll                 6.1.7600.16385              Microsoft Class Mini-driver
    mscms.dll                  6.1.7600.16385              DLL-    
    mscoree.dll                4.0.31106.0                 Microsoft .NET Runtime Execution Engine
    mscorier.dll               2.0.50727.4927               IE    Microsoft .NET
    mscories.dll               2.0.50727.4927              Microsoft .NET IE SECURITY REGISTRATION
    mscpx32r.dll               6.1.7600.16385              ODBC Code Page Translator Resources
    mscpxl32.dll               6.1.7600.16385                 ODBC
    msctf.dll                  6.1.7600.16385                MSCTF
    msctfmonitor.dll           6.1.7600.16385              MsCtfMonitor DLL
    msctfp.dll                 6.1.7600.16385              MSCTFP Server DLL
    msctfui.dll                6.1.7600.16385                MSCTFUI
    msdadc.dll                 6.1.7600.16385              OLE DB Data Conversion Stub
    msdadiag.dll               6.1.7600.16385              Built-In Diagnostics
    msdaenum.dll               6.1.7600.16385              OLE DB Root Enumerator Stub
    msdaer.dll                 6.1.7600.16385              OLE DB Error Collection Stub
    msdaora.dll                6.1.7600.16385              OLE DB Provider for Oracle
    msdaorar.dll               6.1.7600.16385              OLE DB Provider for Oracle Resources
    msdaosp.dll                6.1.7600.16833              OLE DB Simple Provider
    msdaprsr.dll               6.1.7600.16385                OLE DB Persistence Services
    msdaprst.dll               6.1.7600.16385              OLE DB Persistence Services
    msdaps.dll                 6.1.7600.16385              OLE DB Interface Proxies/Stubs
    msdarem.dll                6.1.7600.16385              OLE DB Remote Provider
    msdaremr.dll               6.1.7600.16385              OLE DB Remote Provider Resources
    msdart.dll                 6.1.7600.16385              OLE DB Runtime Routines
    msdasc.dll                 6.1.7600.16385              OLE DB Service Components Stub
    msdasql.dll                6.1.7600.16385              OLE DB Provider for ODBC Drivers
    msdasqlr.dll               6.1.7600.16385              OLE DB Provider for ODBC Drivers Resources
    msdatl3.dll                6.1.7600.16385              OLE DB Implementation Support Routines
    msdatt.dll                 6.1.7600.16385              OLE DB Temporary Table Services
    msdaurl.dll                6.1.7600.16385              OLE DB RootBinder Stub
    msdelta.dll                6.1.7600.16385              Microsoft Patch Engine
    msdfmap.dll                6.1.7600.16385              Data Factory Handler
    msdmeng.dll                8.0.2039.0                  Microsoft Data Mining Engine
    msdmine.dll                8.0.2039.0                  Microsoft OLE DB Provider for Data Mining Services
    msdmo.dll                  6.6.7600.16385              DMO Runtime
    msdri.dll                  6.1.7600.16385              Microsoft Digital Receiver Interface Class Driver
    msdrm.dll                  6.1.7600.16385                 Windows
    msdtckrm.dll               2001.12.8530.16385          Microsoft Distributed Transaction Coordinator OLE Transactions KTM Resource Manager DLL
    msdtclog.dll               2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Log Manager DLL
    msdtcprx.dll               2001.12.8530.16385          Microsoft Distributed Transaction Coordinator OLE Transactions Interface Proxy DLL
    msdtctm.dll                2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Transaction Manager DLL
    msdtcuiu.dll               2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Administrative DLL
    msdtcvsp1res.dll           2001.12.8530.16385               Vista SP1
    msexch40.dll               4.0.9756.0                  Microsoft Jet Exchange Isam
    msexcl40.dll               4.0.9756.0                  Microsoft Jet Excel Isam
    msfeeds.dll                9.0.8112.16526              Microsoft Feeds Manager
    msfeedsbs.dll              9.0.8112.16421                - ()
    msftedit.dll               5.41.21.2509                Rich Text Edit Control, v4.1
    mshtml.dll                 9.0.8112.16526                HTML Microsoft
    mshtmled.dll               9.0.8112.16526              Microsoft HTML Editing Component
    mshtmler.dll               9.0.8112.16421                  HTML (Microsoft)
    msi.dll                    5.0.7600.16385              Windows Installer
    msicofire.dll              6.1.7600.16385                  MSI-
    msidcrl30.dll              6.1.7600.16385              IDCRL Dynamic Link Library
    msident.dll                6.1.7600.16385                (Microsoft)
    msidle.dll                 6.1.7600.16385              User Idle Monitor
    msidntld.dll               6.1.7600.16385                (Microsoft)
    msieftp.dll                6.1.7600.16385                Microsoft Internet Explorer  FTP
    msihnd.dll                 5.0.7600.16385              Windows installer
    msiltcfg.dll               5.0.7600.16385              Windows Installer Configuration API Stub
    msimg32.dll                6.1.7600.16385              GDIEXT Client DLL
    msimsg.dll                 5.0.7600.16385                 Windows
    msimtf.dll                 6.1.7600.16385              Active IMM Server DLL
    msisip.dll                 5.0.7600.16385              MSI Signature SIP Provider
    msjet40.dll                4.0.9756.0                  Microsoft Jet Engine Library
    msjetoledb40.dll           4.0.9756.0                  
    msjint40.dll               4.0.9756.0                       Microsoft Jet
    msjro.dll                  6.1.7600.16385              Jet and Replication Objects
    msjter40.dll               4.0.9756.0                  Microsoft Jet Database Engine Error DLL
    msjtes40.dll               4.0.9756.0                  Microsoft Jet Expression Service
    msls31.dll                 3.10.349.0                  Microsoft Line Services library file
    msltus40.dll               4.0.9756.0                  Microsoft Jet Lotus 1-2-3 Isam
    msmapi32.dll               12.0.4518.1014              Extended MAPI 1.0 for Windows NT
    msmdcb80.dll               8.0.2039.0                  PivotTable Service dll
    msmdgd80.dll               8.0.2039.0                  Microsoft SQL Server Analysis Services driver
    msmdlocal.dll              9.0.3017.0                  Microsoft SQL Server Analysis Services
    msmdun80.dll               2000.80.2039.0              String Function .DLL for SQL Enterprise Components
    msmgdsrv.dll               9.0.3017.0                  Microsoft SQL Server Analysis Services Managed Module
    msmmsp.dll                 6.1.7600.16385              Mount Point Manger Sysprep Utility Library
    msmpeg2adec.dll            6.1.7140.0                  Microsoft DTV-DVD Audio Decoder
    msmpeg2enc.dll             6.1.7600.16385               Microsoft MPEG-2
    msmpeg2vdec.dll            6.1.7140.0                  Microsoft DTV-DVD Video Decoder
    msnetobj.dll               11.0.7600.16385             DRM ActiveX Network Object
    msobjs.dll                 6.1.7600.16385                 
    msoeacct.dll               6.1.7600.16385              Microsoft Internet Account Manager
    msoert2.dll                6.1.7600.16385              Microsoft Windows Mail RT Lib
    msolap80.dll               8.0.2216.0                  Microsoft OLE DB Provider for Analysis Services 8.0
    msolap90.dll               9.0.3017.0                  Microsoft OLE DB Provider for Analysis Services 9.0
    msolui80.dll               8.0.0.2039                  Microsoft OLE DB provider for Analysis Services connection dialog 8.0
    msolui90.dll               9.0.3017.0                  Microsoft OLE DB Provider for Analysis Services Connection Dialog 9.0
    msonpmon.dll               0.3.4518.1014               Microsoft Office OneNote 2007 Printer Driver
    msorc32r.dll               6.1.7600.16385                ODBC  Oracle
    msorcl32.dll               6.1.7600.16385              ODBC Driver for Oracle
    mspatcha.dll               6.1.7600.16385              Microsoft File Patch Application API
    mspbda.dll                 6.1.7600.16385              Microsoft Protected Broadcast Digital Architecture Class Driver
    mspbdacoinst.dll           6.1.7600.16385              Microsoft Protected Broadcast Digital Architecture Class Driver CoInstaller
    mspbde40.dll               4.0.9756.0                  Microsoft Jet Paradox Isam
    msports.dll                6.1.7600.16385                 
    msprivs.dll                6.1.7600.16385                
    msrahc.dll                 6.1.7600.16385                 
    msrating.dll               9.0.8112.16421                   
    msrd2x40.dll               4.0.9756.0                  Microsoft (R) Red ISAM
    msrd3x40.dll               4.0.9756.0                  Microsoft (R) Red ISAM
    msrdc.dll                  6.1.7600.16385              Remote Differential Compression COM server
    msrdpwebaccess.dll         6.1.7600.16385              Microsoft Remote Desktop Services Web Access Control
    msrepl40.dll               4.0.9756.0                  Microsoft Replication Library
    msrle32.dll                6.1.7600.16490              Microsoft RLE Compressor
    msscntrs.dll               7.0.7600.16385              msscntrs.dll
    msscp.dll                  11.0.7600.16385             Windows Media Secure Content Provider
    mssha.dll                  6.1.7600.16385                  Windows
    msshavmsg.dll              6.1.7600.16385                     Windows
    msshooks.dll               7.0.7600.16385              MSSHooks.dll
    mssign32.dll               6.1.7600.16385               API  
    mssip32.dll                6.1.7600.16385              MSSIP32 Forwarder DLL
    mssitlb.dll                7.0.7600.16385              mssitlb
    mssph.dll                  7.0.7600.16385                 Microsoft
    mssphtb.dll                7.0.7600.16385              Outlook MSSearch Connector
    mssprxy.dll                7.0.7600.16385              Microsoft Search Proxy
    mssrch.dll                 7.0.7600.16385              mssrch.dll
    msstdfmt.dll               6.0.84.50                   Microsoft Standard Data Formating Object DLL
    mssvp.dll                  7.0.7600.16385               Vista MSSearch
    msswch.dll                 6.1.7600.16385              msswch
    mstask.dll                 6.1.7600.16385                 
    mstext40.dll               4.0.9756.0                  Microsoft Jet Text Isam
    mstscax.dll                6.1.7600.17233              ActiveX-    
    msutb.dll                  6.1.7600.16385               (DLL)  MSUTB
    msv1_0.dll                 6.1.7600.16420              Microsoft Authentication Package v1.0
    msvbvm60.dll               6.0.98.15                   Visual Basic Virtual Machine
    msvcirt.dll                7.0.7600.16385              Windows NT IOStreams DLL
    msvcp100.dll               10.0.40219.1                Microsoft C Runtime Library
    msvcp110.dll               11.0.50727.1                Microsoft C Runtime Library
    msvcp110_clr0400.dll       11.0.50938.18408            Microsoft C Runtime Library
    msvcp60.dll                7.0.7600.16385              Windows NT C++ Runtime Library DLL
    msvcr100.dll               10.0.40219.1                Microsoft C Runtime Library
    msvcr100_clr0400.dll       11.0.50938.18408            Microsoft .NET Framework
    msvcr110.dll               11.0.50727.1                Microsoft C Runtime Library
    msvcr110_clr0400.dll       11.0.50938.18408            Microsoft C Runtime Library
    msvcrt.dll                 7.0.7600.16930              Windows NT CRT DLL
    msvcrt20.dll               2.12.0.0                    Microsoft C Runtime Library
    msvcrt40.dll               6.1.7600.16385              VC 4.x CRT DLL (Forwarded to msvcrt.dll)
    msvfw32.dll                6.1.7600.16385               Microsoft Video  Windows
    msvidc32.dll               6.1.7600.16490                Microsoft Video 1
    msvidctl.dll               6.5.7600.16385               ActiveX  
    msvideo.dll                1.15.0.1                    Microsoft Video for Windows DLL
    mswdat10.dll               4.0.9756.0                  Microsoft Jet Sort Tables
    mswmdm.dll                 12.0.7600.16385               Windows Media Device Manager
    mswsock.dll                6.1.7600.16385                 API Microsoft Windows Sockets 2.0
    mswstr10.dll               4.0.9756.0                    Microsoft Jet
    msxactps.dll               6.1.7600.16385              OLE DB Transaction Proxies/Stubs
    msxbde40.dll               4.0.9756.0                  Microsoft Jet xBASE Isam
    msxml3.dll                 8.110.7600.17036            MSXML 3.0 SP11
    msxml3r.dll                8.110.7600.16385            XML Resources
    msxml6.dll                 6.30.7600.17157             MSXML 6.0 SP3
    msxml6r.dll                6.30.7600.16385             XML Resources
    msyuv.dll                  6.1.7600.16490              Microsoft UYVY Video Decompressor
    mtxclu.dll                 2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Failover Clustering Support DLL
    mtxdm.dll                  2001.12.8530.16385          COM+
    mtxex.dll                  2001.12.8530.16385          COM+
    mtxlegih.dll               2001.12.8530.16385          COM+
    mtxoci.dll                 2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Database Support DLL for Oracle
    muifontsetup.dll           6.1.7600.16385              MUI Callback for font registry settings
    muilanguagecleanup.dll     6.1.7600.16385              MUI Callback for Language pack cleanup
    mycomput.dll               6.1.7600.16385               
    mydocs.dll                 6.1.7600.16385                 " "
    nahimicapolfx.dll          6.3.9600.16384              Nahimic APO lfx dll
    nahimicaposettingsipc.dll  1.0.0.14112                 Nahimic APO Settings Communication Dll
    napcrypt.dll               6.1.7600.16385              NAP Cryptographic API helper
    napdsnap.dll               6.1.7600.16385               GPEdit    
    naphlpr.dll                6.1.7600.16385              NAP client config API helper
    napinsp.dll                6.1.7600.16385                    
    napipsec.dll               6.1.7600.16385                      IPSec
    napmontr.dll               6.1.7600.16385                NAP  Netsh
    nativehooks.dll            6.1.7600.16385              Microsoft Narrator Native hook handler
    naturallanguage6.dll       6.1.7600.16385              Natural Language Development Platform 6
    ncdprop.dll                6.1.7600.16385                 
    nci.dll                    6.1.7600.16385              CoInstaller: NET
    ncobjapi.dll               6.1.7600.16385              Microsoft Windows Operating System
    ncrypt.dll                 6.1.7600.17172                (Windows)
    ncryptui.dll               6.1.7600.16385               UI     Windows
    ncsi.dll                   6.1.7600.16385                 
    nddeapi.dll                6.1.7600.16385              Network DDE Share Management APIs
    ndfapi.dll                 6.1.7600.16385              API    
    ndfetw.dll                 6.1.7600.16385              Network Diagnostic Engine Event Interface
    ndfhcdiscovery.dll         6.1.7600.16385              Network Diagnostic Framework HC Discovery API
    ndiscapcfg.dll             6.1.7600.16385              NdisCap Notify Object
    ndishc.dll                 6.1.7600.16385                NDIS
    ndproxystub.dll            6.1.7600.16385              Network Diagnostic Engine Proxy/Stub
    negoexts.dll               6.1.7600.16385              NegoExtender Security Package
    netapi.dll                 3.11.0.300                  Microsoft Network Dynamic Link Library for Microsoft Windows
    netapi32.dll               6.1.7600.16385              Net Win32 API DLL
    netbios.dll                6.1.7600.16385              NetBIOS Interface Library
    netcenter.dll              6.1.7600.16385                 -  
    netcfgx.dll                6.1.7600.16385                
    netcorehc.dll              6.1.7600.16385                   
    netdiagfx.dll              6.1.7600.16385                
    netevent.dll               6.1.7600.16385                
    netfxperf.dll              4.0.31106.0                 Extensible Performance Counter Shim
    neth.dll                   6.1.7600.16385                 
    netid.dll                  6.1.7600.16385                  
    netiohlp.dll               6.1.7600.16385               DLL   Netio
    netjoin.dll                6.1.7600.16385              Domain Join DLL
    netlogon.dll               6.1.7600.16385                 Net Logon
    netman.dll                 6.1.7600.16385                
    netmsg.dll                 6.1.7600.16385                
    netplwiz.dll               6.1.7600.16385                   
    netprof.dll                6.1.7600.16385                 
    netprofm.dll               6.1.7600.16385                
    netprojw.dll               6.1.7600.16385                 
    netshell.dll               6.1.7600.16385                
    nettrace.dll               6.1.7600.16385                 
    netutils.dll               6.1.7600.16385              Net Win32 API Helpers DLL
    networkexplorer.dll        6.1.7600.16385               
    networkitemfactory.dll     6.1.7600.16385                
    networkmap.dll             6.1.7600.16385               
    newdev.dll                 6.0.5054.0                    
    nlaapi.dll                 6.1.7600.16385              Network Location Awareness 2
    nlahc.dll                  6.1.7600.16385                NLA
    nlasvc.dll                 6.1.7600.16385                   2
    nlhtml.dll                 2008.0.7600.16385            HTML
    nlmgp.dll                  6.1.7600.16385                 
    nlmsprep.dll               6.1.7600.16385              Network List Manager Sysprep Module
    nlsbres.dll                6.1.7600.16385              NLSBuild resource DLL
    nlsdata0000.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0001.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0002.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0003.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0007.dll            6.1.7600.16385              Microsoft German Natural Language Server Data and Code
    nlsdata0009.dll            6.1.7600.16385              Microsoft English Natural Language Server Data and Code
    nlsdata000a.dll            6.1.7600.16385              Microsoft Spanish Natural Language Server Data and Code
    nlsdata000c.dll            6.1.7600.16385              Microsoft French Natural Language Server Data and Code
    nlsdata000d.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata000f.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0010.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0011.dll            6.1.7600.16385              Microsoft Japanese Natural Language Server Data and Code
    nlsdata0013.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0018.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0019.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001b.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001d.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0020.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0021.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0022.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0024.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0026.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0027.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata002a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0039.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata003e.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0045.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0046.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0047.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0049.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004b.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004c.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004e.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0414.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0416.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0816.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata081a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0c1a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdl.dll                  6.1.7600.16385              Nls Downlevel DLL
    nlslexicons0001.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0002.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0003.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0007.dll        6.1.7600.16385              Microsoft German Natural Language Server Data and Code
    nlslexicons0009.dll        6.1.7600.16385              Microsoft English Natural Language Server Data and Code
    nlslexicons000a.dll        6.1.7600.16385              Microsoft Spanish Natural Language Server Data and Code
    nlslexicons000c.dll        6.1.7600.16385              Microsoft French Natural Language Server Data and Code
    nlslexicons000d.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons000f.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0010.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0011.dll        6.1.7600.16385              Microsoft Japanese Natural Language Server Data and Code
    nlslexicons0013.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0018.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0019.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001b.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001d.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0020.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0021.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0022.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0024.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0026.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0027.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons002a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0039.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons003e.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0045.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0046.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0047.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0049.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004b.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004c.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004e.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0414.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0416.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0816.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons081a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0c1a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsmodels0011.dll          6.1.7600.16385              Microsoft Japanese Natural Language Server Data and Code
    normaliz.dll               6.1.7600.16385              Unicode Normalization DLL
    npmproxy.dll               6.1.7600.16385              Network List Manager Proxy
    nrpsrv.dll                 6.1.7600.16385              Name Resolution Proxy (NRP) RPC interface
    nshhttp.dll                6.1.7600.16385               DLL netsh  HTTP
    nshipsec.dll               6.1.7600.16385               DLL  IPSec  Net
    nshwfp.dll                 6.1.7600.16385                  Windows  Netsh
    nsi.dll                    6.1.7600.16385              NSI User-mode interface DLL
    nsisvc.dll                 6.1.7600.16385              RPC-   
    ntdll.dll                  6.1.7600.16915                NT
    ntdsapi.dll                6.1.7600.16385              Active Directory Domain Services API
    ntlanman.dll               6.1.7600.16385              Microsoft LAN Manager
    ntlanui2.dll               6.1.7600.16385                  
    ntmarta.dll                6.1.7600.16385               Windows NT MARTA
    ntprint.dll                6.1.7600.16385                  
    ntshrui.dll                6.1.7600.16385               ,    
    ntvdmd.dll                 6.1.7600.16385              NTVDMD.DLL
    nvapi.dll                  9.18.13.3182                NVIDIA NVAPI Library, Version 331.82 
    nvaudcap32v.dll            1.2.19.0                    NVIDIA Virtual Audio Driver
    nvcompiler.dll             8.17.13.3182                NVIDIA Compiler, Version 331.82 
    nvcpl.dll                  8.17.13.3182                NVIDIA Display Properties Extension
    nvcuda.dll                 8.17.13.3182                NVIDIA CUDA Driver, Version 331.82 
    nvcuvenc.dll               8.17.13.3182                NVIDIA CUDA Video Encoder, Version 331.82 
    nvcuvid.dll                8.17.13.3182                NVIDIA CUDA Video Decode API, Version 331.82 
    nvd3dum.dll                9.18.13.3182                NVIDIA WDDM D3D Driver, Version 331.82 
    nvdecodemft.dll            8.17.12.9639                NVIDIA Video Decoder MFT, Version 296.39 
    nvdispco32.dll             2.0.25.1                    Display Driver Coinstaller
    nvdispco3233182.dll        2.0.37.4                    Display Driver Coinstaller
    nvdispgenco3233182.dll     2.0.17.2                    Generic Coinstaller
    nvfbc.dll                  6.14.13.3182                NVIDIA Front Buffer Capture Library, Version 
    nvgenco32.dll              2.0.14.0                    Generic Coinstaller
    nvhdagenco32.dll           2.0.16.2                    Generic Coinstaller
    nvhdagenco3220103.dll      2.0.10.3                    Generic Coinstaller
    nvhdap32.dll               1.3.26.4                    NVIDIA HDMI Audio Driver
    nvifr.dll                  6.14.13.3182                NVIDIA In-band Frame Rendering Library, Version 
    nvinit.dll                 9.18.13.3182                NVIDIA shim initialization dll, Version 331.82 
    nvmctray.dll               8.17.13.3182                NVIDIA Media Center Library
    nvoglshim32.dll            9.18.13.3182                NVIDIA OpenGL Shim Driver, Version 331.82 
    nvoglv32.dll               9.18.13.3182                NVIDIA Compatible OpenGL ICD
    nvopencl.dll               8.17.13.3182                NVIDIA CUDA 6.0.1 OpenCL 1.1 Driver, Version 331.82 
    nvshext.dll                1.2.0.1                     NVIDIA Display Shell Extension
    nvspcap.dll                10.11.15.0                  NVIDIA Capture Server Proxy
    nvsvc.dll                  8.17.13.3182                NVIDIA Driver Helper Service, Version 331.82
    nvsvcr.dll                 8.17.13.3182                NVIDIA Driver Helper Service, Version 331.82
    nvumdshim.dll              9.18.13.3182                NVIDIA D3D Shim Driver, Version 331.82 
    nvwgf2um.dll               9.18.13.3182                NVIDIA D3D10 Driver, Version 331.82 
    objsel.dll                 6.1.7600.16385                
    occache.dll                9.0.8112.16421                  
    ocsetapi.dll               6.1.7600.16385              Windows Optional Component Setup API
    odbc16gt.dll               3.510.3711.0                Microsoft ODBC Driver Generic Thunk
    odbc32.dll                 6.1.7600.16688              ODBC Driver Manager
    odbc32gt.dll               6.1.7600.16385              ODBC Driver Generic Thunk
    odbcbcp.dll                6.1.7600.16385              BCP for ODBC
    odbcconf.dll               6.1.7600.16385              ODBC Driver Configuration Program
    odbccp32.dll               6.1.7600.16833              ODBC Installer
    odbccr32.dll               6.1.7600.16833              ODBC Cursor Library
    odbccu32.dll               6.1.7600.16833              ODBC Cursor Library
    odbcint.dll                6.1.7600.16385              ODBC Resources
    odbcji32.dll               6.1.7600.16385              Microsoft ODBC Desktop Driver Pack 3.5
    odbcjt32.dll               6.1.7600.16833              Microsoft ODBC Desktop Driver Pack 3.5
    odbctrac.dll               6.1.7600.16833              ODBC Driver Manager Trace
    oddbse32.dll               6.1.7600.16385              ODBC (3.0) driver for DBase
    odexl32.dll                6.1.7600.16385              ODBC (3.0) driver for Excel
    odfox32.dll                6.1.7600.16385              ODBC (3.0) driver for FoxPro
    odpdx32.dll                6.1.7600.16385              ODBC (3.0) driver for Paradox
    odtext32.dll               6.1.7600.16385              ODBC (3.0) driver for text files
    offfilt.dll                2008.0.7600.16385            OFFICE
    ogldrv.dll                 6.1.7600.16385              MSOGL
    ole2.dll                   2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    ole2disp.dll               2.10.3050.1                 OLE 2.1 16/32 Interoperability Library
    ole2nls.dll                2.10.3050.1                 OLE 2.1 16/32 Interoperability Library
    ole32.dll                  6.1.7600.16624              Microsoft OLE   Windows
    oleacc.dll                 7.0.0.0                     Active Accessibility Core Component
    oleacchooks.dll            7.0.0.0                     Active Accessibility Event Hooks Library
    oleaccrc.dll               7.0.0.0                     Active Accessibility Resource DLL
    oleaut32.dll               6.1.7600.16872              
    olecli.dll                 1.32.0.0                    Object Linking and Embedding Client Library
    olecli32.dll               6.1.7600.16385                OLE
    oledb32.dll                6.1.7600.16385              OLE DB Core Services
    oledb32r.dll               6.1.7600.16385                 OLE DB
    oledlg.dll                 6.1.7600.16385                 OLE
    oleprn.dll                 6.1.7600.16385              Oleprn DLL
    olepro32.dll               6.1.7600.16385              
    oleres.dll                 6.1.7600.16385                OLE
    olesvr.dll                 1.11.0.0                    Object Linking and Embedding Server Library
    olesvr32.dll               6.1.7600.16385              Object Linking and Embedding Server Library
    olethk32.dll               6.1.7600.16385              Microsoft OLE for Windows
    onex.dll                   6.1.7600.16385                IEEE 802.1X
    onexui.dll                 6.1.7600.16385                 IEEE 802.1X
    onlineidcpl.dll            6.1.7600.16385                -  
    oobefldr.dll               6.1.7600.16385                
    opcservices.dll            6.1.7600.16385              Native Code OPC Services Library
    opencl.dll                 1.0.0.0                     OpenCL Client DLL
    opengl32.dll               6.1.7600.16385              OpenGL Client DLL
    osbaseln.dll               6.1.7600.16385              Service Reporting API
    osuninst.dll               6.1.7600.16385              Uninstall Interface
    p2p.dll                    6.1.7600.16385                
    p2pcollab.dll              6.1.7600.16385                  
    p2pgraph.dll               6.1.7600.16385              Peer-to-Peer Graphing
    p2pnetsh.dll               6.1.7600.16385                 NetSh
    p2psvc.dll                 6.1.7600.16385               
    packager.dll               6.1.7600.16917               2
    panmap.dll                 6.1.7600.16385              PANOSE(tm) Font Mapper
    pautoenr.dll               6.1.7600.16385                
    pcadm.dll                  6.1.7600.16385              Program Compatibility Assistant Diagnostic Module
    pcaevts.dll                6.1.7600.16385                   
    pcasvc.dll                 6.1.7600.16385                  
    pcaui.dll                  6.1.7600.16385                  
    pcwum.dll                  6.1.7600.16385              Performance Counters for Windows Native DLL
    pcwutl.dll                 6.1.7600.16385                     
    pdh.dll                    6.1.7600.16385                  Windows
    pdhui.dll                  6.1.7600.16385                
    peerdist.dll               6.1.7600.16385                BranchCache
    peerdisthttptrans.dll      6.1.7600.16385              BranchCache HTTP Tansport
    peerdistsh.dll             6.1.7600.16385                BranchCache Netshell
    peerdistsvc.dll            6.1.7600.16385               BranchCache
    peerdistwsddiscoprov.dll   6.1.7600.16385              BranchCache WSD Discovery Provider
    perfcentercpl.dll          6.1.7600.16385               
    perfctrs.dll               6.1.7600.16385               
    perfdisk.dll               6.1.7600.16385                  Windows
    perfnet.dll                6.1.7600.16385                   Windows
    perfos.dll                 6.1.7600.16385                  Windows
    perfproc.dll               6.1.7600.16385                   Windows
    perftrack.dll              6.1.7600.16385              Microsoft Performance PerfTrack
    perfts.dll                 6.1.7600.16385              Windows Remote Desktop Services Performance Objects
    photometadatahandler.dll   6.1.7600.16385              Photo Metadata Handler
    photowiz.dll               6.1.7600.16385                
    pid.dll                    6.1.7600.16385              Microsoft PID
    pidgenx.dll                6.1.7600.16385              Pid Generation
    pifmgr.dll                 6.1.7600.16385              Windows NT PIF Manager Icon Resources Library
    pku2u.dll                  6.1.7600.16385              Pku2u Security Package
    pla.dll                    6.1.7600.16385                 
    playsndsrv.dll             6.1.7600.16385               PlaySound
    pmcsnap.dll                6.1.7600.16385              pmcsnap dll
    pmspl.dll                  2.10.0.1                    Microsoft LAN Manager 2.1 Network Dynamic Link Library for Microsoft Windows
    pngfilt.dll                9.0.8112.16421              IE PNG plugin image decoder
    pnidui.dll                 6.1.7600.16385                
    pnpsetup.dll               6.1.7600.16385              Pnp installer for CMI
    pnpts.dll                  6.1.7600.16385              PlugPlay Troubleshooter
    pnpui.dll                  5.2.3668.0                  DLL    
    pnpxassoc.dll              6.1.7600.16385              PNPX Association Dll
    pnpxassocprx.dll           6.1.7600.16385                PNPX
    pnrpauto.dll               6.1.7600.16385               DLL   PNRP
    pnrphc.dll                 6.1.7600.16385                 PNRP
    pnrpnsp.dll                6.1.7600.16385                 PNRP
    pnrpsvc.dll                6.1.7600.16385                PNRP
    polstore.dll               6.1.7600.16385              Policy Storage dll
    portabledeviceapi.dll      6.1.7600.16385               API    Windows
    portabledeviceclassextension.dll  6.1.7600.16385              Windows Portable Device Class Extension Component
    portabledeviceconnectapi.dll  6.1.7600.16385              Portable Device Connection API Components
    portabledevicestatus.dll   6.1.7600.16385                  Microsoft Windows
    portabledevicesyncprovider.dll  6.1.7600.16385                 Microsoft Windows
    portabledevicetypes.dll    6.1.7600.16385              Windows Portable Device (Parameter) Types Component
    portabledevicewiacompat.dll  6.1.7600.16385              PortableDevice WIA Compatibility Driver
    portabledevicewmdrm.dll    6.1.7600.16385              Windows Portable Device WMDRM Component
    pots.dll                   6.1.7600.16385               
    powercpl.dll               6.1.7600.16385                
    powrprof.dll               6.1.7600.16385              DLL     
    ppcsnap.dll                6.1.7600.16385              ppcsnap DLL
    presentationcffrasterizernative_v0300.dll  3.0.6920.4902               WinFX OpenType/CFF Rasterizer
    presentationhostproxy.dll  4.0.31106.0                 Windows Presentation Foundation Host Proxy
    presentationnative_v0300.dll  3.0.6920.4902               PresentationNative_v0300.dll
    prflbmsg.dll               6.1.7600.16385                  
    printfilterpipelineprxy.dll  6.1.7600.16385              Print Filter Pipeline Proxy
    printisolationproxy.dll    6.1.7600.16385              Print Sandbox COM Proxy Stub
    printui.dll                6.1.7600.16385                 
    prncache.dll               6.1.7600.16385              Print UI Cache
    prnfldr.dll                6.1.7600.16385              prnfldr dll
    prnntfy.dll                6.1.7600.16385              prnntfy DLL
    prntvpt.dll                6.1.7600.16385              Print Ticket Services Module
    procinst.dll               6.1.7600.16385                
    profapi.dll                6.1.7600.16385              User Profile Basic API
    profprov.dll               6.1.7600.16385              User Profile WMI Provider
    profsvc.dll                6.1.7600.16385              ProfSvc
    propsys.dll                7.0.7600.16385                 (Microsoft)
    provsvc.dll                6.1.7600.16385                Windows
    provthrd.dll               6.1.7600.16385              WMI Provider Thread & Log Library
    psapi.dll                  6.1.7600.16385              Process Status Helper
    psbase.dll                 6.1.7600.16385                
    pshed.dll                  6.1.7600.16385                ,   
    psisdecd.dll               6.6.7600.16867              Microsoft SI/PSI parser for MPEG2 based networks.
    pstorec.dll                6.1.7600.16385              Protected Storage COM interfaces
    pstorsvc.dll               6.1.7600.16385              Protected storage server
    puiapi.dll                 6.1.7600.16385               DLL puiapi
    puiobj.dll                 6.1.7600.16385               DLL  PrintUI
    pwrshplugin.dll            6.1.7600.16385              pwrshplugin.dll
    qagent.dll                 6.1.7600.16385                
    qagentrt.dll               6.1.7600.16385                  
    qasf.dll                   12.0.7600.16385             DirectShow ASF Support
    qcap.dll                   6.6.7600.16385                DirecxX DirectShow.
    qcliprov.dll               6.1.7600.16385               WMI   
    qdv.dll                    6.6.7600.16385                DirecxX DirectShow.
    qdvd.dll                   6.6.7600.16905              DirectShow DVD PlayBack Runtime.
    qedit.dll                  6.6.7600.16385               DirectShow
    qedwipes.dll               6.6.7600.16385              DirectShow Editing SMPTE Wipes
    qmgr.dll                   7.5.7600.16385                 
    qmgrprxy.dll               7.5.7600.16385              Background Intelligent Transfer Service Proxy
    qshvhost.dll               6.1.7600.16385                SHV
    qsvrmgmt.dll               6.1.7600.16385                
    quartz.dll                 6.6.7600.16905                DirecxX DirectShow.
    query.dll                  6.1.7600.16385                  
    qutil.dll                  6.1.7600.16385                
    qwave.dll                  6.1.7600.16385              Windows NT
    r4eea32a.dll               7.2.8000.17                 Dolby PCEE4 ASL Analog x86
    r4eed32a.dll               7.2.8000.17                 Dolby PCEE4 COM DLL x86
    r4eeg32a.dll               7.2.8000.17                 Dolby PCEE4 GFX APO x86
    r4eel32a.dll               7.2.8000.17                 Dolby PCEE4 LFX APO x86
    r4eep32a.dll               7.2.8000.17                 Dolby PCEE4 Control Panel x86
    racengn.dll                6.1.7600.16385                  
    racpldlg.dll               6.1.7600.16385                 
    radardt.dll                6.1.7600.16385                   Windows
    radarrs.dll                6.1.7600.16385                   Microsoft Windows
    rasadhlp.dll               6.1.7600.16385              Remote Access AutoDial Helper
    rasapi32.dll               6.1.7600.16385              Remote Access API
    rasauto.dll                6.1.7600.16385                   
    rascfg.dll                 6.1.7600.16385                RAS
    raschap.dll                6.1.7600.16385                 PPP CHAP
    rasctrs.dll                6.1.7600.16385                     Windows NT
    rasdiag.dll                6.1.7600.16385                  RAS
    rasdlg.dll                 6.1.7600.16385              API     
    rasgcw.dll                 6.1.7600.16385                RAS
    rasman.dll                 6.1.7600.16385              Remote Access Connection Manager
    rasmans.dll                6.1.7600.16385                 
    rasmbmgr.dll               6.1.7600.16385                 VPN -         .
    rasmm.dll                  6.1.7600.16385                RAS
    rasmontr.dll               6.1.7600.16385                RAS
    rasmxs.dll                 6.1.7600.16385              Remote Access Device DLL for modems, PADs and switches
    rasplap.dll                6.1.7600.16385                 RAS PLAP
    rasppp.dll                 6.1.7600.16385              Remote Access PPP
    rasser.dll                 6.1.7600.16385              Remote Access Media DLL for COM ports
    rastapi.dll                6.1.7600.16385              Remote Access TAPI Compliance Layer
    rastls.dll                 6.1.7600.16385                 PPP EAP-TLS
    rdpcfgex.dll               6.1.7600.16385                  ,       ,   RDP
    rdpcore.dll                6.1.7600.16963              RDP Core DLL
    rdpcorekmts.dll            6.1.7600.17009               DLL RDPCore TS (KM)
    rdpd3d.dll                 6.1.7600.16385              RDP Direct3D Remoting DLL
    rdpdd.dll                  6.1.7600.16385              RDP Display Driver
    rdpencdd.dll               6.1.7600.16385              RDP Encoder Mirror Driver
    rdpencom.dll               6.1.7600.16385              RDPSRAPI COM Objects
    rdpendp.dll                6.1.7600.16385                 RDP
    rdprefdd.dll               6.1.7600.16385              Microsoft RDP Reflector Display Driver
    rdprefdrvapi.dll           6.1.7600.16385              Reflector Driver API
    rdpwsx.dll                 6.1.7600.17009              RDP Extension DLL
    reagent.dll                6.1.7600.16385               DLL   Microsoft Windows
    recovery.dll               6.1.7600.16385                
    regapi.dll                 6.1.7600.16385              Registry Configuration APIs
    regctrl.dll                6.1.7600.16385              RegCtrl
    regidle.dll                6.1.7600.16385                 RegIdle
    regsvc.dll                 6.1.7600.16385                 
    remotepg.dll               6.1.7600.16385              CPL-  
    resampledmo.dll            6.1.7600.16385              Windows Media Resampler
    resutils.dll               6.1.7600.16385              Microsoft Cluster Resource Utility DLL
    rgb9rast.dll               6.1.7600.16385              Microsoft Windows Operating System
    riched20.dll               5.31.23.1229                Rich Text Edit Control, v3.1
    riched32.dll               6.1.7600.16385              Wrapper Dll for Richedit 1.0
    rnr20.dll                  6.1.7600.16385              Windows Socket2 NameSpace DLL
    rp3daa32.dll               6.0.6001.18                 PCEE3 DAA Control Panel x86
    rp3dht32.dll               6.0.6001.18                 PCEE3 DHT Control Panel x86
    rpcdiag.dll                6.1.7600.16385              RPC Diagnostics
    rpcepmap.dll               6.1.7600.16385                 RPC

    rpchttp.dll                6.1.7600.16385              RPC HTTP DLL
    rpcndfp.dll                1.0.0.1                        RPC NDF
    rpcns4.dll                 6.1.7600.16385                    (RPC)
    rpcnsh.dll                 6.1.7600.16385                RPC Netshell
    rpcrt4.dll                 6.1.7600.16385                 
    rpcrtremote.dll            6.1.7600.16385              Remote RPC Extension
    rpcss.dll                  6.1.7600.16385              Distributed COM Services
    rsaenh.dll                 6.1.7600.16385              Microsoft Enhanced Cryptographic Provider
    rshx32.dll                 6.1.7600.16385                
    rstrtmgr.dll               6.1.7600.16385               
    rteed32a.dll               6.1.6001.33                 Dolby PCEE3 COM DLL x86
    rteeg32a.dll               6.1.6001.33                 Dolby PCEE3 GFX APO x86
    rteel32a.dll               6.1.6001.33                 Dolby PCEE3 LFX APO x86
    rteep32a.dll               6.1.6001.33                 Dolby PCEE3 Control Panel x86
    rtffilt.dll                2008.0.7600.16385            RTF
    rtkapo.dll                 11.0.6000.347               Realtek(r) LFX/GFX DSP component 
    rtkapoapi.dll              1.0.0.70                    Realtek APO API
    rtkcoinstii.dll            2.1.5.5                     Realtek HD Audio Coinstaller
    rtkcoldr.dll               1.0.0.1                     Realtek HD Audio Coinstaller
    rtkpgext.dll               6.0.6000.297                Realtek LFX/GFX DSP UI component for Windows Vista
    rtm.dll                    6.1.7600.16385                
    rtutils.dll                6.1.7600.16617              Routing Utilities
    rtvcvfw32.dll                                          
    rtvcvfw64.dll                                          
    samcli.dll                 6.1.7600.16385              Security Accounts Manager Client DLL
    samlib.dll                 6.1.7600.16385              SAM Library DLL
    sampleres.dll              6.1.7600.16385               (Microsoft)
    samsrv.dll                 6.1.7600.16385                  
    sas.dll                    6.1.7600.16385              WinLogon Software SAS Library
    sbe.dll                    6.6.7600.16724              DirectShow Stream Buffer Filter.
    sbeio.dll                  12.0.7600.16385             Stream Buffer IO DLL
    sberes.dll                 6.6.7600.16385                  DirectShow.
    scansetting.dll            6.1.7600.16385                    Microsoft Windows(TM)
    scarddlg.dll               6.1.7600.16385              SCardDlg -   -
    scardsvr.dll               6.1.7600.16385                 -
    sccls.dll                  6.1.7600.16385               DLL    -
    scecli.dll                 6.1.7600.16385                 
    scesrv.dll                 6.1.7600.16385                
    scext.dll                  6.1.7600.16385                DLL      minwin-
    schannel.dll               6.1.7600.17035              TLS / SSL Security Provider
    schedcli.dll               6.1.7600.16385              Scheduler Service Client DLL
    schedsvc.dll               6.1.7600.16699                
    scksp.dll                  6.1.7600.16385              Microsoft Smart Card Key Storage Provider
    scp32.dll                  2.0.330.0                   Code Page Translation Library
    scripto.dll                6.6.7600.16385              Microsoft ScriptO
    scrobj.dll                 5.8.7600.16385              Windows  Script Component Runtime
    scrptadm.dll               6.1.7600.16385                
    scrrun.dll                 5.8.7600.16385              Microsoft  Script Runtime
    sdautoplay.dll             6.1.7600.16385                  Microsoft Windows
    sdcpl.dll                  6.1.7600.16385                  
    sdengin2.dll               6.1.7600.16385                Microsoft Windows
    sdhcinst.dll               6.1.7600.16385              Secure Digital Host Controller Class Installer
    sdiageng.dll               6.1.7600.16385                 
    sdiagprv.dll               6.1.7600.16385              API    Windows
    sdiagschd.dll              6.1.7600.16385                 
    sdohlp.dll                 6.1.7600.16385                 SDO NPS
    sdrsvc.dll                 6.1.7600.16385                Microsoft Windows
    sdshext.dll                6.1.7600.16385                 Microsoft Windows
    searchfolder.dll           6.1.7600.16385              SearchFolder
    sechost.dll                6.1.7600.16385              Host for SCM/SDDL/LSA Lookup APIs
    seclogon.dll               6.1.7600.16385              DLL   
    secproc.dll                6.1.7600.16385              Windows Rights Management Desktop Security Processor
    secproc_isv.dll            6.1.7600.16385              Windows Rights Management Desktop Security Processor
    secproc_ssp.dll            6.1.7600.16385              Windows Rights Management Services Server Security Processor
    secproc_ssp_isv.dll        6.1.7600.16385              Windows Rights Management Services Server Security Processor (Pre-production)
    secur32.dll                6.1.7600.16915              Security Support Provider Interface
    security.dll               6.1.7600.16385              Security Support Provider Interface
    sendmail.dll               6.1.7600.16385               
    sens.dll                   6.1.7600.16385                   (SENS)
    sensapi.dll                6.1.7600.16385              SENS Connectivity API DLL
    sensorsapi.dll             6.1.7600.16385              Sensor API
    sensorsclassextension.dll  6.1.7600.16385              Sensor Driver Class Extension component
    sensorscpl.dll             6.1.7600.16385                "    "
    sensrsvc.dll               6.1.7600.16385                  Microsoft Windows
    serialui.dll               6.1.7600.16385                
    serwvdrv.dll               6.1.7600.16385                Unimodem
    sessenv.dll                6.1.7600.16385                   
    setbcdlocale.dll           6.1.7600.16385              MUI Callback for Bcd
    setupapi.dll               6.1.7600.16385              Windows Setup API
    setupcln.dll               6.1.7600.16385                
    setupetw.dll               6.1.7600.16385                  Windows  
    sfapo.dll                  3.0.0.16                    SFAPO.DLL
    sfc.dll                    6.1.7600.16385              Windows File Protection
    sfc_os.dll                 6.1.7600.16385              Windows File Protection
    sfcom.dll                  3.0.0.16                    SFCOM.DLL
    sfnhk.dll                  3.0.0.16                    SFNHK.DLL
    sfss_apo.dll               1.6.0.7270                  Sony SFSS APO(32bit)
    shacct.dll                 6.1.7600.16385              Shell Accounts Classes
    sharemediacpl.dll          6.1.7600.16385                    
    shdocvw.dll                6.1.7600.16385                    
    shell.dll                  3.10.0.103                  Windows Shell library
    shell32.dll                6.1.7600.17038                 Windows
    shellstyle.dll             6.1.7600.16385              Windows Shell Style Resource Dll
    shfolder.dll               6.1.7600.16385              Shell Folder Service
    shgina.dll                 6.1.7600.16385              Windows Shell User Logon
    shimeng.dll                6.1.7600.16385              Shim Engine DLL
    shimgvw.dll                6.1.7600.16385               
    shlwapi.dll                6.1.7600.16385                 
    shpafact.dll               6.1.7600.16385              Windows Shell LUA/PA Elevation Factory Dll
    shsetup.dll                6.1.7600.16385              Shell setup helper
    shsvcs.dll                 6.1.7600.16385               DLL   Windows
    shunimpl.dll               6.1.7600.16385              Windows Shell Obsolete APIs
    shwebsvc.dll               6.1.7600.16385              -  Windows
    signdrv.dll                6.1.7600.16385              WMI provider for Signed Drivers
    sisbkup.dll                6.1.7600.16385              Single-Instance Store Backup Support Functions
    sl3apo32.dll               3.1.10.0                    DTS Studio Sound
    slc.dll                    6.1.7600.16385              Software Licensing Client DLL
    slcext.dll                 6.1.7600.16385              Software Licensing Client Extension Dll
    slcnt32.dll                3.1.10.0                    SRS Labs
    slprp32.dll                1.0.0.1                     TODO: <File description>
    sltech32.dll               3.1.10.0                    DTS Studio Sound
    slwga.dll                  6.1.7600.16385              Software Licensing WGA API
    smartcardcredentialprovider.dll  6.1.7600.16385                 - Windows
    smbhelperclass.dll         1.0.0.1                        SMB (   )    
    smiengine.dll              6.1.7600.16385              WMI Configuration Core
    sndvolsso.dll              6.1.7600.16385               SCA 
    snmpapi.dll                6.1.7600.16385              SNMP Utility Library
    sntsearch.dll              6.1.7600.16385               DLL  
    softkbd.dll                6.1.7600.16385                  
    softpub.dll                6.1.7600.16385              Softpub Forwarder DLL
    sortserver2003compat.dll   6.1.7600.16385              Sort Version Server 2003
    sortwindows6compat.dll     6.1.7600.16385              Sort Version Windows 6.0
    spbcd.dll                  6.1.7600.16385              BCD Sysprep Plugin
    spcmsg.dll                 6.1.7600.16385               Dll    
    sperror.dll                6.1.7600.16385                
    spfileq.dll                6.1.7600.16385              Windows SPFILEQ
    spinf.dll                  6.1.7600.16385              Windows SPINF
    spnet.dll                  6.1.7600.16385              Net Sysprep Plugin
    spoolss.dll                6.1.7600.16385              Spooler SubSystem DLL
    spopk.dll                  6.1.7600.16385              OPK Sysprep Plugin
    spp.dll                    6.1.7600.16385                  Microsoft Windows
    sppc.dll                   6.1.7600.16385              Software Licensing Client DLL
    sppcc.dll                  6.1.7600.16385                  
    sppcext.dll                6.1.7600.16385              Software Protection Platform Client Extension Dll
    sppcomapi.dll              6.1.7600.16385                 
    sppcommdlg.dll             6.1.7600.16385              API     
    sppinst.dll                6.1.7600.16385              SPP CMI Installer Plug-in DLL
    sppnp.dll                  6.1.7600.16385              PnP- SysPrep
    sppobjs.dll                6.1.7600.16385              Software Protection Platform Plugins
    sppuinotify.dll            6.1.7600.16385                SPP
    sppwinob.dll               6.1.7600.16385              Software Protection Platform Windows Plugin
    sppwmi.dll                 6.1.7600.16385              Software Protection Platform WMI provider
    spwinsat.dll               6.1.7600.16385              WinSAT Sysprep Plugin
    spwizeng.dll               6.1.7600.16385              Setup Wizard Framework
    spwizimg.dll               6.1.7600.16385              Setup Wizard Framework Resources
    spwizres.dll               6.1.7600.16385                 
    spwizui.dll                6.1.7600.16385               UI SPC
    spwmp.dll                  6.1.7600.16385              Windows Media Player System Preparation DLL
    sqlceoledb30.dll           3.0.7600.0                  Microsoft SQL Mobile
    sqlceqp30.dll              3.0.7600.0                  Microsoft SQL Mobile
    sqlcese30.dll              3.0.7600.0                  Microsoft SQL Mobile
    sqloledb.dll               6.1.7600.16385              OLE DB Provider for SQL Server
    sqlsrv32.dll               6.1.7600.16385              SQL Server ODBC Driver
    sqlunirl.dll               2000.80.728.0               String Function .DLL for SQL Enterprise Components
    sqlwid.dll                 1999.10.20.0                Unicode Function .DLL for SQL Enterprise Components
    sqlwoa.dll                 1999.10.20.0                Unicode/ANSI Function .DLL for SQL Enterprise Components
    sqlxmlx.dll                6.1.7600.16385              XML extensions for SQL Server
    sqmapi.dll                 6.1.7600.16385              SQM Client
    srchadmin.dll              7.0.7600.16385               
    srclient.dll               6.1.7600.16385              Microsoft Windows System Restore Client Library
    srcore.dll                 6.1.7600.16385                  Microsoft Windows
    srhelper.dll               6.1.7600.16385              Microsoft Windows driver and windows update enumeration library
    srpuxnativesnapin.dll      6.1.7600.16385                     
    srrstr.dll                 6.1.7600.16385                  Microsoft Windows
    srshp360.dll               1.1.0.0                     COM object implementing SRS Headphone 360
    srstshd.dll                1.1.4.0                     TruSurround HD and HD4 COM object for Windows
    srstsxt.dll                3.2.0.0                     TruSurroundXT Module
    srswow.dll                 1.1.3.0                     WOW HD COM object for Windows
    srvcli.dll                 6.1.7600.16385              Server Service Client DLL
    srvsvc.dll                 6.1.7600.16664               (DLL)    
    srwmi.dll                  6.1.7600.16385              Microsoft Windows System Restore WMI Provider
    sscore.dll                 6.1.7600.16385               DLL-  
    ssdpapi.dll                6.1.7600.16385              SSDP Client API DLL
    ssdpsrv.dll                6.1.7600.16385               DLL  SSDP
    sspicli.dll                6.1.7600.16915              Security Support Provider Interface
    sspisrv.dll                6.1.7600.16915              LSA SSPI RPC interface DLL
    ssshim.dll                 6.1.7600.16385              Windows Componentization Platform Servicing API
    sstpsvc.dll                6.1.7600.16385                 SSTP        VPN.
    stclient.dll               2001.12.8530.16385          COM+ Configuration Catalog Client
    sti.dll                    6.1.7600.16385                   
    sti_ci.dll                 6.1.7600.16385                 
    stobject.dll               6.1.7600.16385                 Systray
    storage.dll                2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    storagecontexthandler.dll  6.1.7600.16385                   
    storprop.dll               6.1.7600.16385                  
    streamci.dll               6.1.7600.16385              Streaming Device Class Installer
    structuredquery.dll        7.0.7600.16587              Structured Query
    sud.dll                    6.1.7600.16385                SUD
    swprv.dll                  6.1.7600.16385                 Microsoft Volume Shadow Copy Service
    sxproxy.dll                6.1.7600.16385                  Microsoft Windows
    sxs.dll                    6.1.7600.16385              Fusion 2.5
    sxshared.dll               6.1.7600.16385              Microsoft Windows SX Shared Library
    sxssrv.dll                 6.1.7600.16385              Windows SxS Server DLL
    sxsstore.dll               6.1.7600.16385              Sxs Store DLL
    synccenter.dll             6.1.7600.16385                
    synceng.dll                6.1.7600.17130              Windows Briefcase Engine
    synchostps.dll             6.1.7600.16385              Proxystub for sync host
    syncinfrastructure.dll     6.1.7600.16385                Microsoft Windows.
    syncinfrastructureps.dll   6.1.7600.16385              Microsoft Windows sync infrastructure proxy stub.
    syncreg.dll                2007.94.7600.16385          Microsoft Synchronization Framework Registration
    syncui.dll                 6.1.7600.16385               Windows
    sysclass.dll               6.1.7600.16385                 
    sysfxui.dll                6.1.7600.16385                   
    sysmain.dll                6.1.7600.16385                Superfetch
    sysntfy.dll                6.1.7600.16385              Windows Notifications Dynamic Link Library
    sysprepmce.dll             6.1.7600.16385              Windows Media Center SysPrep DLL
    syssetup.dll               6.1.7600.16385              Windows NT System Setup
    systemcpl.dll              6.1.7600.16385              CPL 
    t2embed.dll                6.1.7600.16663              Microsoft T2Embed Font Embedding
    tabbtn.dll                 6.1.7600.16385                  (Microsoft)
    tabbtnex.dll               6.1.7600.16385              Microsoft Tablet PC Extended Buttons Component
    tabsvc.dll                 6.1.7600.16385                  (Microsoft)
    tadefxapo.dll              1.0.1.12                    TOSHIBA Audio Enhancement APO
    tadefxapo2.dll             1.2.1.0                     TOSHIBA Audio Enhancement APO
    tapi.dll                   3.10.0.103                  Microsoft Windows(TM) Telephony Server16
    tapi3.dll                  6.1.7600.16385              Microsoft TAPI3
    tapi32.dll                 6.1.7600.16385               API  Microsoft Windows
    tapilua.dll                6.1.7600.16385              Microsoft Windows(TM) Phone And Modem Lua Elevation Dll
    tapimigplugin.dll          6.1.7600.16385              Microsoft Windows(TM) TAPI Migration Plugin Dll
    tapiperf.dll               6.1.7600.16385              Microsoft Windows(TM) Telephony Performance Monitor
    tapisrv.dll                6.1.7600.16385                 Microsoft Windows
    tapisysprep.dll            6.1.7600.16385              Microsoft Windows(TM) Telephony Sysprep Work
    tapiui.dll                 6.1.7600.16385               DLL   Microsoft Windows
    taskbarcpl.dll             6.1.7600.16385                -  
    taskcomp.dll               6.1.7600.16699                  
    taskschd.dll               6.1.7600.16699              Task Scheduler COM API
    taskschdps.dll             6.1.7600.16385              Task Scheduler Interfaces Proxy
    tbs.dll                    6.1.7600.16385              TBS
    tbssvc.dll                 6.1.7600.16385               TBS
    tcpipcfg.dll               6.1.7600.16385                
    tcpmib.dll                 6.1.7600.16385              Standard TCP/IP Port Monitor Helper DLL
    tcpmon.dll                 6.1.7600.16385                 TCP/IP
    tcpmonui.dll               6.1.7600.16385                  TCP/IP
    tdh.dll                    6.1.7600.16385                 
    tepeqapo.dll               1.1.0.0                     Tepeq APO
    termmgr.dll                6.1.7600.16385              Microsoft TAPI3 Terminal Manager
    termsrv.dll                6.1.7600.16385                  ,       
    thawbrkr.dll               6.1.7600.16385              Thai Word Breaker
    themecpl.dll               6.1.7600.16385              CPL 
    themeservice.dll           6.1.7600.16385               DLL    Windows
    themeui.dll                6.1.7600.16385              API   Windows
    thumbcache.dll             6.1.7600.16385                
    timedatemuicallback.dll    6.1.7600.16385              Time Date Control UI Language Change plugin
    tlscsp.dll                 6.1.7600.16385              Microsoft Remote Desktop Services Cryptographic Utility
    toolhelp.dll               3.10.0.103                  Windows Debug/Tool helper library
    tosade.dll                 1.0.1.12                    TOSHIBA Audio Enhancement
    tpmcompc.dll               6.1.7600.16385                
    tquery.dll                 7.0.7600.16385              tquery.dll
    traffic.dll                6.1.7600.16385              Microsoft Traffic Control 1.0 DLL
    trapi.dll                  6.1.7600.16385              Microsoft Narrator Text Renderer
    trkwks.dll                 6.1.7600.16385                 
    tsbyuv.dll                 6.1.7600.16490              Toshiba Video Codec
    tscfgwmi.dll               6.1.7600.16385              Remote Desktop Session Host Server Configuration WMI provider
    tschannel.dll              6.1.7600.16385              Task Scheduler Proxy
    tsddd.dll                  6.1.7600.16385              Framebuffer Display Driver
    tserrredir.dll             6.1.7600.16385              Remote Desktop Services Logon Error Redirector
    tsgqec.dll                 6.1.7600.17233                      
    tsmf.dll                   6.1.7600.16385                MF    
    tspkg.dll                  6.1.7600.16385              Web Service Security Package
    tspnprdrcoinstaller.dll    6.1.7600.16385              Remote Desktop PnP Redirected Device Co-Installer
    tspubwmi.dll               6.1.7600.16385              Remote Desktop Programs WMI provider
    tsworkspace.dll            6.1.7600.16385                      RemoteApp
    tvratings.dll              6.6.7600.16385              Module for managing TV ratings
    twext.dll                  6.1.7600.16385              :  
    txflog.dll                 2001.12.8530.16385          COM+
    txfw32.dll                 6.1.7600.16385              TxF Win32 DLL
    typelib.dll                2.10.3029.1                 OLE 2.1 16/32 Interoperability Library
    tzres.dll                  6.1.7600.17162               DLL   
    ubpm.dll                   6.1.7600.16385               DLL    
    ucmhc.dll                  6.1.7600.16385                 UCM
    udhisapi.dll               6.1.7600.16385              UPnP Device Host ISAPI Extension
    udwm.dll                   6.1.7600.16385                  
    uexfat.dll                 6.1.7600.16385              eXfat Utility DLL
    ufat.dll                   6.1.7600.16385              FAT Utility DLL
    uianimation.dll            6.1.7600.16385              Windows Animation Manager
    uiautomationcore.dll       7.0.0.0                        Microsoft UI
    uicom.dll                  6.1.7600.16385              Add/Remove Modems
    uihub.dll                  6.1.7600.16385                     (Microsoft)
    uiribbon.dll               6.1.7600.16385                Windows
    uiribbonres.dll            6.1.7600.16385              Windows Ribbon Framework Resources
    ulib.dll                   6.1.7600.16385              DLL   
    umb.dll                    6.1.7600.16385              User Mode Bus Driver Interface Dll
    umdmxfrm.dll               6.1.7600.16385              Unimodem Tranform Module
    umpnpmgr.dll               6.1.7600.16820                  (Plug-and-Play)
    umpo.dll                   6.1.7600.16385                 
    umrdp.dll                  6.1.7600.16385                    
    unattend.dll               6.1.7600.16385              Unattend Library
    unimdmat.dll               6.1.7600.16385              - AT   Unimodem
    uniplat.dll                6.1.7600.16385              Unimodem AT Mini Driver Platform Driver for Windows NT
    unrar.dll                  4.20.100.526                
    untfs.dll                  6.1.7600.16385              NTFS Utility DLL
    upnp.dll                   6.1.7600.16385              API   UPnP
    upnphost.dll               6.1.7600.16385                PNP-
    ureg.dll                   6.1.7600.16385              Registry Utility DLL
    url.dll                    9.0.8112.16526              Internet Shortcut Shell Extension DLL
    urlmon.dll                 9.0.8112.16526               OLE32  Win32
    usbceip.dll                6.1.7600.16385               USBCEIP
    usbmon.dll                 6.1.7600.16385              Standard Dynamic Printing Port Monitor DLL
    usbperf.dll                6.1.7600.16385               DLL   USB
    usbui.dll                  6.1.7600.16385              USB UI Dll
    user32.dll                 6.1.7600.16385                 USER API Windows
    useraccountcontrolsettings.dll  6.1.7600.16385                  
    usercpl.dll                6.1.7600.16385                
    userenv.dll                6.1.7600.16385              Userenv
    usp10.dll                  1.626.7600.16385            Uniscribe Unicode script processor
    utildll.dll                6.1.7600.16385                WinStation
    uudf.dll                   6.1.7600.16385              UDF Utility DLL
    uxinit.dll                 6.1.7600.16385              Windows User Experience Session Initialization Dll
    uxlib.dll                  6.1.7600.16385              Setup Wizard Framework
    uxlibres.dll               6.1.7600.16385              UXLib Resources
    uxsms.dll                  6.1.7600.16385              Microsoft User Experience Session Management Service
    uxtheme.dll                6.1.7600.16385                UxTheme (Microsoft)
    van.dll                    6.1.7600.16385                
    vault.dll                  6.1.7600.16385                -  Windows
    vaultcli.dll               6.1.7600.16385              Credential Vault Client Library
    vaultcredprovider.dll      6.1.7600.16385                 Vault
    vaultsvc.dll               6.1.7600.16385                 
    vbajet32.dll               6.0.1.9431                  Visual Basic for Applications Development Environment - Expression Service Loader
    vbame.dll                  2.0.2.5                     VBA : Middle East Support
    vbscript.dll               5.8.7601.17026              Microsoft  VBScript
    vcamp110.dll               11.0.50727.1                Microsoft C++ AMP Runtime
    vccorlib110.dll            11.0.50727.1                Microsoft  VC WinRT core library
    vcomp100.dll               10.0.40219.1                Microsoft C/C++ OpenMP Runtime
    vcomp110.dll               11.0.50727.1                Microsoft C/C++ OpenMP Runtime
    vdmdbg.dll                 6.1.7600.16385              VDMDBG.DLL
    vdmredir.dll               6.1.7600.16385              Virtual Dos Machine Network Interface Library
    vds_ps.dll                 6.1.7600.16385              Microsoft Virtual Disk Service proxy/stub
    vdsbas.dll                 6.1.7600.16385                  
    vdsdyn.dll                 6.1.7600.16385                  VDS,  2.1.0.1
    vdsutil.dll                6.1.7600.16385                  
    vdsvd.dll                  6.1.7600.16385              VDS Virtual Disk Provider, Version 1.0
    ver.dll                    3.10.0.103                  Version Checking and File Installation Libraries
    verifier.dll               6.1.7600.16385              Standard application verifier provider dll
    version.dll                6.1.7600.16385              Version Checking and File Installation Libraries
    vfpodbc.dll                1.0.2.0                     vfpodbc
    vfwwdm32.dll               6.1.7600.16385               VfW MM Driver    WDM-
    vga.dll                    6.1.7600.16385              VGA 16 Colour Display Driver
    vga256.dll                 6.1.7600.16385              256 Color VGA\SVGA Display Driver
    vga64k.dll                 6.1.7600.16385              32K/64K color VGA\SVGA Display Driver
    vidreszr.dll               6.1.7600.16385              Windows Media Resizer
    virtdisk.dll               6.1.7600.16385              Virtual Disk API DLL
    vmbuscoinstaller.dll       6.1.7600.16385              Hyper-V VMBUS Coinstaller
    vmbuspipe.dll              6.1.7600.16385              VmBus User Mode Pipe DLL
    vmbusres.dll               6.1.7600.16385                 VMBus
    vmdcoinstall.dll           6.1.7600.16385              Hyper-V Integration Components Coinstaller
    vmicres.dll                6.1.7600.16385                    
    vmictimeprovider.dll       6.1.7600.16385              Virtual Machine Integration Component Time Sync Provider Library
    vmstorfltres.dll           6.1.7600.16385                   
    vpnike.dll                 6.1.7600.16385              VPNIKE Protocol Engine - Test dll
    vpnikeapi.dll              6.1.7600.16385              VPN IKE API's
    vss_ps.dll                 6.1.7600.16385              Microsoft Volume Shadow Copy Service proxy/stub
    vssapi.dll                 6.1.7600.16385              Microsoft Volume Shadow Copy Requestor/Writer Services API DLL
    vsstrace.dll               6.1.7600.16385                    Microsoft
    w32time.dll                6.1.7600.16385                Windows
    w32topl.dll                6.1.7600.16385              Windows NT Topology Maintenance Tool
    wab32.dll                  6.1.7600.16891              Microsoft (R) Contacts DLL
    wab32res.dll               6.1.7600.16385               Microsoft (R) DLL
    wabsyncprovider.dll        6.1.7600.16385                 Microsoft Windows
    wavdest.dll                6.1.7600.16385              Windows Sound Recorder
    wavemsp.dll                6.1.7600.16385              Microsoft Wave MSP
    wavesguilib.dll            4.4.3.0                     General Library for Plug-Ins
    waveslib.dll               5.9.7.0                     General Library for Plug-Ins
    wbemcomn.dll               6.1.7600.16385              WMI
    wbiosrvc.dll               6.1.7600.16385                Windows
    wcnapi.dll                 6.1.7600.16385              Windows Connect Now - API Helper DLL
    wcncsvc.dll                6.1.7600.16385                Windows -   
    wcneapauthproxy.dll        6.1.7600.16385              Windows Connect Now - WCN EAP Authenticator Proxy
    wcneappeerproxy.dll        6.1.7600.16385              Windows Connect Now - WCN EAP PEER Proxy
    wcnnetsh.dll               6.1.7600.16385               DLL    Netsh  WCN
    wcnwiz.dll                 6.1.7600.16385                Windows Connect Now
    wcspluginservice.dll       6.1.7600.16385               DLL WcsPlugInService
    wdc.dll                    6.1.7600.16385               
    wdi.dll                    6.1.7600.16385                Windows
    wdiasqmmodule.dll          6.1.7600.16385              Adaptive SQM WDI Plugin
    wdigest.dll                6.1.7600.16385              Microsoft Digest Access
    wdscore.dll                6.1.7600.16385              Panther Engine Module
    webcheck.dll               9.0.8112.16421               -
    webclnt.dll                6.1.7600.16385               DLL - DAV
    webio.dll                  6.1.7600.16915              API    
    webservices.dll            6.1.7600.16385                - Windows
    wecapi.dll                 6.1.7600.16385              Event Collector Configuration API
    wecsvc.dll                 6.1.7600.16385                
    wer.dll                    6.1.7600.16385                  Windows
    werconcpl.dll              6.1.7600.16385              PRS CPL
    wercplsupport.dll          6.1.7600.16385                   
    werdiagcontroller.dll      6.1.7600.16385              WER Diagnostic Controller
    wersvc.dll                 6.1.7600.16385                 Windows
    werui.dll                  6.1.7600.16385               DLL      Windows
    wevtapi.dll                6.1.7600.16385              API    
    wevtfwd.dll                6.1.7600.16385              WS-Management Event Forwarding Plug-in
    wevtsvc.dll                6.1.7600.16385                
    wfapigp.dll                6.1.7600.16385              Windows Firewall GPO Helper dll
    wfhc.dll                   6.1.7600.16385               Windows.   
    wfsr.dll                   6.1.7600.16385                  Windows
    whealogr.dll               6.1.7600.16385                WHEA
    whhelper.dll               6.1.7600.16385              DLL     winHttp
    wiaaut.dll                 6.1.7600.16385               WIA-
    wiadefui.dll               6.1.7600.16385                  WIA
    wiadss.dll                 6.1.7600.16385               WIA -  TWAIN
    wiarpc.dll                 6.1.7600.16385              Windows Image Acquisition RPC client DLL
    wiascanprofiles.dll        6.1.7600.16385              Microsoft Windows ScanProfiles
    wiaservc.dll               6.1.7600.16385                  
    wiashext.dll               6.1.7600.16385                     
    wiatrace.dll               6.1.7600.16385              WIA Tracing
    wiavideo.dll               6.1.7600.16385              WIA Video
    wifeman.dll                3.10.0.103                  Windows WIFE interface core component
    wimgapi.dll                6.1.7600.16385               Windows Imaging
    win32spl.dll               6.1.7600.17162                    
    win87em.dll                                            
    winbio.dll                 6.1.7600.16385              API   Windows
    winbrand.dll               6.1.7600.16385              Windows Branding Resources
    wincredprovider.dll        6.1.7600.16385               DLL wincredprovider
    windowscodecs.dll          6.1.7600.16385              Microsoft Windows Codecs Library
    windowscodecsext.dll       6.1.7600.16385              Microsoft Windows Codecs Extended Library
    winethc.dll                6.1.7600.16385                 WinInet
    winfax.dll                 6.1.7600.16385              Microsoft  Fax API Support DLL
    winhttp.dll                6.1.7600.16385               HTTP Windows
    wininet.dll                9.0.8112.16526                 Win32
    winipsec.dll               6.1.7600.16385              Windows IPsec SPD Client DLL
    winmm.dll                  6.1.7600.16385              MCI API DLL
    winnls.dll                 3.10.0.103                  Windows IME interface core component
    winnsi.dll                 6.1.7600.16385              Network Store Information RPC interface
    winrnr.dll                 6.1.7600.16385              LDAP RnR Provider DLL
    winrscmd.dll               6.1.7600.16385              remtsvc
    winrsmgr.dll               6.1.7600.16385              WSMan Shell API
    winrssrv.dll               6.1.7600.16385              winrssrv
    winsatapi.dll              6.1.7600.16385              Windows System Assessment Tool API
    winscard.dll               6.1.7600.16385              API - (Microsoft)
    winshfhc.dll               6.1.7600.16385              File Risk Estimation
    winsock.dll                3.10.0.103                  Windows Socket 16-Bit DLL
    winsockhc.dll              6.1.7600.16385                   Winsock
    winsrpc.dll                6.1.7600.16385              WINS RPC LIBRARY
    winsrv.dll                 6.1.7600.17206                 Windows
    winsta.dll                 6.1.7600.16385              Winstation Library
    winsync.dll                2007.94.7600.16385          Synchronization Framework
    winsyncmetastore.dll       2007.94.7600.16385          Windows Synchronization Metadata Store
    winsyncproviders.dll       2007.94.7600.16385          Windows Synchronization Provider Framework
    wintrust.dll               6.1.7600.17115              Microsoft Trust Verification APIs
    winusb.dll                 6.1.7600.16385              Windows USB Driver User Library
    wkscli.dll                 6.1.7600.16385              Workstation Service Client DLL
    wksprtps.dll               6.1.7600.16385              WorkspaceRuntime ProxyStub DLL
    wkssvc.dll                 6.1.7600.16385               DLL   
    wlanapi.dll                6.1.7600.16385              Windows WLAN AutoConfig Client Side API DLL
    wlancfg.dll                6.1.7600.16385               DLL    Netsh  WLAN
    wlanconn.dll               6.1.7600.16385                Dot11
    wlandlg.dll                6.1.7600.16385                   
    wlangpui.dll               6.1.7600.16385               "   "
    wlanhc.dll                 6.1.7600.16385                   
    wlanhlp.dll                6.1.7600.16385              Windows Wireless LAN 802.11 Client Side Helper API
    wlaninst.dll               6.1.7600.16385              Windows NET Device Class Co-Installer for Wireless LAN
    wlanmm.dll                 6.1.7600.16385                Dot11   
    wlanmsm.dll                6.1.7600.16385              Windows Wireless LAN 802.11 MSM DLL
    wlanpref.dll               6.1.7600.16385                
    wlansec.dll                6.1.7600.16385              Windows Wireless LAN 802.11 MSM Security Module DLL
    wlansvc.dll                6.1.7600.16385               DLL       Windows
    wlanui.dll                 6.1.7600.16385                 
    wlanutil.dll               6.1.7600.16385               DLL     Windows   802.11
    wldap32.dll                6.1.7600.16385              Win32 LDAP API DLL
    wlgpclnt.dll               6.1.7600.16385                 802.11
    wls0wndh.dll               6.1.7600.16385              Session0 Viewer Window Hook DLL
    wmadmod.dll                6.1.7600.16385              Windows Media Audio Decoder
    wmadmoe.dll                6.1.7600.16385              Windows Media Audio 10 Encoder/Transcoder
    wmalfxgfxdsp.dll           6.1.7600.16385              SysFx DSP
    wmasf.dll                  12.0.7600.16385             Windows Media ASF DLL
    wmcodecdspps.dll           6.1.7600.16385              Windows Media CodecDSP Proxy Stub Dll
    wmdmlog.dll                12.0.7600.16385             Windows Media Device Manager Logger
    wmdmps.dll                 12.0.7600.16385             Windows Media Device Manager Proxy Stub
    wmdrmdev.dll               12.0.7600.16385             Windows Media DRM for Network Devices Registration DLL
    wmdrmnet.dll               12.0.7600.16385             Windows Media DRM for Network Devices DLL
    wmdrmsdk.dll               11.0.7600.16385             Windows Media DRM SDK DLL
    wmerror.dll                12.0.7600.16385               Windows Media ()
    wmi.dll                    6.1.7600.16970              WMI DC and DP functionality
    wmicmiplugin.dll           6.1.7600.16699              WMI CMI Plugin
    wmidx.dll                  12.0.7600.16385             Windows Media Indexer DLL
    wmiprop.dll                6.1.7600.16385                  WDM
    wmnetmgr.dll               12.0.7600.16385             Windows Media Network Plugin Manager DLL
    wmp.dll                    12.0.7600.16667             Windows Media Player
    wmpcm.dll                  12.0.7600.16385             Windows Media Player Compositing Mixer
    wmpdui.dll                 12.0.7600.16385             Windows Media Player UI Engine
    wmpdxm.dll                 12.0.7600.16385             Windows Media Player Extension
    wmpeffects.dll             12.0.7600.16385             Windows Media Player Effects
    wmpencen.dll               12.0.7600.16385             Windows Media Player Encoding Module
    wmphoto.dll                6.1.7600.16385               Windows Media
    wmploc.dll                 12.0.7600.16667               Windows Media
    wmpmde.dll                 12.0.7600.16661             WMPMDE DLL
    wmpps.dll                  12.0.7600.16385             Windows Media Player Proxy Stub Dll
    wmpshell.dll               12.0.7600.16385                Windows Media
    wmpsrcwp.dll               12.0.7600.16385             WMPSrcWp Module
    wmsgapi.dll                6.1.7600.16385              WinLogon IPC Client
    wmspdmod.dll               6.1.7600.16385              Windows Media Audio Voice Decoder
    wmspdmoe.dll               6.1.7600.16385              Windows Media Audio Voice Encoder
    wmvcore.dll                12.0.7600.16385             Windows Media Playback/Authoring DLL
    wmvdecod.dll               6.1.7600.16597              Windows Media Video Decoder
    wmvdspa.dll                6.1.7600.16385              Windows Media Video DSP Components - Advanced
    wmvencod.dll               6.1.7600.16385              Windows Media Video 9 Encoder
    wmvsdecd.dll               6.1.7600.16385              Windows Media Screen Decoder
    wmvsencd.dll               6.1.7600.16385              Windows Media Screen Encoder
    wmvxencd.dll               6.1.7600.16385              Windows Media Video Encoder
    wow32.dll                  6.1.7600.16385              32-bit WOW Subsystem Library
    wpc.dll                    1.0.0.1                        
    wpcao.dll                  6.1.7600.16385                WPC
    wpccpl.dll                 6.1.7600.16385                 " "
    wpcmig.dll                 1.0.0.1                         Windows
    wpcsvc.dll                 1.0.0.1                         Windows
    wpcumi.dll                 1.0.0.1                        Windows
    wpd_ci.dll                 6.1.7600.16385                     Windows
    wpdbusenum.dll             6.1.7600.16385                
    wpdmtp.dll                 6.1.7600.16385              MTP core protocol component
    wpdmtpus.dll               6.1.7600.16385              Usbscan transport layer for MTP driver
    wpdshext.dll               6.1.7600.16385                  
    wpdshserviceobj.dll        6.1.7600.16385              Windows Portable Device Shell Service Object
    wpdsp.dll                  6.1.7600.16385              WMDM Service Provider for Windows Portable Devices
    wpdwcn.dll                 6.1.7600.16385                    WCN
    ws2_32.dll                 6.1.7600.16385              32-  Windows Socket 2.0
    ws2help.dll                6.1.7600.16385              Windows Socket 2.0 Helper for Windows NT
    wscapi.dll                 6.1.7600.16385              Windows Security Center API
    wscinterop.dll             6.1.7600.16385              Windows Health Center WSC Interop
    wscisvif.dll               6.1.7600.16385              Windows Security Center ISV API
    wscmisetup.dll             6.1.7600.16385              Installers for Winsock Transport and Name Space Providers
    wscproxystub.dll           6.1.7600.16385              Windows Security Center ISV Proxy Stub
    wscsvc.dll                 6.1.7600.16385                  Windows
    wsdapi.dll                 6.1.7600.16385              -   DLL API- 
    wsdchngr.dll               6.1.7600.16385              WSD Challenge Component
    wsdmon.dll                 6.1.7600.16385                 WSD
    wsdprintproxy.dll          6.1.7600.16385              Function Discovery Printer Proxy Dll
    wsdscanproxy.dll           6.1.7600.16385              Function Discovery WSD Scanner Proxy Dll
    wsecedit.dll               6.1.7600.16385                 
    wsepno.dll                 7.0.7600.16385                     Windows Search
    wshbth.dll                 6.1.7600.16385              Windows Sockets Helper DLL
    wshcon.dll                 5.8.7600.16385              Microsoft  Windows Script Controller
    wshelper.dll               6.1.7600.16385               DLL    Winsock Net
    wshext.dll                 5.8.7600.16385              Microsoft  Shell Extension for Windows Script Host
    wship6.dll                 6.1.7600.16385               DLL  Winsock2 (TL/IPv6)
    wshirda.dll                6.1.7600.16385              Windows Sockets Helper DLL
    wshnetbs.dll               6.1.7600.16385              Netbios Windows Sockets Helper DLL
    wshqos.dll                 6.1.7600.16385               DLL   QoS Winsock2
    wshrm.dll                  6.1.7600.16385                DLL   Windows  PGM
    wshtcpip.dll               6.1.7600.16385               DLL   Winsock2 (TL/IPv4)
    wsmanmigrationplugin.dll   6.1.7600.16385              WinRM Migration Plugin
    wsmauto.dll                6.1.7600.16385              WSMAN Automation
    wsmplpxy.dll               6.1.7600.16385              wsmplpxy
    wsmres.dll                 6.1.7600.16385               DLL  WSMan
    wsmsvc.dll                 6.1.7600.16385               WSMan
    wsmwmipl.dll               6.1.7600.16385              WSMAN WMI Provider
    wsnmp32.dll                6.1.7600.16385              Microsoft WinSNMP v2.0 Manager API
    wsock32.dll                6.1.7600.16385              Windows Socket 32-Bit DLL
    wtsapi32.dll               6.1.7600.16385              Windows Remote Desktop Session Host Server SDK APIs
    wuapi.dll                  7.6.7600.256                API    Windows
    wuaueng.dll                7.6.7600.256                  Windows
    wucltux.dll                7.6.7600.256                     Windows
    wudfcoinstaller.dll        6.1.7600.16385              Windows Driver Foundation - User-mode Platform Device Co-Installer
    wudfplatform.dll           6.1.7600.16385              Windows Driver Foundation -    
    wudfsvc.dll                6.1.7600.16385              Windows Driver Foundation (WDF) -     
    wudfx.dll                  6.1.7600.16385              WDF:UMDF Framework Library
    wudriver.dll               7.6.7600.256                Windows Update WUDriver Stub
    wups.dll                   7.6.7600.256                Windows Update client proxy stub
    wups2.dll                  7.6.7600.256                Windows Update client proxy stub 2
    wuwebv.dll                 7.6.7600.256                Windows Update Vista Web Control
    wvc.dll                    6.1.7600.16385              Windows Visual Components
    wwanadvui.dll              8.1.2.0                         
    wwanapi.dll                6.1.7600.16385              Mbnapi
    wwancfg.dll                6.1.7600.16385                DLL  Netsh  MBN
    wwanconn.dll               8.1.2.0                         
    wwanhc.dll                 8.1.2.0                         
    wwaninst.dll               8.1.2.0                     Windows NET Device Class Co-Installer for Wireless WAN
    wwanmm.dll                 8.1.2.0                         
    wwanpref.dll               8.1.2.0                          
    wwanprotdim.dll            8.1.2.0                     WWAN Device Interface Module
    wwansvc.dll                8.1.2.0                       WWAN
    wwapi.dll                  8.1.2.0                     WWAN API
    wzcdlg.dll                 6.1.7600.16385              Windows Connect Now - Flash Config Enrollee
    x264vfw.dll                38.2274.36885.0             x264vfw - H.264/MPEG-4 AVC codec
    x3daudio1_0.dll            9.11.519.0                  X3DAudio
    x3daudio1_1.dll            9.15.779.0                  X3DAudio
    x3daudio1_2.dll            9.21.1148.0                 X3DAudio
    x3daudio1_3.dll            9.22.1284.0                 X3DAudio
    x3daudio1_4.dll            9.23.1350.0                 X3DAudio
    x3daudio1_5.dll            9.25.1476.0                 X3DAudio
    x3daudio1_6.dll            9.26.1590.0                 3D Audio Library
    x3daudio1_7.dll            9.28.1886.0                 3D Audio Library
    xactengine2_0.dll          9.11.519.0                  XACT Engine API
    xactengine2_1.dll          9.12.589.0                  XACT Engine API
    xactengine2_10.dll         9.21.1148.0                 XACT Engine API
    xactengine2_2.dll          9.13.644.0                  XACT Engine API
    xactengine2_3.dll          9.14.701.0                  XACT Engine API
    xactengine2_4.dll          9.15.779.0                  XACT Engine API
    xactengine2_5.dll          9.16.857.0                  XACT Engine API
    xactengine2_6.dll          9.17.892.0                  XACT Engine API
    xactengine2_7.dll          9.18.944.0                  XACT Engine API
    xactengine2_8.dll          9.19.1007.0                 XACT Engine API
    xactengine2_9.dll          9.20.1057.0                 XACT Engine API
    xactengine3_0.dll          9.22.1284.0                 XACT Engine API
    xactengine3_1.dll          9.23.1350.0                 XACT Engine API
    xactengine3_2.dll          9.24.1400.0                 XACT Engine API
    xactengine3_3.dll          9.25.1476.0                 XACT Engine API
    xactengine3_4.dll          9.26.1590.0                 XACT Engine API
    xactengine3_5.dll          9.27.1734.0                 XACT Engine API
    xactengine3_6.dll          9.28.1886.0                 XACT Engine API
    xactengine3_7.dll          9.29.1962.0                 XACT Engine API
    xapofx1_0.dll              9.23.1350.0                 XAPOFX
    xapofx1_1.dll              9.24.1400.0                 XAPOFX
    xapofx1_2.dll              9.25.1476.0                 XAPOFX
    xapofx1_3.dll              9.26.1590.0                 Audio Effect Library
    xapofx1_4.dll              9.28.1886.0                 Audio Effect Library
    xapofx1_5.dll              9.29.1962.0                 Audio Effect Library
    xaudio2_0.dll              9.22.1284.0                 XAudio2 Game Audio API
    xaudio2_1.dll              9.23.1350.0                 XAudio2 Game Audio API
    xaudio2_2.dll              9.24.1400.0                 XAudio2 Game Audio API
    xaudio2_3.dll              9.25.1476.0                 XAudio2 Game Audio API
    xaudio2_4.dll              9.26.1590.0                 XAudio2 Game Audio API
    xaudio2_5.dll              9.27.1734.0                 XAudio2 Game Audio API
    xaudio2_6.dll              9.28.1886.0                 XAudio2 Game Audio API
    xaudio2_7.dll              9.29.1962.0                 XAudio2 Game Audio API
    xinput1_1.dll              9.12.589.0                  Microsoft Common Controller API
    xinput1_2.dll              9.14.701.0                  Microsoft Common Controller API
    xinput1_3.dll              9.18.944.0                  Microsoft Common Controller API
    xinput9_1_0.dll            6.1.7600.16385                XNA
    xmlfilter.dll              2008.0.7600.16385            XML
    xmllite.dll                1.3.1000.0                  Microsoft XmlLite Library
    xmlprovi.dll               6.1.7600.16385              Network Provisioning Service Client API
    xmlrw.dll                  2.0.3609.0                  Microsoft XML Slim Library
    xmlrwbin.dll               2.0.3609.0                  Microsoft XML Slim Library
    xolehlp.dll                2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Helper APIs DLL
    xpsfilt.dll                6.1.7600.16385              XML Paper Specification Document IFilter
    xpsgdiconverter.dll        6.1.7600.16699              XPS to GDI Converter
    xpsprint.dll               6.1.7600.16699              XPS Printing DLL
    xpsrasterservice.dll       6.1.7600.16699              XPS Rasterization Service Component
    xpsservices.dll            6.1.7600.16385              Xps Object Model in memory creation and deserialization
    xpsshhdr.dll               6.1.7600.16385              Package Document Shell Extension Handler
    xpssvcs.dll                6.1.7600.16385              Native Code Xps Services Library
    xvidcore.dll                                           
    xvidvfw.dll                                            
    xwizards.dll               6.1.7600.16385                 
    xwreg.dll                  6.1.7600.16385              Extensible Wizard Registration Manager Module
    xwtpdui.dll                6.1.7600.16385                   DUI
    xwtpw32.dll                6.1.7600.16385                   Win32
    zgmprxy.dll                6.1.7600.16385              Internal file used by the Internet Games
    zipfldr.dll                6.1.7600.16385               ZIP-


--------[   ]------------------------------------------------------------------------------------------------

     :
                         07.01.2014 22:23:01
                           08.01.2014 0:00:12
                                            08.01.2014 0:08:40
                                             523  (0 ., 0 , 8 , 43 )

      :
                                     05.01.2014 16:07:01
                            05.01.2014 16:06:20
                                        69729  (0 ., 19 , 22 , 9 )
                                       214346  (2 ., 11 , 32 , 26 )
                                  18056  (0 ., 5 , 0 , 56 )
                                 37451  (0 ., 10 , 24 , 11 )
                                       38
                                24.55%

      (" "):
                                              0

    :
                                                    


--------[   ]-----------------------------------------------------------------------------------------------

    ADMIN$                                    Admin                           C:\Windows
    C$                                                           C:\
    D$                                                           D:\
    G$                                                           G:\
    Lansweeper$                              Lansweeper Actions                        C:\Program Files\Lansweeper\Actions
    IPC$                            IPC            IPC                             


--------[  ]------------------------------------------------------------------------------------------------

       :
                                          
                                             -
                              
                      
      ./.                      0 / 42 .
                                  0 
                                     
                                       
                                30 
                                30 


--------[    ]----------------------------------------------------------------------------------------------

                                     -              -


--------[  ]------------------------------------------------------------------------------------------------

  [  ]

     :
                                         
                                               
                                                 /
                                               
                                     21
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [  ]

     :
                                         
                                               
                                                      
                                               
                                     0
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            


--------[   ]--------------------------------------------------------------------------------------------

  [ AMD FUEL ]

      :
                                             Members of this group can change AMD platform power controls within Catalyst Control Center to balance system performance with power usage.

  [ IIS_IUSRS ]

      :
                                              ,    IIS.

     :
      IUSR                                              

  [  ]

      :
                                               ,         

     :
                                           

  [  ]

      :
                                                   ,   ,     "",     .

     :
                                                   

  [   ]

      :
                                                 .

  [   ]

      :
                                                         .

  [    ]

      :
                                                         

  [   ]

      :
                                                        

  [  DCOM ]

      :
                                                 ,     DCOM   .

  [    ]

      :
                                                     ,         ,        .

  [    ]

      :
                                                  ,       

  [     ]

      :
                                                     

  [  ]

      :
                                                         

     :
                                           
                                       

  [  ]

      :
                                                 

  [    ]

      :
                                                      


--------[   ]-------------------------------------------------------------------------------------------

  [ None ]

      :
                                             Ordinary users

     :
                                           
                                                   


--------[  Windows ]-----------------------------------------------------------------------------------------------

  [ NVIDIA GeForce GTX 550 Ti ]

     :
                                      NVIDIA GeForce GTX 550 Ti
                                          GeForce GTX 550 Ti
       BIOS                                       Version 70.26.3a.0.1
                                      GeForce GTX 550 Ti
       DAC                                           Integrated RAMDAC
                                            11.11.2013
                                          9.18.13.3182 - nVIDIA Detonator 31.82
                                       NVIDIA
                                           1024 

     :
      nvd3dum                                           9.18.13.3182 - nVIDIA Detonator 31.82
      nvwgf2um                                          9.18.13.3182
      nvwgf2um                                          9.18.13.3182

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ NVIDIA GeForce GTX 550 Ti ]

     :
                                      NVIDIA GeForce GTX 550 Ti
                                          GeForce GTX 550 Ti
       BIOS                                       Version 70.26.3a.0.1
                                      GeForce GTX 550 Ti
       DAC                                           Integrated RAMDAC
                                            11.11.2013
                                          9.18.13.3182 - nVIDIA Detonator 31.82
                                       NVIDIA
                                           1024 

     :
      nvd3dum                                           9.18.13.3182 - nVIDIA Detonator 31.82
      nvwgf2um                                          9.18.13.3182
      nvwgf2um                                          9.18.13.3182

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates


--------[   ]---------------------------------------------------------------------------------------

  [ nVIDIA SLI ]

    nVIDIA SLI:
       SLI                                        


--------[  ]-----------------------------------------------------------------------------------------------------

  [ BenQ G922HDA ]

     :
                                             BenQ G922HDA
      ID                                        BNQ783C
                                                  BenQ G922HDA
                                             19" LCD (WXGA)
                                              44 / 2009
                                           WA900911019
      .                         41 cm x 23 cm (18.5")
                                       16:9
                                            30 - 63 
                                           50 - 76 
                           110 
                                  1366 x 768
                                                   2.20
        DPMS                        Active-Off

     :
      640 x 480                                         76 
      800 x 480                                         76 
      800 x 600                                         76 
      1024 x 600                                        76 
      1024 x 768                                        75 
      1280 x 720                                        76 
      1280 x 768                                        75 
      1366 x 768                                        75 

     :
                                                   BenQ Inc.
                                     http://www.benq.com/products/LCD
                                       http://www.benq.us/ServiceAndSupport
                                     http://www.aida64.com/driver-updates


--------[   ]------------------------------------------------------------------------------------------------

      :
                                     
                                              1366 x 768
                                            32 
                                       1
                                        96 dpi
        /                         36 / 36
                                     51
                                      60 
                                    C:\Users\\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg

      :
       -                             
                                              
                                      
                              
      ClearType                                         
             
                                
                                  
                                      
                                  
                                 
                                            
                                   
       /           
                                           
                              
                               
                            
                              
      Windows Aero                                      
       Windows Plus!                               


--------[  ]-----------------------------------------------------------------------------------------------

    \\.\DISPLAY1           (0,0)          (1366,768)


--------[  ]-------------------------------------------------------------------------------------------------

    640 x 480           8   59 Hz
    640 x 480           8   60 Hz
    640 x 480           8   75 Hz
    640 x 480          16   59 Hz
    640 x 480          16   60 Hz
    640 x 480          16   75 Hz
    640 x 480          32   59 Hz
    640 x 480          32   60 Hz
    640 x 480          32   75 Hz
    720 x 480           8   60 Hz
    720 x 480           8   60 Hz
    720 x 480           8   60 Hz
    720 x 480           8   75 Hz
    720 x 480           8   75 Hz
    720 x 480           8   75 Hz
    720 x 480          16   60 Hz
    720 x 480          16   60 Hz
    720 x 480          16   60 Hz
    720 x 480          16   75 Hz
    720 x 480          16   75 Hz
    720 x 480          16   75 Hz
    720 x 480          32   60 Hz
    720 x 480          32   60 Hz
    720 x 480          32   60 Hz
    720 x 480          32   75 Hz
    720 x 480          32   75 Hz
    720 x 480          32   75 Hz
    720 x 576           8   60 Hz
    720 x 576           8   60 Hz
    720 x 576           8   60 Hz
    720 x 576           8   75 Hz
    720 x 576           8   75 Hz
    720 x 576           8   75 Hz
    720 x 576          16   60 Hz
    720 x 576          16   60 Hz
    720 x 576          16   60 Hz
    720 x 576          16   75 Hz
    720 x 576          16   75 Hz
    720 x 576          16   75 Hz
    720 x 576          32   60 Hz
    720 x 576          32   60 Hz
    720 x 576          32   60 Hz
    720 x 576          32   75 Hz
    720 x 576          32   75 Hz
    720 x 576          32   75 Hz
    800 x 600           8   60 Hz
    800 x 600           8   75 Hz
    800 x 600          16   60 Hz
    800 x 600          16   75 Hz
    800 x 600          32   60 Hz
    800 x 600          32   75 Hz
    1024 x 768          8   60 Hz
    1024 x 768          8   75 Hz
    1024 x 768         16   60 Hz
    1024 x 768         16   75 Hz
    1024 x 768         32   60 Hz
    1024 x 768         32   75 Hz
    1280 x 720          8   60 Hz
    1280 x 720          8   75 Hz
    1280 x 720         16   60 Hz
    1280 x 720         16   75 Hz
    1280 x 720         32   60 Hz
    1280 x 720         32   75 Hz
    1280 x 768          8   60 Hz
    1280 x 768          8   60 Hz
    1280 x 768          8   60 Hz
    1280 x 768         16   60 Hz
    1280 x 768         16   60 Hz
    1280 x 768         16   60 Hz
    1280 x 768         32   60 Hz
    1280 x 768         32   60 Hz
    1280 x 768         32   60 Hz
    1360 x 768          8   60 Hz
    1360 x 768          8   60 Hz
    1360 x 768          8   60 Hz
    1360 x 768         16   60 Hz
    1360 x 768         16   60 Hz
    1360 x 768         16   60 Hz
    1360 x 768         32   60 Hz
    1360 x 768         32   60 Hz
    1360 x 768         32   60 Hz
    1366 x 768          8   60 Hz
    1366 x 768         16   60 Hz
    1366 x 768         32   60 Hz


--------[ OpenGL ]------------------------------------------------------------------------------------------------------

     OpenGL:
                                           NVIDIA Corporation
      Renderer                                          GeForce GTX 550 Ti/PCIe/SSE2/3DNOW!
                                                  4.4.0
                                    4.40 NVIDIA via Cg compiler
      OpenGL DLL                                        6.1.7600.16385(win7_rtm.090713-1255)
      Multitexture Texture Units                        4
      Occlusion Query Counter Bits                      32
      Sub-Pixel Precision                               8 
      Max Viewport Size                                 16384 x 16384
      Max Cube Map Texture Size                         16384 x 16384
      Max Rectangle Texture Size                        16384 x 16384
      Max 3D Texture Size                               2048 x 2048 x 2048
      Max Anisotropy                                    16
      Max Clipping Planes                               8
      Max Display-List Nesting Level                    64
      Max Draw Buffers                                  8
      Max Evaluator Order                               8
      Max General Register Combiners                    8
      Max Light Sources                                 8
      Max Pixel Map Table Size                          65536
      Min / Max Program Texel Offset                    -8 / 7
      Max Texture Array Layers                          2048
      Max Texture LOD Bias                              15
      Max Vertex Array Range Element Size               1048575

     OpenGL:
      OpenGL 1.1                                          (100%)
      OpenGL 1.2                                          (100%)
      OpenGL 1.3                                          (100%)
      OpenGL 1.4                                          (100%)
      OpenGL 1.5                                          (100%)
      OpenGL 2.0                                          (100%)
      OpenGL 2.1                                          (100%)
      OpenGL 3.0                                          (100%)
      OpenGL 3.1                                          (100%)
      OpenGL 3.2                                          (100%)
      OpenGL 3.3                                          (100%)
      OpenGL 4.0                                          (100%)
      OpenGL 4.1                                          (100%)

    Max Stack Depth:
      Attribute Stack                                   16
      Client Attribute Stack                            16
      Modelview Matrix Stack                            32
      Name Stack                                        128
      Projection Matrix Stack                           4
      Texture Matrix Stack                              10

    Draw Range Elements:
      Max Index Count                                   1048576
      Max Vertex Count                                  1048576

    Extended Lighting Parameters:
      Max Shininess                                     128
      Max Spot Exponent                                 128

    Transform Feedback:
      Max Interleaved Components                        128
      Max Separate Attributes                           4
      Max Separate Components                           4

    Framebuffer Object:
      Max Color Attachments                             8
      Max Render Buffer Size                            16384 x 16384

    Imaging:
      Max Color Matrix Stack Depth                      2
      Max Convolution Width / Height                    11 / 11

    Vertex Shader:
      Max Uniform Vertex Components                     4096
      Max Varying Floats                                124
      Max Vertex Texture Image Units                    32
      Max Combined Texture Image Units                  192

    Geometry Shader:
      Max Geometry Texture Units                        32
      Max Varying Components                            124
      Max Geometry Varying Components                   124
      Max Vertex Varying Components                     124
      Max Geometry Uniform Components                   2048
      Max Geometry Output Vertices                      1024
      Max Geometry Total Output Components              1024

    Fragment Shader:
      Max Uniform Fragment Components                   2048

    Vertex Program:
      Max Local Parameters                              1024
      Max Environment Parameters                        256
      Max Program Matrices                              8
      Max Program Matrix Stack Depth                    1
      Max Tracking Matrices                             8
      Max Tracking Matrix Stack Depth                   1
      Max Vertex Attributes                             16
      Max Instructions                                  16384
      Max Native Instructions                           16384
      Max Temporaries                                   4096
      Max Native Temporaries                            4096
      Max Parameters                                    1024
      Max Native Parameters                             1024
      Max Attributes                                    16
      Max Native Attributes                             16
      Max Address Registers                             2
      Max Native Address Registers                      2

    Fragment Program:
      Max Local Parameters                              512
      Max Environment Parameters                        256
      Max Texture Coordinates                           8
      Max Texture Image Units                           32
      Max Instructions                                  16384
      Max Native Instructions                           16384
      Max Temporaries                                   4096
      Max Native Temporaries                            4096
      Max Parameters                                    1024
      Max Native Parameters                             1024
      Max Attributes                                    16
      Max Native Attributes                             16
      Max Address Registers                             1
      Max Native Address Registers                      1
      Max ALU Instructions                              16384
      Max Native ALU Instructions                       16384
      Max Texture Instructions                          16384
      Max Native Texture Instructions                   16384
      Max Texture Indirections                          16384
      Max Native Texture Indirections                   16384
      Max Execution Instructions                        16777216
      Max Call Stack Depth                              32
      Max If Statement Depth                            64
      Max Loop Depth                                    64
      Max Loop Count                                    16777216

     OpenGL:
      GL_3DFX_multisample                                
      GL_3DFX_tbuffer                                    
      GL_3DFX_texture_compression_FXT1                   
      GL_3DL_direct_texture_access2                      
      GL_3Dlabs_multisample_transparency_id              
      GL_3Dlabs_multisample_transparency_range           
      GL_AMD_blend_minmax_factor                         
      GL_AMD_conservative_depth                          
      GL_AMD_debug_output                                
      GL_AMD_depth_clamp_separate                        
      GL_AMD_draw_buffers_blend                          
      GL_AMD_multi_draw_indirect                        
      GL_AMD_name_gen_delete                             
      GL_AMD_performance_monitor                         
      GL_AMD_sample_positions                            
      GL_AMD_seamless_cubemap_per_texture                
      GL_AMD_shader_stencil_export                       
      GL_AMD_shader_trace                                
      GL_AMD_texture_compression_dxt6                    
      GL_AMD_texture_compression_dxt7                    
      GL_AMD_texture_cube_map_array                      
      GL_AMD_texture_texture4                            
      GL_AMD_transform_feedback3_lines_triangles         
      GL_AMD_vertex_shader_tessellator                   
      GL_AMDX_debug_output                               
      GL_AMDX_name_gen_delete                            
      GL_AMDX_random_access_target                       
      GL_AMDX_vertex_shader_tessellator                  
      GL_APPLE_aux_depth_stencil                         
      GL_APPLE_client_storage                            
      GL_APPLE_element_array                             
      GL_APPLE_fence                                     
      GL_APPLE_float_pixels                              
      GL_APPLE_flush_buffer_range                        
      GL_APPLE_flush_render                              
      GL_APPLE_object_purgeable                          
      GL_APPLE_packed_pixel                              
      GL_APPLE_packed_pixels                             
      GL_APPLE_pixel_buffer                              
      GL_APPLE_rgb_422                                   
      GL_APPLE_specular_vector                           
      GL_APPLE_texture_range                             
      GL_APPLE_transform_hint                            
      GL_APPLE_vertex_array_object                       
      GL_APPLE_vertex_array_range                        
      GL_APPLE_vertex_program_evaluators                 
      GL_APPLE_ycbcr_422                                 
      GL_ARB_arrays_of_arrays                           
      GL_ARB_base_instance                              
      GL_ARB_blend_func_extended                        
      GL_ARB_buffer_storage                             
      GL_ARB_clear_buffer_object                        
      GL_ARB_clear_texture                              
      GL_ARB_color_buffer_float                         
      GL_ARB_compatibility                              
      GL_ARB_compressed_texture_pixel_storage           
      GL_ARB_compute_shader                             
      GL_ARB_compute_variable_group_size                
      GL_ARB_conservative_depth                         
      GL_ARB_copy_buffer                                
      GL_ARB_copy_image                                 
      GL_ARB_debug_output                               
      GL_ARB_depth_buffer_float                         
      GL_ARB_depth_clamp                                
      GL_ARB_depth_texture                              
      GL_ARB_draw_buffers                               
      GL_ARB_draw_buffers_blend                         
      GL_ARB_draw_elements_base_vertex                  
      GL_ARB_draw_indirect                              
      GL_ARB_draw_instanced                             
      GL_ARB_enhanced_layouts                           
      GL_ARB_ES2_compatibility                          
      GL_ARB_ES3_compatibility                          
      GL_ARB_explicit_attrib_location                   
      GL_ARB_explicit_uniform_location                  
      GL_ARB_fragment_coord_conventions                 
      GL_ARB_fragment_layer_viewport                    
      GL_ARB_fragment_program                           
      GL_ARB_fragment_program_shadow                    
      GL_ARB_fragment_shader                            
      GL_ARB_framebuffer_no_attachments                 
      GL_ARB_framebuffer_object                         
      GL_ARB_framebuffer_sRGB                           
      GL_ARB_geometry_shader4                           
      GL_ARB_get_program_binary                         
      GL_ARB_gpu_shader_fp64                            
      GL_ARB_gpu_shader5                                
      GL_ARB_half_float_pixel                           
      GL_ARB_half_float_vertex                          
      GL_ARB_imaging                                    
      GL_ARB_indirect_parameters                        
      GL_ARB_instanced_arrays                           
      GL_ARB_internalformat_query                       
      GL_ARB_internalformat_query2                      
      GL_ARB_invalidate_subdata                         
      GL_ARB_make_current_read                           
      GL_ARB_map_buffer_alignment                       
      GL_ARB_map_buffer_range                           
      GL_ARB_matrix_palette                              
      GL_ARB_multi_bind                                 
      GL_ARB_multi_draw_indirect                        
      GL_ARB_multisample                                
      GL_ARB_multitexture                               
      GL_ARB_occlusion_query                            
      GL_ARB_occlusion_query2                           
      GL_ARB_pixel_buffer_object                        
      GL_ARB_point_parameters                           
      GL_ARB_point_sprite                               
      GL_ARB_program_interface_query                    
      GL_ARB_provoking_vertex                           
      GL_ARB_query_buffer_object                        
      GL_ARB_robust_buffer_access_behavior              
      GL_ARB_robustness                                 
      GL_ARB_sample_shading                             
      GL_ARB_sampler_objects                            
      GL_ARB_seamless_cube_map                          
      GL_ARB_separate_shader_objects                    
      GL_ARB_shader_atomic_counters                     
      GL_ARB_shader_bit_encoding                        
      GL_ARB_shader_draw_parameters                     
      GL_ARB_shader_group_vote                          
      GL_ARB_shader_image_load_store                    
      GL_ARB_shader_image_size                          
      GL_ARB_shader_objects                             
      GL_ARB_shader_precision                           
      GL_ARB_shader_stencil_export                       
      GL_ARB_shader_storage_buffer_object               
      GL_ARB_shader_subroutine                          
      GL_ARB_shader_texture_lod                         
      GL_ARB_shading_language_100                       
      GL_ARB_shading_language_120                        
      GL_ARB_shading_language_420pack                   
      GL_ARB_shading_language_include                   
      GL_ARB_shading_language_packing                   
      GL_ARB_shadow                                     
      GL_ARB_shadow_ambient                              
      GL_ARB_sparse_texture                             
      GL_ARB_stencil_texturing                          
      GL_ARB_swap_buffers                                
      GL_ARB_sync                                       
      GL_ARB_tessellation_shader                        
      GL_ARB_texture_border_clamp                       
      GL_ARB_texture_buffer_object                      
      GL_ARB_texture_buffer_object_rgb32                
      GL_ARB_texture_buffer_range                       
      GL_ARB_texture_compression                        
      GL_ARB_texture_compression_bptc                   
      GL_ARB_texture_compression_rgtc                   
      GL_ARB_texture_cube_map                           
      GL_ARB_texture_cube_map_array                     
      GL_ARB_texture_env_add                            
      GL_ARB_texture_env_combine                        
      GL_ARB_texture_env_crossbar                       
      GL_ARB_texture_env_dot3                           
      GL_ARB_texture_float                              
      GL_ARB_texture_gather                             
      GL_ARB_texture_mirror_clamp_to_edge               
      GL_ARB_texture_mirrored_repeat                    
      GL_ARB_texture_multisample                        
      GL_ARB_texture_non_power_of_two                   
      GL_ARB_texture_query_levels                       
      GL_ARB_texture_query_lod                          
      GL_ARB_texture_rectangle                          
      GL_ARB_texture_rg                                 
      GL_ARB_texture_rgb10_a2ui                         
      GL_ARB_texture_snorm                               
      GL_ARB_texture_stencil8                           
      GL_ARB_texture_storage                            
      GL_ARB_texture_storage_multisample                
      GL_ARB_texture_swizzle                            
      GL_ARB_texture_view                               
      GL_ARB_timer_query                                
      GL_ARB_transform_feedback_instanced               
      GL_ARB_transform_feedback2                        
      GL_ARB_transform_feedback3                        
      GL_ARB_transpose_matrix                           
      GL_ARB_uber_buffers                                
      GL_ARB_uber_mem_image                              
      GL_ARB_uber_vertex_array                           
      GL_ARB_uniform_buffer_object                      
      GL_ARB_vertex_array_bgra                          
      GL_ARB_vertex_array_object                        
      GL_ARB_vertex_attrib_64bit                        
      GL_ARB_vertex_attrib_binding                      
      GL_ARB_vertex_blend                                
      GL_ARB_vertex_buffer_object                       
      GL_ARB_vertex_program                             
      GL_ARB_vertex_shader                              
      GL_ARB_vertex_type_10f_11f_11f_rev                
      GL_ARB_vertex_type_2_10_10_10_rev                 
      GL_ARB_viewport_array                             
      GL_ARB_window_pos                                 
      GL_ATI_array_rev_comps_in_4_bytes                  
      GL_ATI_blend_equation_separate                     
      GL_ATI_blend_weighted_minmax                       
      GL_ATI_draw_buffers                               
      GL_ATI_element_array                               
      GL_ATI_envmap_bumpmap                              
      GL_ATI_fragment_shader                             
      GL_ATI_lock_texture                                
      GL_ATI_map_object_buffer                           
      GL_ATI_meminfo                                     
      GL_ATI_pixel_format_float                          
      GL_ATI_pn_triangles                                
      GL_ATI_point_cull_mode                             
      GL_ATI_separate_stencil                            
      GL_ATI_shader_texture_lod                          
      GL_ATI_text_fragment_shader                        
      GL_ATI_texture_compression_3dc                     
      GL_ATI_texture_env_combine3                        
      GL_ATI_texture_float                              
      GL_ATI_texture_mirror_once                        
      GL_ATI_vertex_array_object                         
      GL_ATI_vertex_attrib_array_object                  
      GL_ATI_vertex_blend                                
      GL_ATI_vertex_shader                               
      GL_ATI_vertex_streams                              
      GL_ATIX_pn_triangles                               
      GL_ATIX_texture_env_combine3                       
      GL_ATIX_texture_env_route                          
      GL_ATIX_vertex_shader_output_point_size            
      GL_Autodesk_facet_normal                           
      GL_Autodesk_valid_back_buffer_hint                 
      GL_DIMD_YUV                                        
      GL_EXT_422_pixels                                  
      GL_EXT_abgr                                       
      GL_EXT_bgra                                       
      GL_EXT_bindable_uniform                           
      GL_EXT_blend_color                                
      GL_EXT_blend_equation_separate                    
      GL_EXT_blend_func_separate                        
      GL_EXT_blend_logic_op                              
      GL_EXT_blend_minmax                               
      GL_EXT_blend_subtract                             
      GL_EXT_Cg_shader                                  
      GL_EXT_clip_volume_hint                            
      GL_EXT_cmyka                                       
      GL_EXT_color_matrix                                
      GL_EXT_color_subtable                              
      GL_EXT_color_table                                 
      GL_EXT_compiled_vertex_array                      
      GL_EXT_convolution                                 
      GL_EXT_convolution_border_modes                    
      GL_EXT_coordinate_frame                            
      GL_EXT_copy_buffer                                 
      GL_EXT_copy_texture                                
      GL_EXT_cull_vertex                                 
      GL_EXT_depth_bounds_test                          
      GL_EXT_depth_buffer_float                          
      GL_EXT_direct_state_access                        
      GL_EXT_draw_buffers2                              
      GL_EXT_draw_indirect                               
      GL_EXT_draw_instanced                             
      GL_EXT_draw_range_elements                        
      GL_EXT_fog_coord                                  
      GL_EXT_fog_function                                
      GL_EXT_fog_offset                                  
      GL_EXT_fragment_lighting                           
      GL_EXT_framebuffer_blit                           
      GL_EXT_framebuffer_multisample                    
      GL_EXT_framebuffer_multisample_blit_scaled        
      GL_EXT_framebuffer_object                         
      GL_EXT_framebuffer_sRGB                           
      GL_EXT_generate_mipmap                             
      GL_EXT_geometry_shader4                           
      GL_EXT_gpu_program_parameters                     
      GL_EXT_gpu_shader_fp64                             
      GL_EXT_gpu_shader4                                
      GL_EXT_gpu_shader5                                 
      GL_EXT_histogram                                   
      GL_EXT_import_sync_object                         
      GL_EXT_index_array_formats                         
      GL_EXT_index_func                                  
      GL_EXT_index_material                              
      GL_EXT_index_texture                               
      GL_EXT_interlace                                   
      GL_EXT_light_texture                               
      GL_EXT_misc_attribute                              
      GL_EXT_multi_draw_arrays                          
      GL_EXT_multisample                                 
      GL_EXT_packed_depth_stencil                       
      GL_EXT_packed_float                               
      GL_EXT_packed_pixels                              
      GL_EXT_packed_pixels_12                            
      GL_EXT_paletted_texture                            
      GL_EXT_pixel_buffer_object                        
      GL_EXT_pixel_format                                
      GL_EXT_pixel_texture                               
      GL_EXT_pixel_transform                             
      GL_EXT_pixel_transform_color_table                 
      GL_EXT_point_parameters                           
      GL_EXT_polygon_offset                              
      GL_EXT_provoking_vertex                           
      GL_EXT_rescale_normal                             
      GL_EXT_scene_marker                                
      GL_EXT_secondary_color                            
      GL_EXT_separate_shader_objects                    
      GL_EXT_separate_specular_color                    
      GL_EXT_shader_atomic_counters                      
      GL_EXT_shader_image_load_store                    
      GL_EXT_shader_subroutine                           
      GL_EXT_shadow_funcs                               
      GL_EXT_shared_texture_palette                      
      GL_EXT_stencil_clear_tag                           
      GL_EXT_stencil_two_side                           
      GL_EXT_stencil_wrap                               
      GL_EXT_subtexture                                  
      GL_EXT_swap_control                                
      GL_EXT_tessellation_shader                         
      GL_EXT_texgen_reflection                           
      GL_EXT_texture                                     
      GL_EXT_texture_array                              
      GL_EXT_texture_border_clamp                        
      GL_EXT_texture_buffer_object                      
      GL_EXT_texture_buffer_object_rgb32                 
      GL_EXT_texture_color_table                         
      GL_EXT_texture_compression_bptc                    
      GL_EXT_texture_compression_dxt1                   
      GL_EXT_texture_compression_latc                   
      GL_EXT_texture_compression_rgtc                   
      GL_EXT_texture_compression_s3tc                   
      GL_EXT_texture_cube_map                           
      GL_EXT_texture_edge_clamp                         
      GL_EXT_texture_env                                 
      GL_EXT_texture_env_add                            
      GL_EXT_texture_env_combine                        
      GL_EXT_texture_env_dot3                           
      GL_EXT_texture_filter_anisotropic                 
      GL_EXT_texture_integer                            
      GL_EXT_texture_lod                                
      GL_EXT_texture_lod_bias                           
      GL_EXT_texture_mirror_clamp                       
      GL_EXT_texture_object                             
      GL_EXT_texture_perturb_normal                      
      GL_EXT_texture_rectangle                           
      GL_EXT_texture_shared_exponent                    
      GL_EXT_texture_snorm                               
      GL_EXT_texture_sRGB                               
      GL_EXT_texture_sRGB_decode                        
      GL_EXT_texture_storage                            
      GL_EXT_texture_swizzle                            
      GL_EXT_texture3D                                  
      GL_EXT_texture4D                                   
      GL_EXT_timer_query                                
      GL_EXT_transform_feedback                          
      GL_EXT_transform_feedback2                        
      GL_EXT_transform_feedback3                         
      GL_EXT_vertex_array                               
      GL_EXT_vertex_array_bgra                          
      GL_EXT_vertex_attrib_64bit                        
      GL_EXT_vertex_shader                               
      GL_EXT_vertex_weighting                            
      GL_EXTX_framebuffer_mixed_formats                 
      GL_EXTX_packed_depth_stencil                       
      GL_FGL_lock_texture                                
      GL_GL2_geometry_shader                             
      GL_GREMEDY_frame_terminator                        
      GL_GREMEDY_string_marker                           
      GL_HP_convolution_border_modes                     
      GL_HP_image_transform                              
      GL_HP_occlusion_test                               
      GL_HP_texture_lighting                             
      GL_I3D_argb                                        
      GL_I3D_color_clamp                                 
      GL_I3D_interlace_read                              
      GL_IBM_clip_check                                  
      GL_IBM_cull_vertex                                 
      GL_IBM_load_named_matrix                           
      GL_IBM_multi_draw_arrays                           
      GL_IBM_multimode_draw_arrays                       
      GL_IBM_occlusion_cull                              
      GL_IBM_pixel_filter_hint                           
      GL_IBM_rasterpos_clip                             
      GL_IBM_rescale_normal                              
      GL_IBM_static_data                                 
      GL_IBM_texture_clamp_nodraw                        
      GL_IBM_texture_mirrored_repeat                    
      GL_IBM_vertex_array_lists                          
      GL_IBM_YCbCr                                       
      GL_IMG_read_format                                 
      GL_IMG_texture_compression_pvrtc                   
      GL_IMG_texture_env_enhanced_fixed_function         
      GL_IMG_texture_format_BGRA8888                     
      GL_IMG_user_clip_planes                            
      GL_IMG_vertex_program                              
      GL_INGR_blend_func_separate                        
      GL_INGR_color_clamp                                
      GL_INGR_interlace_read                             
      GL_INGR_multiple_palette                           
      GL_INTEL_parallel_arrays                           
      GL_INTEL_texture_scissor                           
      GL_KHR_debug                                      
      GL_KTX_buffer_region                              
      GL_MESA_pack_invert                                
      GL_MESA_program_debug                              
      GL_MESA_resize_buffers                             
      GL_MESA_window_pos                                 
      GL_MESA_ycbcr_texture                              
      GL_MESAX_texture_stack                             
      GL_MTX_fragment_shader                             
      GL_MTX_precision_dpi                               
      GL_NV_bindless_multi_draw_indirect                
      GL_NV_blend_equation_advanced                     
      GL_NV_blend_square                                
      GL_NV_centroid_sample                              
      GL_NV_compute_program5                            
      GL_NV_conditional_render                          
      GL_NV_copy_depth_to_color                         
      GL_NV_copy_image                                  
      GL_NV_depth_buffer_float                          
      GL_NV_depth_clamp                                 
      GL_NV_depth_range_unclamped                        
      GL_NV_draw_texture                                
      GL_NV_ES1_1_compatibility                         
      GL_NV_evaluators                                   
      GL_NV_explicit_multisample                        
      GL_NV_fence                                       
      GL_NV_float_buffer                                
      GL_NV_fog_distance                                
      GL_NV_fragment_program                            
      GL_NV_fragment_program_option                     
      GL_NV_fragment_program2                           
      GL_NV_fragment_program4                            
      GL_NV_framebuffer_multisample_coverage            
      GL_NV_framebuffer_multisample_ex                   
      GL_NV_geometry_program4                            
      GL_NV_geometry_shader4                            
      GL_NV_gpu_program_fp64                            
      GL_NV_gpu_program4                                
      GL_NV_gpu_program4_1                              
      GL_NV_gpu_program5                                
      GL_NV_gpu_program5_mem_extended                   
      GL_NV_gpu_shader5                                 
      GL_NV_half_float                                  
      GL_NV_light_max_exponent                          
      GL_NV_multisample_coverage                        
      GL_NV_multisample_filter_hint                     
      GL_NV_occlusion_query                             
      GL_NV_packed_depth_stencil                        
      GL_NV_parameter_buffer_object                     
      GL_NV_parameter_buffer_object2                    
      GL_NV_path_rendering                              
      GL_NV_pixel_buffer_object                          
      GL_NV_pixel_data_range                            
      GL_NV_point_sprite                                
      GL_NV_present_video                                
      GL_NV_primitive_restart                           
      GL_NV_register_combiners                          
      GL_NV_register_combiners2                         
      GL_NV_shader_atomic_counters                      
      GL_NV_shader_atomic_float                         
      GL_NV_shader_buffer_load                          
      GL_NV_shader_buffer_store                          
      GL_NV_shader_storage_buffer_object                
      GL_NV_tessellation_program5                        
      GL_NV_texgen_emboss                                
      GL_NV_texgen_reflection                           
      GL_NV_texture_barrier                             
      GL_NV_texture_compression_latc                     
      GL_NV_texture_compression_vtc                     
      GL_NV_texture_env_combine4                        
      GL_NV_texture_expand_normal                       
      GL_NV_texture_multisample                         
      GL_NV_texture_rectangle                           
      GL_NV_texture_shader                              
      GL_NV_texture_shader2                             
      GL_NV_texture_shader3                             
      GL_NV_timer_query                                  
      GL_NV_transform_feedback                          
      GL_NV_transform_feedback2                         
      GL_NV_vdpau_interop                                
      GL_NV_vertex_array_range                          
      GL_NV_vertex_array_range2                         
      GL_NV_vertex_attrib_64bit                          
      GL_NV_vertex_attrib_integer_64bit                 
      GL_NV_vertex_buffer_unified_memory                
      GL_NV_vertex_program                              
      GL_NV_vertex_program1_1                           
      GL_NV_vertex_program2                             
      GL_NV_vertex_program2_option                      
      GL_NV_vertex_program3                             
      GL_NV_vertex_program4                              
      GL_NVX_conditional_render                         
      GL_NVX_flush_hold                                  
      GL_NVX_gpu_memory_info                            
      GL_NVX_instanced_arrays                            
      GL_NVX_ycrcb                                       
      GL_OES_blend_subtract                              
      GL_OES_byte_coordinates                            
      GL_OES_compressed_paletted_texture                 
      GL_OES_conditional_query                           
      GL_OES_depth24                                     
      GL_OES_draw_texture                                
      GL_OES_fixed_point                                 
      GL_OES_framebuffer_object                          
      GL_OES_mapbuffer                                   
      GL_OES_matrix_get                                  
      GL_OES_matrix_palette                              
      GL_OES_point_size_array                            
      GL_OES_point_sprite                                
      GL_OES_query_matrix                                
      GL_OES_read_format                                 
      GL_OES_rgb8_rgba8                                  
      GL_OES_single_precision                            
      GL_OES_texture_mirrored_repeat                     
      GL_OML_interlace                                   
      GL_OML_resample                                    
      GL_OML_subsample                                   
      GL_PGI_misc_hints                                  
      GL_PGI_vertex_hints                                
      GL_REND_screen_coordinates                         
      GL_S3_performance_analyzer                         
      GL_S3_s3tc                                        
      GL_SGI_color_matrix                                
      GL_SGI_color_table                                 
      GL_SGI_compiled_vertex_array                       
      GL_SGI_cull_vertex                                 
      GL_SGI_index_array_formats                         
      GL_SGI_index_func                                  
      GL_SGI_index_material                              
      GL_SGI_index_texture                               
      GL_SGI_make_current_read                           
      GL_SGI_texture_add_env                             
      GL_SGI_texture_color_table                         
      GL_SGI_texture_edge_clamp                          
      GL_SGI_texture_lod                                 
      GL_SGIS_color_range                                
      GL_SGIS_detail_texture                             
      GL_SGIS_fog_function                               
      GL_SGIS_generate_mipmap                           
      GL_SGIS_multisample                                
      GL_SGIS_multitexture                               
      GL_SGIS_pixel_texture                              
      GL_SGIS_point_line_texgen                          
      GL_SGIS_sharpen_texture                            
      GL_SGIS_texture_border_clamp                       
      GL_SGIS_texture_color_mask                         
      GL_SGIS_texture_edge_clamp                         
      GL_SGIS_texture_filter4                            
      GL_SGIS_texture_lod                               
      GL_SGIS_texture_select                             
      GL_SGIS_texture4D                                  
      GL_SGIX_async                                      
      GL_SGIX_async_histogram                            
      GL_SGIX_async_pixel                                
      GL_SGIX_blend_alpha_minmax                         
      GL_SGIX_clipmap                                    
      GL_SGIX_convolution_accuracy                       
      GL_SGIX_depth_pass_instrument                      
      GL_SGIX_depth_texture                             
      GL_SGIX_flush_raster                               
      GL_SGIX_fog_offset                                 
      GL_SGIX_fog_texture                                
      GL_SGIX_fragment_specular_lighting                 
      GL_SGIX_framezoom                                  
      GL_SGIX_instruments                                
      GL_SGIX_interlace                                  
      GL_SGIX_ir_instrument1                             
      GL_SGIX_list_priority                              
      GL_SGIX_pbuffer                                    
      GL_SGIX_pixel_texture                              
      GL_SGIX_pixel_texture_bits                         
      GL_SGIX_reference_plane                            
      GL_SGIX_resample                                   
      GL_SGIX_shadow                                    
      GL_SGIX_shadow_ambient                             
      GL_SGIX_sprite                                     
      GL_SGIX_subsample                                  
      GL_SGIX_tag_sample_buffer                          
      GL_SGIX_texture_add_env                            
      GL_SGIX_texture_coordinate_clamp                   
      GL_SGIX_texture_lod_bias                           
      GL_SGIX_texture_multi_buffer                       
      GL_SGIX_texture_range                              
      GL_SGIX_texture_scale_bias                         
      GL_SGIX_vertex_preclip                             
      GL_SGIX_vertex_preclip_hint                        
      GL_SGIX_ycrcb                                      
      GL_SGIX_ycrcb_subsample                            
      GL_SUN_convolution_border_modes                    
      GL_SUN_global_alpha                                
      GL_SUN_mesh_array                                  
      GL_SUN_multi_draw_arrays                           
      GL_SUN_read_video_pixels                           
      GL_SUN_slice_accum                                
      GL_SUN_triangle_list                               
      GL_SUN_vertex                                      
      GL_SUNX_constant_data                              
      GL_WGL_ARB_extensions_string                       
      GL_WGL_EXT_extensions_string                       
      GL_WGL_EXT_swap_control                            
      GL_WIN_phong_shading                               
      GL_WIN_specular_fog                                
      GL_WIN_swap_hint                                  
      GLU_EXT_nurbs_tessellator                          
      GLU_EXT_object_space_tess                          
      GLU_SGI_filter4_parameters                         
      GLX_ARB_create_context                             
      GLX_ARB_fbconfig_float                             
      GLX_ARB_framebuffer_sRGB                           
      GLX_ARB_get_proc_address                           
      GLX_ARB_multisample                                
      GLX_EXT_fbconfig_packed_float                      
      GLX_EXT_framebuffer_sRGB                           
      GLX_EXT_import_context                             
      GLX_EXT_scene_marker                               
      GLX_EXT_texture_from_pixmap                        
      GLX_EXT_visual_info                                
      GLX_EXT_visual_rating                              
      GLX_MESA_agp_offset                                
      GLX_MESA_copy_sub_buffer                           
      GLX_MESA_pixmap_colormap                           
      GLX_MESA_release_buffers                           
      GLX_MESA_set_3dfx_mode                             
      GLX_NV_present_video                               
      GLX_NV_swap_group                                  
      GLX_NV_video_output                                
      GLX_OML_swap_method                                
      GLX_OML_sync_control                               
      GLX_SGI_cushion                                    
      GLX_SGI_make_current_read                          
      GLX_SGI_swap_control                               
      GLX_SGI_video_sync                                 
      GLX_SGIS_blended_overlay                           
      GLX_SGIS_color_range                               
      GLX_SGIS_multisample                               
      GLX_SGIX_dm_buffer                                 
      GLX_SGIX_fbconfig                                  
      GLX_SGIX_hyperpipe                                 
      GLX_SGIX_pbuffer                                   
      GLX_SGIX_swap_barrier                              
      GLX_SGIX_swap_group                                
      GLX_SGIX_video_resize                              
      GLX_SGIX_video_source                              
      GLX_SGIX_visual_select_group                       
      GLX_SUN_get_transparent_index                      
      GLX_SUN_video_resize                               
      WGL_3DFX_gamma_control                             
      WGL_3DFX_multisample                               
      WGL_3DL_stereo_control                             
      WGL_AMD_gpu_association                            
      WGL_AMDX_gpu_association                           
      WGL_ARB_buffer_region                             
      WGL_ARB_create_context                            
      WGL_ARB_create_context_profile                    
      WGL_ARB_create_context_robustness                 
      WGL_ARB_extensions_string                         
      WGL_ARB_framebuffer_sRGB                           
      WGL_ARB_make_current_read                         
      WGL_ARB_multisample                               
      WGL_ARB_pbuffer                                   
      WGL_ARB_pixel_format                              
      WGL_ARB_pixel_format_float                        
      WGL_ARB_render_texture                            
      WGL_ATI_pbuffer_memory_hint                        
      WGL_ATI_pixel_format_float                        
      WGL_ATI_render_texture_rectangle                   
      WGL_EXT_buffer_region                              
      WGL_EXT_create_context_es_profile                 
      WGL_EXT_create_context_es2_profile                
      WGL_EXT_depth_float                                
      WGL_EXT_display_color_table                        
      WGL_EXT_extensions_string                         
      WGL_EXT_framebuffer_sRGB                          
      WGL_EXT_framebuffer_sRGBWGL_ARB_create_context     
      WGL_EXT_gamma_control                              
      WGL_EXT_make_current_read                          
      WGL_EXT_multisample                                
      WGL_EXT_pbuffer                                    
      WGL_EXT_pixel_format                               
      WGL_EXT_pixel_format_packed_float                 
      WGL_EXT_render_texture                             
      WGL_EXT_swap_control                              
      WGL_EXT_swap_control_tear                         
      WGL_EXT_swap_interval                              
      WGL_I3D_digital_video_control                      
      WGL_I3D_gamma                                      
      WGL_I3D_genlock                                    
      WGL_I3D_image_buffer                               
      WGL_I3D_swap_frame_lock                            
      WGL_I3D_swap_frame_usage                           
      WGL_MTX_video_preview                              
      WGL_NV_copy_image                                  
      WGL_NV_delay_before_swap                          
      WGL_NV_DX_interop                                 
      WGL_NV_DX_interop2                                
      WGL_NV_float_buffer                               
      WGL_NV_gpu_affinity                                
      WGL_NV_multisample_coverage                       
      WGL_NV_present_video                               
      WGL_NV_render_depth_texture                       
      WGL_NV_render_texture_rectangle                   
      WGL_NV_swap_group                                  
      WGL_NV_vertex_array_range                          
      WGL_NV_video_output                                
      WGL_NVX_DX_interop                                
      WGL_OML_sync_control                               

       :
      RGB DXT1                                          
      RGBA DXT1                                          
      RGBA DXT3                                         
      RGBA DXT5                                         
      RGB FXT1                                           
      RGBA FXT1                                          
      3Dc                                                

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates


--------[ GPGPU ]-------------------------------------------------------------------------------------------------------

  [ CUDA: GeForce GTX 550 Ti ]

     :
                                           GeForce GTX 550 Ti
                                                 1800 
      /                             4 / 128
      Max Threads Per Block                             1024
      Max Registers Per Block                           32768
      Warp Size                                         32 threads
      Max Block Size                                    1024 x 1024 x 64
      Max Grid Size                                     65535 x 65535 x 65535
      Compute Capability                                2.1
      CUDA DLL                                          nvcuda.dll (8.17.13.3182 - nVIDIA Detonator 31.82)

     :
      Total Memory                                      1024 
      Total Constant Memory                             64 
      Max Shared Memory Per Block                       48 
      Max Memory Pitch                                  2147483647 
      Texture Alignment                                 512 

     :
      32-bit Floating-Point Atomic Addition             
      32-bit Integer Atomic Operations                  
      64-bit Integer Atomic Operations                  
      Concurrent Memory Copy & Execute                  
      Double-Precision Floating-Point                   
      Warp Vote Functions                               
      __ballot()                                        
      __syncthreads_and()                               
      __syncthreads_count()                             
      __syncthreads_or()                                
      __threadfence_system()                            

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ Direct3D: NVIDIA GeForce GTX 550 Ti ]

     :
                                           NVIDIA GeForce GTX 550 Ti
                                             nvd3dum.dll
                                          9.18.13.3182 - nVIDIA Detonator 31.82
      Shader Model                                      SM 5.0
      Max Threads                                       1024
      Multiple UAV Access                               8 UAVs
      Thread Dispatch                                   3D
      Thread Local Storage                              32 

     :
      Append/Consume Buffers                            
      Atomic Operations                                 
      Double-Precision Floating-Point                   
      Gather4                                           
      Indirect Compute Dispatch                         

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ OpenCL: GeForce GTX 550 Ti ]

    OpenCL Properties:
      Platform Name                                     NVIDIA CUDA
      Platform Vendor                                   NVIDIA Corporation
      Platform Version                                  OpenCL 1.1 CUDA 6.0.1
      Platform Profile                                  Full

     :
                                           GeForce GTX 550 Ti
                                            
      Device Vendor                                     NVIDIA Corporation
      Device Version                                    OpenCL 1.1 CUDA
      Device Profile                                    Full
                                                 1800 
      Multiprocessors                                   4
      Max 2D Image Size                                 32768 x 32768
      Max 3D Image Size                                 2048 x 2048 x 2048
      Max Samplers                                      16
      Max Work-Item Size                                1024 x 1024 x 64
      Max Work-Group Size                               1024
      Max Argument Size                                 4352 
      Max Constant Buffer Size                          64 
      Max Constant Arguments                            9
      Profiling Timer Resolution                        1000 ns
      OpenCL DLL                                        opencl.dll (1.0.0)

     :
      Global Memory                                     1024 
      Global Memory Cache                               64   (Read/Write, 128-byte line)
      Local Memory                                      48 
      Memory Base Address Alignment                     4096 
      Min Data Type Alignment                           128 

     :
      Command-Queue Out Of Order Execution              
      Command-Queue Profiling                           
      Compiler                                          
                                          
      Images                                            
      Kernel Execution                                  
      Native Kernel Execution                            

    Device Extensions:
      cl_amd_d3d10_interop                               
      cl_amd_d3d9_interop                                
      cl_amd_device_attribute_query                      
      cl_amd_fp64                                        
      cl_amd_media_ops                                   
      cl_amd_printf                                      
      cl_khr_3d_image_writes                             
      cl_khr_byte_addressable_store                     
      cl_khr_d3d10_sharing                              
      cl_khr_fp16                                        
      cl_khr_fp64                                       
      cl_khr_gl_sharing                                 
      cl_khr_global_int32_base_atomics                  
      cl_khr_global_int32_extended_atomics              
      cl_khr_icd                                        
      cl_khr_int64_base_atomics                          
      cl_khr_int64_extended_atomics                      
      cl_khr_local_int32_base_atomics                   
      cl_khr_local_int32_extended_atomics               
      cl_khr_select_fprounding_mode                      
      cl_nv_compiler_options                            
      cl_nv_d3d10_sharing                               
      cl_nv_d3d11_sharing                               
      cl_nv_d3d9_sharing                                
      cl_nv_device_attribute_query                      
      cl_nv_pragma_unroll                               

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates


--------[  ]------------------------------------------------------------------------------------------------------

    @Arial Unicode MS                         Swiss                               14 x 43   40 %
    @Arial Unicode MS                         Swiss                             14 x 43   40 %
    @Arial Unicode MS                         Swiss                            14 x 43   40 %
    @Arial Unicode MS                         Swiss                              14 x 43   40 %
    @Arial Unicode MS                         Swiss                               14 x 43   40 %
    @Arial Unicode MS                         Swiss                                  14 x 43   40 %
    @Arial Unicode MS                         Swiss                          14 x 43   40 %
    @Arial Unicode MS                         Swiss                (2312)        14 x 43   40 %
    @Arial Unicode MS                         Swiss                (BIG5)        14 x 43   40 %
    @Arial Unicode MS                         Swiss                                14 x 43   40 %
    @Arial Unicode MS                         Swiss                               14 x 43   40 %
    @Arial Unicode MS                         Swiss                (Johab)         14 x 43   40 %
    @Arial Unicode MS                         Swiss                                14 x 43   40 %
    @Arial Unicode MS                         Swiss                  14 x 43   40 %
    @Arial Unicode MS                         Swiss                               14 x 43   40 %
    @Batang                                   Roman       Regular                      16 x 32   40 %
    @Batang                                   Roman       Regular                       16 x 32   40 %
    @Batang                                   Roman       Regular                        16 x 32   40 %
    @Batang                                   Roman       Regular                   16 x 32   40 %
    @Batang                                   Roman       Regular                        16 x 32   40 %
    @Batang                                   Roman       Regular                         16 x 32   40 %
    @Batang                                   Roman       Regular           16 x 32   40 %
    @BatangChe                                Modern      Regular                      16 x 32   40 %
    @BatangChe                                Modern      Regular                       16 x 32   40 %
    @BatangChe                                Modern      Regular                        16 x 32   40 %
    @BatangChe                                Modern      Regular                   16 x 32   40 %
    @BatangChe                                Modern      Regular                        16 x 32   40 %
    @BatangChe                                Modern      Regular                         16 x 32   40 %
    @BatangChe                                Modern      Regular           16 x 32   40 %
    @DFKai-SB                                 Script      Regular                        16 x 32   40 %
    @DFKai-SB                                 Script      Regular         (BIG5)        16 x 32   40 %
    @Dotum                                    Swiss       Regular                      16 x 32   40 %
    @Dotum                                    Swiss       Regular                       16 x 32   40 %
    @Dotum                                    Swiss       Regular                        16 x 32   40 %
    @Dotum                                    Swiss       Regular                   16 x 32   40 %
    @Dotum                                    Swiss       Regular                        16 x 32   40 %
    @Dotum                                    Swiss       Regular                         16 x 32   40 %
    @Dotum                                    Swiss       Regular           16 x 32   40 %
    @DotumChe                                 Modern      Regular                      16 x 32   40 %
    @DotumChe                                 Modern      Regular                       16 x 32   40 %
    @DotumChe                                 Modern      Regular                        16 x 32   40 %
    @DotumChe                                 Modern      Regular                   16 x 32   40 %
    @DotumChe                                 Modern      Regular                        16 x 32   40 %
    @DotumChe                                 Modern      Regular                         16 x 32   40 %
    @DotumChe                                 Modern      Regular           16 x 32   40 %
    @FangSong                                 Modern                              16 x 32   40 %
    @FangSong                                 Modern               (2312)        16 x 32   40 %
    @Gulim                                    Swiss       Regular                      16 x 32   40 %
    @Gulim                                    Swiss       Regular                       16 x 32   40 %
    @Gulim                                    Swiss       Regular                        16 x 32   40 %
    @Gulim                                    Swiss       Regular                   16 x 32   40 %
    @Gulim                                    Swiss       Regular                        16 x 32   40 %
    @Gulim                                    Swiss       Regular                         16 x 32   40 %
    @Gulim                                    Swiss       Regular           16 x 32   40 %
    @GulimChe                                 Modern      Regular                      16 x 32   40 %
    @GulimChe                                 Modern      Regular                       16 x 32   40 %
    @GulimChe                                 Modern      Regular                        16 x 32   40 %
    @GulimChe                                 Modern      Regular                   16 x 32   40 %
    @GulimChe                                 Modern      Regular                        16 x 32   40 %
    @GulimChe                                 Modern      Regular                         16 x 32   40 %
    @GulimChe                                 Modern      Regular           16 x 32   40 %
    @Gungsuh                                  Roman       Regular                      16 x 32   40 %
    @Gungsuh                                  Roman       Regular                       16 x 32   40 %
    @Gungsuh                                  Roman       Regular                        16 x 32   40 %
    @Gungsuh                                  Roman       Regular                   16 x 32   40 %
    @Gungsuh                                  Roman       Regular                        16 x 32   40 %
    @Gungsuh                                  Roman       Regular                         16 x 32   40 %
    @Gungsuh                                  Roman       Regular           16 x 32   40 %
    @GungsuhChe                               Modern      Regular                      16 x 32   40 %
    @GungsuhChe                               Modern      Regular                       16 x 32   40 %
    @GungsuhChe                               Modern      Regular                        16 x 32   40 %
    @GungsuhChe                               Modern      Regular                   16 x 32   40 %
    @GungsuhChe                               Modern      Regular                        16 x 32   40 %
    @GungsuhChe                               Modern      Regular                         16 x 32   40 %
    @GungsuhChe                               Modern      Regular           16 x 32   40 %
    @KaiTi                                    Modern                              16 x 32   40 %
    @KaiTi                                    Modern               (2312)        16 x 32   40 %
    @Malgun Gothic                            Swiss       Regular                        15 x 43   40 %
    @Malgun Gothic                            Swiss       Regular                         15 x 43   40 %
    @Meiryo UI                                Swiss                             17 x 41   40 %
    @Meiryo UI                                Swiss                              17 x 41   40 %
    @Meiryo UI                                Swiss                               17 x 41   40 %
    @Meiryo UI                                Swiss                          17 x 41   40 %
    @Meiryo UI                                Swiss                               17 x 41   40 %
    @Meiryo UI                                Swiss                  17 x 41   40 %
    @Meiryo UI                                Swiss                               17 x 41   40 %
    @Meiryo                                   Swiss                             31 x 48   40 %
    @Meiryo                                   Swiss                              31 x 48   40 %
    @Meiryo                                   Swiss                               31 x 48   40 %
    @Meiryo                                   Swiss                          31 x 48   40 %
    @Meiryo                                   Swiss                               31 x 48   40 %
    @Meiryo                                   Swiss                  31 x 48   40 %
    @Meiryo                                   Swiss                               31 x 48   40 %
    @Microsoft JhengHei                       Swiss                              15 x 43   40 %
    @Microsoft JhengHei                       Swiss                               15 x 43   40 %
    @Microsoft JhengHei                       Swiss                (BIG5)        15 x 43   40 %
    @Microsoft YaHei                          Swiss                              15 x 42   40 %
    @Microsoft YaHei                          Swiss                               15 x 42   40 %
    @Microsoft YaHei                          Swiss                          15 x 42   40 %
    @Microsoft YaHei                          Swiss                (2312)        15 x 42   40 %
    @Microsoft YaHei                          Swiss                               15 x 42   40 %
    @Microsoft YaHei                          Swiss                  15 x 42   40 %
    @MingLiU                                  Modern      Regular                        16 x 32   40 %
    @MingLiU                                  Modern      Regular         (BIG5)        16 x 32   40 %
    @MingLiU_HKSCS                            Roman       Regular                        16 x 32   40 %
    @MingLiU_HKSCS                            Roman       Regular         (BIG5)        16 x 32   40 %
    @MingLiU_HKSCS-ExtB                       Roman       Regular                        16 x 32   40 %
    @MingLiU_HKSCS-ExtB                       Roman       Regular         (BIG5)        16 x 32   40 %
    @MingLiU-ExtB                             Roman       Regular                        16 x 32   40 %
    @MingLiU-ExtB                             Roman       Regular         (BIG5)        16 x 32   40 %
    @MS Gothic                                Modern      Regular                      16 x 32   40 %
    @MS Gothic                                Modern      Regular                       16 x 32   40 %
    @MS Gothic                                Modern      Regular                        16 x 32   40 %
    @MS Gothic                                Modern      Regular                   16 x 32   40 %
    @MS Gothic                                Modern      Regular                        16 x 32   40 %
    @MS Gothic                                Modern      Regular           16 x 32   40 %
    @MS Gothic                                Modern      Regular                        16 x 32   40 %
    @MS Mincho                                Modern      Regular                      16 x 32   40 %
    @MS Mincho                                Modern      Regular                       16 x 32   40 %
    @MS Mincho                                Modern      Regular                        16 x 32   40 %
    @MS Mincho                                Modern      Regular                   16 x 32   40 %
    @MS Mincho                                Modern      Regular                        16 x 32   40 %
    @MS Mincho                                Modern      Regular           16 x 32   40 %
    @MS Mincho                                Modern      Regular                        16 x 32   40 %
    @MS PGothic                               Swiss       Regular                      13 x 32   40 %
    @MS PGothic                               Swiss       Regular                       13 x 32   40 %
    @MS PGothic                               Swiss       Regular                        13 x 32   40 %
    @MS PGothic                               Swiss       Regular                   13 x 32   40 %
    @MS PGothic                               Swiss       Regular                        13 x 32   40 %
    @MS PGothic                               Swiss       Regular           13 x 32   40 %
    @MS PGothic                               Swiss       Regular                        13 x 32   40 %
    @MS PMincho                               Roman       Regular                      13 x 32   40 %
    @MS PMincho                               Roman       Regular                       13 x 32   40 %
    @MS PMincho                               Roman       Regular                        13 x 32   40 %
    @MS PMincho                               Roman       Regular                   13 x 32   40 %
    @MS PMincho                               Roman       Regular                        13 x 32   40 %
    @MS PMincho                               Roman       Regular           13 x 32   40 %
    @MS PMincho                               Roman       Regular                        13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                      13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                       13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                        13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                   13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                        13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular           13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                        13 x 32   40 %
    @NSimSun                                  Modern      Regular                        16 x 32   40 %
    @NSimSun                                  Modern      Regular         (2312)        16 x 32   40 %
    @PMingLiU                                 Roman       Regular                        16 x 32   40 %
    @PMingLiU                                 Roman       Regular         (BIG5)        16 x 32   40 %
    @PMingLiU-ExtB                            Roman       Regular                        16 x 32   40 %
    @PMingLiU-ExtB                            Roman       Regular         (BIG5)        16 x 32   40 %
    @SimHei                                   Modern                              16 x 32   40 %
    @SimHei                                   Modern               (2312)        16 x 32   40 %
    @SimSun                                   Special     Regular                        16 x 32   40 %
    @SimSun                                   Special     Regular         (2312)        16 x 32   40 %
    @SimSun-ExtB                              Modern                              16 x 32   40 %
    @SimSun-ExtB                              Modern               (2312)        16 x 32   40 %
    Agency FB                                 Swiss                            11 x 37   70 %
    Aharoni                                   Special                             15 x 32   70 %
    Algerian                                  Decorative  Regular                        17 x 36   40 %
    Andalus                                   Roman       Regular                        15 x 49   40 %
    Andalus                                   Roman       Regular                        15 x 49   40 %
    Angsana New                               Roman                                8 x 43   40 %
    Angsana New                               Roman                                 8 x 43   40 %
    AngsanaUPC                                Roman                                8 x 43   40 %
    AngsanaUPC                                Roman                                 8 x 43   40 %
    Aparajita                                 Swiss       Regular                        16 x 38   40 %
    Arabic Typesetting                        Script                               9 x 36   40 %
    Arabic Typesetting                        Script                             9 x 36   40 %
    Arabic Typesetting                        Script                               9 x 36   40 %
    Arabic Typesetting                        Script                               9 x 36   40 %
    Arabic Typesetting                        Script                  9 x 36   40 %
    Arial Black                               Swiss                             18 x 45   90 %
    Arial Black                               Swiss                              18 x 45   90 %
    Arial Black                               Swiss                               18 x 45   90 %
    Arial Black                               Swiss                          18 x 45   90 %
    Arial Black                               Swiss                               18 x 45   90 %
    Arial Black                               Swiss                  18 x 45   90 %
    Arial Narrow                              Swiss                             12 x 36   40 %
    Arial Narrow                              Swiss                              12 x 36   40 %
    Arial Narrow                              Swiss                               12 x 36   40 %
    Arial Narrow                              Swiss                          12 x 36   40 %
    Arial Narrow                              Swiss                               12 x 36   40 %
    Arial Narrow                              Swiss                  12 x 36   40 %
    Arial Rounded MT Bold                     Swiss                               15 x 37   40 %
    Arial Unicode MS                          Swiss                               14 x 43   40 %
    Arial Unicode MS                          Swiss                             14 x 43   40 %
    Arial Unicode MS                          Swiss                            14 x 43   40 %
    Arial Unicode MS                          Swiss                              14 x 43   40 %
    Arial Unicode MS                          Swiss                               14 x 43   40 %
    Arial Unicode MS                          Swiss                                  14 x 43   40 %
    Arial Unicode MS                          Swiss                          14 x 43   40 %
    Arial Unicode MS                          Swiss                (2312)        14 x 43   40 %
    Arial Unicode MS                          Swiss                (BIG5)        14 x 43   40 %
    Arial Unicode MS                          Swiss                                14 x 43   40 %
    Arial Unicode MS                          Swiss                               14 x 43   40 %
    Arial Unicode MS                          Swiss                (Johab)         14 x 43   40 %
    Arial Unicode MS                          Swiss                                14 x 43   40 %
    Arial Unicode MS                          Swiss                  14 x 43   40 %
    Arial Unicode MS                          Swiss                               14 x 43   40 %
    Arial                                     Swiss                               14 x 36   40 %
    Arial                                     Swiss                             14 x 36   40 %
    Arial                                     Swiss                            14 x 36   40 %
    Arial                                     Swiss                              14 x 36   40 %
    Arial                                     Swiss                               14 x 36   40 %
    Arial                                     Swiss                                  14 x 36   40 %
    Arial                                     Swiss                          14 x 36   40 %
    Arial                                     Swiss                               14 x 36   40 %
    Arial                                     Swiss                  14 x 36   40 %
    Baskerville Old Face                      Roman                               13 x 37   40 %
    Batang                                    Roman       Regular                      16 x 32   40 %
    Batang                                    Roman       Regular                       16 x 32   40 %
    Batang                                    Roman       Regular                        16 x 32   40 %
    Batang                                    Roman       Regular                   16 x 32   40 %
    Batang                                    Roman       Regular                        16 x 32   40 %
    Batang                                    Roman       Regular                         16 x 32   40 %
    Batang                                    Roman       Regular           16 x 32   40 %
    BatangChe                                 Modern      Regular                      16 x 32   40 %
    BatangChe                                 Modern      Regular                       16 x 32   40 %
    BatangChe                                 Modern      Regular                        16 x 32   40 %
    BatangChe                                 Modern      Regular                   16 x 32   40 %
    BatangChe                                 Modern      Regular                        16 x 32   40 %
    BatangChe                                 Modern      Regular                         16 x 32   40 %
    BatangChe                                 Modern      Regular           16 x 32   40 %
    Bauhaus 93                                Decorative                          14 x 36   40 %
    Bell MT                                   Roman                               13 x 35   40 %
    Berlin Sans FB Demi                       Swiss                            14 x 36   70 %
    Berlin Sans FB                            Swiss                            15 x 36   70 %
    Bernard MT Condensed                      Roman                               12 x 38   40 %
    Blackadder ITC                            Decorative                          10 x 41   40 %
    Bodoni MT Black                           Roman                                17 x 37   90 %
    Bodoni MT Condensed                       Roman                            11 x 38   70 %
    Bodoni MT Poster Compressed               Roman                                8 x 37   30 %
    Bodoni MT Poster Compressed               Roman                                8 x 37   30 %
    Bodoni MT                                 Roman                            13 x 38   70 %
    Book Antiqua                              Roman                          15 x 38   70 %
    Book Antiqua                              Roman                           15 x 38   70 %
    Book Antiqua                              Roman                            15 x 38   70 %
    Book Antiqua                              Roman                       15 x 38   70 %
    Book Antiqua                              Roman                            15 x 38   70 %
    Book Antiqua                              Roman               15 x 38   70 %
    Bookman Old Style                         Roman                             16 x 36   30 %
    Bookman Old Style                         Roman                              16 x 36   30 %
    Bookman Old Style                         Roman                               16 x 36   30 %
    Bookman Old Style                         Roman                          16 x 36   30 %
    Bookman Old Style                         Roman                               16 x 36   30 %
    Bookman Old Style                         Roman                  16 x 36   30 %
    Bookshelf Symbol 7                        Special     Regular                      21 x 32   40 %
    Bradley Hand ITC                          Script                              13 x 40   40 %
    Britannic Bold                            Swiss                               14 x 35   40 %
    Broadway                                  Decorative                          17 x 36   40 %
    Browallia New                             Swiss       Regular                         9 x 40   40 %
    Browallia New                             Swiss       Regular                          9 x 40   40 %
    BrowalliaUPC                              Swiss       Regular                         9 x 40   40 %
    BrowalliaUPC                              Swiss       Regular                          9 x 40   40 %
    Brush Script MT                           Script                               10 x 39   40 %
    Calibri                                   Swiss       Regular                      17 x 39   40 %
    Calibri                                   Swiss       Regular                     17 x 39   40 %
    Calibri                                   Swiss       Regular                       17 x 39   40 %
    Calibri                                   Swiss       Regular                        17 x 39   40 %
    Calibri                                   Swiss       Regular                   17 x 39   40 %
    Calibri                                   Swiss       Regular                        17 x 39   40 %
    Calibri                                   Swiss       Regular           17 x 39   40 %
    Californian FB                            Roman                            14 x 37   70 %
    Calisto MT                                Roman                               13 x 37   40 %
    Cambria Math                              Roman       Regular                      20 x 179   40 %
    Cambria Math                              Roman       Regular                     20 x 179   40 %
    Cambria Math                              Roman       Regular                       20 x 179   40 %
    Cambria Math                              Roman       Regular                        20 x 179   40 %
    Cambria Math                              Roman       Regular                   20 x 179   40 %
    Cambria Math                              Roman       Regular                        20 x 179   40 %
    Cambria Math                              Roman       Regular           20 x 179   40 %
    Cambria                                   Roman       Regular                      20 x 40   40 %
    Cambria                                   Roman       Regular                     20 x 40   40 %
    Cambria                                   Roman       Regular                       20 x 40   40 %
    Cambria                                   Roman       Regular                        20 x 40   40 %
    Cambria                                   Roman       Regular                   20 x 40   40 %
    Cambria                                   Roman       Regular                        20 x 40   40 %
    Cambria                                   Roman       Regular           20 x 40   40 %
    Candara                                   Swiss       Regular                      17 x 39   40 %
    Candara                                   Swiss       Regular                     17 x 39   40 %
    Candara                                   Swiss       Regular                       17 x 39   40 %
    Candara                                   Swiss       Regular                        17 x 39   40 %
    Candara                                   Swiss       Regular                   17 x 39   40 %
    Candara                                   Swiss       Regular                        17 x 39   40 %
    Candara                                   Swiss       Regular           17 x 39   40 %
    Castellar                                 Roman                               21 x 39   40 %
    Centaur                                   Roman                               12 x 36   40 %
    Century Gothic                            Swiss                             16 x 38   40 %
    Century Gothic                            Swiss                              16 x 38   40 %
    Century Gothic                            Swiss                               16 x 38   40 %
    Century Gothic                            Swiss                          16 x 38   40 %
    Century Gothic                            Swiss                               16 x 38   40 %
    Century Gothic                            Swiss                  16 x 38   40 %
    Century Schoolbook                        Roman                             15 x 38   40 %
    Century Schoolbook                        Roman                              15 x 38   40 %
    Century Schoolbook                        Roman                               15 x 38   40 %
    Century Schoolbook                        Roman                          15 x 38   40 %
    Century Schoolbook                        Roman                               15 x 38   40 %
    Century Schoolbook                        Roman                  15 x 38   40 %
    Century                                   Roman                             15 x 38   40 %
    Century                                   Roman                              15 x 38   40 %
    Century                                   Roman                               15 x 38   40 %
    Century                                   Roman                          15 x 38   40 %
    Century                                   Roman                               15 x 38   40 %
    Century                                   Roman                  15 x 38   40 %
    Chiller                                   Decorative                           9 x 37   40 %
    Colonna MT                                Decorative                          13 x 34   40 %
    Comic Sans MS                             Script                            15 x 45   40 %
    Comic Sans MS                             Script                             15 x 45   40 %
    Comic Sans MS                             Script                              15 x 45   40 %
    Comic Sans MS                             Script                         15 x 45   40 %
    Comic Sans MS                             Script                              15 x 45   40 %
    Comic Sans MS                             Script                 15 x 45   40 %
    Consolas                                  Modern      Regular                      18 x 37   40 %
    Consolas                                  Modern      Regular                     18 x 37   40 %
    Consolas                                  Modern      Regular                       18 x 37   40 %
    Consolas                                  Modern      Regular                        18 x 37   40 %
    Consolas                                  Modern      Regular                   18 x 37   40 %
    Consolas                                  Modern      Regular                        18 x 37   40 %
    Consolas                                  Modern      Regular           18 x 37   40 %
    Constantia                                Roman       Regular                      17 x 39   40 %
    Constantia                                Roman       Regular                     17 x 39   40 %
    Constantia                                Roman       Regular                       17 x 39   40 %
    Constantia                                Roman       Regular                        17 x 39   40 %
    Constantia                                Roman       Regular                   17 x 39   40 %
    Constantia                                Roman       Regular                        17 x 39   40 %
    Constantia                                Roman       Regular           17 x 39   40 %
    Cooper Black                              Roman                               16 x 37   40 %
    Copperplate Gothic Bold                   Swiss                               19 x 36   40 %
    Copperplate Gothic Light                  Swiss                               18 x 35   40 %
    Corbel                                    Swiss       Regular                      17 x 39   40 %
    Corbel                                    Swiss       Regular                     17 x 39   40 %
    Corbel                                    Swiss       Regular                       17 x 39   40 %
    Corbel                                    Swiss       Regular                        17 x 39   40 %
    Corbel                                    Swiss       Regular                   17 x 39   40 %
    Corbel                                    Swiss       Regular                        17 x 39   40 %
    Corbel                                    Swiss       Regular           17 x 39   40 %
    Cordia New                                Swiss       Regular                         9 x 44   40 %
    Cordia New                                Swiss       Regular                          9 x 44   40 %
    CordiaUPC                                 Swiss       Regular                         9 x 44   40 %
    CordiaUPC                                 Swiss       Regular                          9 x 44   40 %
    Courier New                               Modern                              19 x 36   40 %
    Courier New                               Modern                            19 x 36   40 %
    Courier New                               Modern                           19 x 36   40 %
    Courier New                               Modern                             19 x 36   40 %
    Courier New                               Modern                              19 x 36   40 %
    Courier New                               Modern                                 19 x 36   40 %
    Courier New                               Modern                         19 x 36   40 %
    Courier New                               Modern                              19 x 36   40 %
    Courier New                               Modern                 19 x 36   40 %
    Courier                                   Roman                                  8 x 13   40 %
    Curlz MT                                  Decorative                          12 x 42   40 %
    DaunPenh                                  Special                             12 x 43   40 %
    David                                     Swiss       Regular                           13 x 31   40 %
    DFKai-SB                                  Script      Regular                        16 x 32   40 %
    DFKai-SB                                  Script      Regular         (BIG5)        16 x 32   40 %
    DilleniaUPC                               Roman                                9 x 42   40 %
    DilleniaUPC                               Roman                                 9 x 42   40 %
    DokChampa                                 Swiss                               19 x 62   40 %
    DokChampa                                 Swiss                                19 x 62   40 %
    Dotum                                     Swiss       Regular                      16 x 32   40 %
    Dotum                                     Swiss       Regular                       16 x 32   40 %
    Dotum                                     Swiss       Regular                        16 x 32   40 %
    Dotum                                     Swiss       Regular                   16 x 32   40 %
    Dotum                                     Swiss       Regular                        16 x 32   40 %
    Dotum                                     Swiss       Regular                         16 x 32   40 %
    Dotum                                     Swiss       Regular           16 x 32   40 %
    DotumChe                                  Modern      Regular                      16 x 32   40 %
    DotumChe                                  Modern      Regular                       16 x 32   40 %
    DotumChe                                  Modern      Regular                        16 x 32   40 %
    DotumChe                                  Modern      Regular                   16 x 32   40 %
    DotumChe                                  Modern      Regular                        16 x 32   40 %
    DotumChe                                  Modern      Regular                         16 x 32   40 %
    DotumChe                                  Modern      Regular           16 x 32   40 %
    Ebrima                                    Special                           19 x 43   40 %
    Ebrima                                    Special                             19 x 43   40 %
    Ebrima                                    Special                             19 x 43   40 %
    Ebrima                                    Special                19 x 43   40 %
    Edwardian Script ITC                      Script                               8 x 38   40 %
    Elephant                                  Roman                               16 x 41   40 %
    Engravers MT                              Roman                               25 x 37   50 %
    Eras Bold ITC                             Swiss                               16 x 37   40 %
    Eras Demi ITC                             Swiss                               15 x 36   40 %
    Eras Light ITC                            Swiss                               13 x 36   40 %
    Eras Medium ITC                           Swiss                               14 x 36   40 %
    Estrangelo Edessa                         Script                              16 x 36   40 %
    EucrosiaUPC                               Roman                                9 x 39   40 %
    EucrosiaUPC                               Roman                                 9 x 39   40 %
    Euphemia                                  Swiss       Regular                        22 x 42   40 %
    FangSong                                  Modern                              16 x 32   40 %
    FangSong                                  Modern               (2312)        16 x 32   40 %
    Felix Titling                             Decorative                          19 x 37   40 %
    Fixedsys                                  Swiss                                  8 x 16   40 %
    Footlight MT Light                        Roman                               13 x 34   30 %
    Forte                                     Script      Regular                        14 x 35   40 %
    Franklin Gothic Book                      Swiss                             13 x 36   40 %
    Franklin Gothic Book                      Swiss                              13 x 36   40 %
    Franklin Gothic Book                      Swiss                               13 x 36   40 %
    Franklin Gothic Book                      Swiss                          13 x 36   40 %
    Franklin Gothic Book                      Swiss                               13 x 36   40 %
    Franklin Gothic Book                      Swiss                  13 x 36   40 %
    Franklin Gothic Demi Cond                 Swiss                             12 x 36   40 %
    Franklin Gothic Demi Cond                 Swiss                              12 x 36   40 %
    Franklin Gothic Demi Cond                 Swiss                               12 x 36   40 %
    Franklin Gothic Demi Cond                 Swiss                          12 x 36   40 %
    Franklin Gothic Demi Cond                 Swiss                               12 x 36   40 %
    Franklin Gothic Demi Cond                 Swiss                  12 x 36   40 %
    Franklin Gothic Demi                      Swiss                             14 x 36   40 %
    Franklin Gothic Demi                      Swiss                              14 x 36   40 %
    Franklin Gothic Demi                      Swiss                               14 x 36   40 %
    Franklin Gothic Demi                      Swiss                          14 x 36   40 %
    Franklin Gothic Demi                      Swiss                               14 x 36   40 %
    Franklin Gothic Demi                      Swiss                  14 x 36   40 %
    Franklin Gothic Heavy                     Swiss                             15 x 36   40 %
    Franklin Gothic Heavy                     Swiss                              15 x 36   40 %
    Franklin Gothic Heavy                     Swiss                               15 x 36   40 %
    Franklin Gothic Heavy                     Swiss                          15 x 36   40 %
    Franklin Gothic Heavy                     Swiss                               15 x 36   40 %
    Franklin Gothic Heavy                     Swiss                  15 x 36   40 %
    Franklin Gothic Medium Cond               Swiss                             12 x 36   40 %
    Franklin Gothic Medium Cond               Swiss                              12 x 36   40 %
    Franklin Gothic Medium Cond               Swiss                               12 x 36   40 %
    Franklin Gothic Medium Cond               Swiss                          12 x 36   40 %
    Franklin Gothic Medium Cond               Swiss                               12 x 36   40 %
    Franklin Gothic Medium Cond               Swiss                  12 x 36   40 %
    Franklin Gothic Medium                    Swiss                             14 x 36   40 %
    Franklin Gothic Medium                    Swiss                              14 x 36   40 %
    Franklin Gothic Medium                    Swiss                               14 x 36   40 %
    Franklin Gothic Medium                    Swiss                          14 x 36   40 %
    Franklin Gothic Medium                    Swiss                               14 x 36   40 %
    Franklin Gothic Medium                    Swiss                  14 x 36   40 %
    FrankRuehl                                Swiss       Regular                           13 x 30   40 %
    FreesiaUPC                                Swiss       Regular                         9 x 38   40 %
    FreesiaUPC                                Swiss       Regular                          9 x 38   40 %
    Freestyle Script                          Script                               8 x 38   40 %
    French Script MT                          Script                               9 x 36   40 %
    Gabriola                                  Decorative  Regular                      16 x 59   40 %
    Gabriola                                  Decorative  Regular                       16 x 59   40 %
    Gabriola                                  Decorative  Regular                        16 x 59   40 %
    Gabriola                                  Decorative  Regular                   16 x 59   40 %
    Gabriola                                  Decorative  Regular                        16 x 59   40 %
    Gabriola                                  Decorative  Regular           16 x 59   40 %
    Garamond                                  Roman                             12 x 36   40 %
    Garamond                                  Roman                              12 x 36   40 %
    Garamond                                  Roman                               12 x 36   40 %
    Garamond                                  Roman                          12 x 36   40 %
    Garamond                                  Roman                               12 x 36   40 %
    Garamond                                  Roman                  12 x 36   40 %
    Gautami                                   Swiss       Regular                        18 x 56   40 %
    Georgia                                   Roman                             14 x 36   40 %
    Georgia                                   Roman                              14 x 36   40 %
    Georgia                                   Roman                               14 x 36   40 %
    Georgia                                   Roman                          14 x 36   40 %
    Georgia                                   Roman                               14 x 36   40 %
    Georgia                                   Roman                  14 x 36   40 %
    Gigi                                      Decorative                          13 x 44   40 %
    Gill Sans MT Condensed                    Swiss                               10 x 39   40 %
    Gill Sans MT Condensed                    Swiss                  10 x 39   40 %
    Gill Sans MT Ext Condensed Bold           Swiss                                7 x 38   40 %
    Gill Sans MT Ext Condensed Bold           Swiss                   7 x 38   40 %
    Gill Sans MT                              Swiss                          14 x 37   70 %
    Gill Sans MT                              Swiss             14 x 37   70 %
    Gill Sans Ultra Bold Condensed            Swiss                               14 x 40   40 %
    Gill Sans Ultra Bold Condensed            Swiss                  14 x 40   40 %
    Gill Sans Ultra Bold                      Swiss                               20 x 40   40 %
    Gill Sans Ultra Bold                      Swiss                  20 x 40   40 %
    Gisha                                     Swiss                               16 x 38   40 %
    Gisha                                     Swiss                                  16 x 38   40 %
    Gloucester MT Extra Condensed             Roman       Regular                         9 x 37   40 %
    Goudy Old Style                           Roman                               13 x 36   40 %
    Goudy Stout                               Roman                               36 x 44   40 %
    Gulim                                     Swiss       Regular                      16 x 32   40 %
    Gulim                                     Swiss       Regular                       16 x 32   40 %
    Gulim                                     Swiss       Regular                        16 x 32   40 %
    Gulim                                     Swiss       Regular                   16 x 32   40 %
    Gulim                                     Swiss       Regular                        16 x 32   40 %
    Gulim                                     Swiss       Regular                         16 x 32   40 %
    Gulim                                     Swiss       Regular           16 x 32   40 %
    GulimChe                                  Modern      Regular                      16 x 32   40 %
    GulimChe                                  Modern      Regular                       16 x 32   40 %
    GulimChe                                  Modern      Regular                        16 x 32   40 %
    GulimChe                                  Modern      Regular                   16 x 32   40 %
    GulimChe                                  Modern      Regular                        16 x 32   40 %
    GulimChe                                  Modern      Regular                         16 x 32   40 %
    GulimChe                                  Modern      Regular           16 x 32   40 %
    Gungsuh                                   Roman       Regular                      16 x 32   40 %
    Gungsuh                                   Roman       Regular                       16 x 32   40 %
    Gungsuh                                   Roman       Regular                        16 x 32   40 %
    Gungsuh                                   Roman       Regular                   16 x 32   40 %
    Gungsuh                                   Roman       Regular                        16 x 32   40 %
    Gungsuh                                   Roman       Regular                         16 x 32   40 %
    Gungsuh                                   Roman       Regular           16 x 32   40 %
    GungsuhChe                                Modern      Regular                      16 x 32   40 %
    GungsuhChe                                Modern      Regular                       16 x 32   40 %
    GungsuhChe                                Modern      Regular                        16 x 32   40 %
    GungsuhChe                                Modern      Regular                   16 x 32   40 %
    GungsuhChe                                Modern      Regular                        16 x 32   40 %
    GungsuhChe                                Modern      Regular                         16 x 32   40 %
    GungsuhChe                                Modern      Regular           16 x 32   40 %
    Haettenschweiler                          Swiss                             10 x 33   40 %
    Haettenschweiler                          Swiss                              10 x 33   40 %
    Haettenschweiler                          Swiss                               10 x 33   40 %
    Haettenschweiler                          Swiss                          10 x 33   40 %
    Haettenschweiler                          Swiss                               10 x 33   40 %
    Haettenschweiler                          Swiss                  10 x 33   40 %
    Harlow Solid Italic                       Decorative  Italic                         12 x 40   40 %
    Harrington                                Decorative                          14 x 38   40 %
    High Tower Text                           Roman                               13 x 37   40 %
    Impact                                    Swiss                             13 x 39   40 %
    Impact                                    Swiss                              13 x 39   40 %
    Impact                                    Swiss                               13 x 39   40 %
    Impact                                    Swiss                          13 x 39   40 %
    Impact                                    Swiss                               13 x 39   40 %
    Impact                                    Swiss                  13 x 39   40 %
    Imprint MT Shadow                         Decorative                          13 x 38   40 %
    Informal Roman                            Script                              12 x 32   40 %
    IrisUPC                                   Swiss       Regular                         9 x 40   40 %
    IrisUPC                                   Swiss       Regular                          9 x 40   40 %
    Iskoola Pota                              Swiss                               22 x 36   40 %
    JasmineUPC                                Roman       Regular                         9 x 34   40 %
    JasmineUPC                                Roman       Regular                          9 x 34   40 %
    Jokerman                                  Decorative                          16 x 48   40 %
    Juice ITC                                 Decorative                           9 x 36   40 %
    KaiTi                                     Modern                              16 x 32   40 %
    KaiTi                                     Modern               (2312)        16 x 32   40 %
    Kalinga                                   Swiss       Regular                        19 x 48   40 %
    Kartika                                   Roman       Regular                        27 x 46   40 %
    Khmer UI                                  Swiss                               21 x 36   40 %
    KodchiangUPC                              Roman       Regular                         9 x 31   40 %
    KodchiangUPC                              Roman       Regular                          9 x 31   40 %
    Kokila                                    Swiss       Regular                        13 x 37   40 %
    Kristen ITC                               Script                              16 x 44   40 %
    Kunstler Script                           Script                               8 x 35   40 %
    Lao UI                                    Swiss                               18 x 43   40 %
    Latha                                     Swiss       Regular                        23 x 44   40 %
    Leelawadee                                Swiss                               17 x 38   40 %
    Leelawadee                                Swiss                                17 x 38   40 %
    Levenim MT                                Special     Regular                           16 x 42   40 %
    LilyUPC                                   Swiss                                9 x 30   40 %
    LilyUPC                                   Swiss                                 9 x 30   40 %
    Lucida Bright                             Roman       Regular                        16 x 36   40 %
    Lucida Calligraphy                        Script      Italic                         17 x 40   40 %
    Lucida Console                            Modern                             19 x 32   40 %
    Lucida Console                            Modern                              19 x 32   40 %
    Lucida Console                            Modern                         19 x 32   40 %
    Lucida Console                            Modern                              19 x 32   40 %
    Lucida Console                            Modern                 19 x 32   40 %
    Lucida Fax                                Roman       Regular                        16 x 37   40 %
    Lucida Handwriting                        Script      Italic                         18 x 41   40 %
    Lucida Sans Typewriter                    Modern      Regular                        19 x 36   40 %
    Lucida Sans Unicode                       Swiss                             16 x 49   40 %
    Lucida Sans Unicode                       Swiss                              16 x 49   40 %
    Lucida Sans Unicode                       Swiss                               16 x 49   40 %
    Lucida Sans Unicode                       Swiss                                  16 x 49   40 %
    Lucida Sans Unicode                       Swiss                          16 x 49   40 %
    Lucida Sans Unicode                       Swiss                               16 x 49   40 %
    Lucida Sans Unicode                       Swiss                  16 x 49   40 %
    Lucida Sans                               Swiss       Regular                        16 x 36   40 %
    Magneto                                   Decorative                       18 x 39   70 %
    Maiandra GD                               Swiss                               14 x 38   40 %
    Malgun Gothic                             Swiss       Regular                        15 x 43   40 %
    Malgun Gothic                             Swiss       Regular                         15 x 43   40 %
    Mangal                                    Roman       Regular                        19 x 54   40 %
    Marlett                                   Special     Regular                      31 x 32   50 %
    Matura MT Script Capitals                 Script                              14 x 43   40 %
    Meiryo UI                                 Swiss                             17 x 41   40 %
    Meiryo UI                                 Swiss                              17 x 41   40 %
    Meiryo UI                                 Swiss                               17 x 41   40 %
    Meiryo UI                                 Swiss                          17 x 41   40 %
    Meiryo UI                                 Swiss                               17 x 41   40 %
    Meiryo UI                                 Swiss                  17 x 41   40 %
    Meiryo UI                                 Swiss                               17 x 41   40 %
    Meiryo                                    Swiss                             31 x 48   40 %
    Meiryo                                    Swiss                              31 x 48   40 %
    Meiryo                                    Swiss                               31 x 48   40 %
    Meiryo                                    Swiss                          31 x 48   40 %
    Meiryo                                    Swiss                               31 x 48   40 %
    Meiryo                                    Swiss                  31 x 48   40 %
    Meiryo                                    Swiss                               31 x 48   40 %
    Microsoft Himalaya                        Special                             13 x 32   40 %
    Microsoft JhengHei                        Swiss                              15 x 43   40 %
    Microsoft JhengHei                        Swiss                               15 x 43   40 %
    Microsoft JhengHei                        Swiss                (BIG5)        15 x 43   40 %
    Microsoft New Tai Lue                     Swiss       Regular                        19 x 42   40 %
    Microsoft PhagsPa                         Swiss       Regular                        24 x 41   40 %
    Microsoft Sans Serif                      Swiss                               14 x 36   40 %
    Microsoft Sans Serif                      Swiss                             14 x 36   40 %
    Microsoft Sans Serif                      Swiss                            14 x 36   40 %
    Microsoft Sans Serif                      Swiss                              14 x 36   40 %
    Microsoft Sans Serif                      Swiss                               14 x 36   40 %
    Microsoft Sans Serif                      Swiss                                  14 x 36   40 %
    Microsoft Sans Serif                      Swiss                          14 x 36   40 %
    Microsoft Sans Serif                      Swiss                                14 x 36   40 %
    Microsoft Sans Serif                      Swiss                               14 x 36   40 %
    Microsoft Sans Serif                      Swiss                  14 x 36   40 %
    Microsoft Tai Le                          Swiss       Regular                        19 x 41   40 %
    Microsoft Uighur                          Special                             13 x 32   40 %
    Microsoft Uighur                          Special                             13 x 32   40 %
    Microsoft YaHei                           Swiss                              15 x 42   40 %
    Microsoft YaHei                           Swiss                               15 x 42   40 %
    Microsoft YaHei                           Swiss                          15 x 42   40 %
    Microsoft YaHei                           Swiss                (2312)        15 x 42   40 %
    Microsoft YaHei                           Swiss                               15 x 42   40 %
    Microsoft YaHei                           Swiss                  15 x 42   40 %
    Microsoft Yi Baiti                        Script                              21 x 32   40 %
    MingLiU                                   Modern      Regular                        16 x 32   40 %
    MingLiU                                   Modern      Regular         (BIG5)        16 x 32   40 %
    MingLiU_HKSCS                             Roman       Regular                        16 x 32   40 %
    MingLiU_HKSCS                             Roman       Regular         (BIG5)        16 x 32   40 %
    MingLiU_HKSCS-ExtB                        Roman       Regular                        16 x 32   40 %
    MingLiU_HKSCS-ExtB                        Roman       Regular         (BIG5)        16 x 32   40 %
    MingLiU-ExtB                              Roman       Regular                        16 x 32   40 %
    MingLiU-ExtB                              Roman       Regular         (BIG5)        16 x 32   40 %
    Miriam Fixed                              Modern      Regular                           19 x 32   40 %
    Miriam                                    Swiss       Regular                           13 x 32   40 %
    Mistral                                   Script                            10 x 39   40 %
    Mistral                                   Script                             10 x 39   40 %
    Mistral                                   Script                              10 x 39   40 %
    Mistral                                   Script                         10 x 39   40 %
    Mistral                                   Script                              10 x 39   40 %
    Mistral                                   Script                 10 x 39   40 %
    Modern No. 20                             Roman                               13 x 33   40 %
    Modern                                    Modern                     OEM/DOS                 19 x 37   40 %
    Mongolian Baiti                           Script                              14 x 34   40 %
    Monotype Corsiva                          Script                            11 x 35   40 %
    Monotype Corsiva                          Script                             11 x 35   40 %
    Monotype Corsiva                          Script                              11 x 35   40 %
    Monotype Corsiva                          Script                         11 x 35   40 %
    Monotype Corsiva                          Script                              11 x 35   40 %
    Monotype Corsiva                          Script                 11 x 35   40 %
    MoolBoran                                 Swiss                               13 x 43   40 %
    MS Gothic                                 Modern      Regular                      16 x 32   40 %
    MS Gothic                                 Modern      Regular                       16 x 32   40 %
    MS Gothic                                 Modern      Regular                        16 x 32   40 %
    MS Gothic                                 Modern      Regular                   16 x 32   40 %
    MS Gothic                                 Modern      Regular                        16 x 32   40 %
    MS Gothic                                 Modern      Regular           16 x 32   40 %
    MS Gothic                                 Modern      Regular                        16 x 32   40 %
    MS Mincho                                 Modern      Regular                      16 x 32   40 %
    MS Mincho                                 Modern      Regular                       16 x 32   40 %
    MS Mincho                                 Modern      Regular                        16 x 32   40 %
    MS Mincho                                 Modern      Regular                   16 x 32   40 %
    MS Mincho                                 Modern      Regular                        16 x 32   40 %
    MS Mincho                                 Modern      Regular           16 x 32   40 %
    MS Mincho                                 Modern      Regular                        16 x 32   40 %
    MS Outlook                                Special                           31 x 33   40 %
    MS PGothic                                Swiss       Regular                      13 x 32   40 %
    MS PGothic                                Swiss       Regular                       13 x 32   40 %
    MS PGothic                                Swiss       Regular                        13 x 32   40 %
    MS PGothic                                Swiss       Regular                   13 x 32   40 %
    MS PGothic                                Swiss       Regular                        13 x 32   40 %
    MS PGothic                                Swiss       Regular           13 x 32   40 %
    MS PGothic                                Swiss       Regular                        13 x 32   40 %
    MS PMincho                                Roman       Regular                      13 x 32   40 %
    MS PMincho                                Roman       Regular                       13 x 32   40 %
    MS PMincho                                Roman       Regular                        13 x 32   40 %
    MS PMincho                                Roman       Regular                   13 x 32   40 %
    MS PMincho                                Roman       Regular                        13 x 32   40 %
    MS PMincho                                Roman       Regular           13 x 32   40 %
    MS PMincho                                Roman       Regular                        13 x 32   40 %
    MS Reference Sans Serif                   Swiss                             16 x 39   40 %
    MS Reference Sans Serif                   Swiss                            16 x 39   40 %
    MS Reference Sans Serif                   Swiss                              16 x 39   40 %
    MS Reference Sans Serif                   Swiss                               16 x 39   40 %
    MS Reference Sans Serif                   Swiss                          16 x 39   40 %
    MS Reference Sans Serif                   Swiss                               16 x 39   40 %
    MS Reference Sans Serif                   Swiss                  16 x 39   40 %
    MS Reference Specialty                    Special                           23 x 39   40 %
    MS Sans Serif                             Swiss                                  5 x 13   40 %
    MS Serif                                  Roman                                  5 x 13   40 %
    MS UI Gothic                              Swiss       Regular                      13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                       13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                        13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                   13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                        13 x 32   40 %
    MS UI Gothic                              Swiss       Regular           13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                        13 x 32   40 %
    MT Extra                                  Roman       Regular                      20 x 32   40 %
    MV Boli                                   Special                             18 x 52   40 %
    Narkisim                                  Swiss       Regular                           12 x 32   40 %
    Niagara Engraved                          Decorative                           8 x 34   40 %
    Niagara Solid                             Decorative                           8 x 34   40 %
    NSimSun                                   Modern      Regular                        16 x 32   40 %
    NSimSun                                   Modern      Regular         (2312)        16 x 32   40 %
    Nyala                                     Special                           18 x 33   40 %
    Nyala                                     Special                             18 x 33   40 %
    Nyala                                     Special                             18 x 33   40 %
    Nyala                                     Special                18 x 33   40 %
    OCR A Extended                            Modern                              19 x 33   40 %
    Old English Text MT                       Script                              12 x 39   40 %
    Onyx                                      Decorative                           8 x 37   40 %
    Palace Script MT                          Script      Regular                         7 x 30   40 %
    Palatino Linotype                         Roman                             14 x 43   40 %
    Palatino Linotype                         Roman                            14 x 43   40 %
    Palatino Linotype                         Roman                              14 x 43   40 %
    Palatino Linotype                         Roman                               14 x 43   40 %
    Palatino Linotype                         Roman                          14 x 43   40 %
    Palatino Linotype                         Roman                               14 x 43   40 %
    Palatino Linotype                         Roman                  14 x 43   40 %
    Papyrus                                   Script                              13 x 50   40 %
    Parchment                                 Script                               6 x 34   40 %
    Perpetua Titling MT                       Roman                            21 x 39   70 %
    Perpetua                                  Roman                          12 x 37   70 %
    Plantagenet Cherokee                      Roman                               14 x 41   40 %
    Playbill                                  Decorative                           8 x 32   40 %
    PMingLiU                                  Roman       Regular                        16 x 32   40 %
    PMingLiU                                  Roman       Regular         (BIG5)        16 x 32   40 %
    PMingLiU-ExtB                             Roman       Regular                        16 x 32   40 %
    PMingLiU-ExtB                             Roman       Regular         (BIG5)        16 x 32   40 %
    Poor Richard                              Roman                               12 x 36   40 %
    Pristina                                  Script                              10 x 42   40 %
    Raavi                                     Swiss       Regular                        13 x 53   40 %
    Rage Italic                               Script                              11 x 40   40 %
    Ravie                                     Decorative                          22 x 43   40 %
    Rockwell Condensed                        Roman                            13 x 38   70 %
    Rockwell Extra Bold                       Roman                               19 x 38   80 %
    Rockwell                                  Roman                               15 x 38   40 %
    Rod                                       Modern      Regular                           19 x 31   40 %
    Roman                                     Roman                      OEM/DOS                 22 x 37   40 %
    Sakkal Majalla                            Special                             16 x 45   40 %
    Sakkal Majalla                            Special                           16 x 45   40 %
    Sakkal Majalla                            Special                             16 x 45   40 %
    Sakkal Majalla                            Special                             16 x 45   40 %
    Sakkal Majalla                            Special                16 x 45   40 %
    Script MT Bold                            Script      Regular                        13 x 39   70 %
    Script                                    Script                     OEM/DOS                 16 x 36   40 %
    Segoe Print                               Special     Regular                      21 x 56   40 %
    Segoe Print                               Special     Regular                       21 x 56   40 %
    Segoe Print                               Special     Regular                        21 x 56   40 %
    Segoe Print                               Special     Regular                   21 x 56   40 %
    Segoe Print                               Special     Regular                        21 x 56   40 %
    Segoe Print                               Special     Regular           21 x 56   40 %
    Segoe Script                              Swiss                             22 x 51   40 %
    Segoe Script                              Swiss                              22 x 51   40 %
    Segoe Script                              Swiss                               22 x 51   40 %
    Segoe Script                              Swiss                          22 x 51   40 %
    Segoe Script                              Swiss                               22 x 51   40 %
    Segoe Script                              Swiss                  22 x 51   40 %
    Segoe UI Light                            Swiss       Regular                      17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                     17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                       17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                        17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                   17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                        17 x 43   30 %
    Segoe UI Light                            Swiss       Regular           17 x 43   30 %
    Segoe UI Semibold                         Swiss       Regular                      18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                     18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                       18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                        18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                   18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                        18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular           18 x 43   60 %
    Segoe UI Symbol                           Swiss                               23 x 43   40 %
    Segoe UI                                  Swiss                               17 x 43   40 %
    Segoe UI                                  Swiss                             17 x 43   40 %
    Segoe UI                                  Swiss                            17 x 43   40 %
    Segoe UI                                  Swiss                              17 x 43   40 %
    Segoe UI                                  Swiss                               17 x 43   40 %
    Segoe UI                                  Swiss                          17 x 43   40 %
    Segoe UI                                  Swiss                               17 x 43   40 %
    Segoe UI                                  Swiss                  17 x 43   40 %
    Shonar Bangla                             Swiss       Regular                        16 x 41   40 %
    Showcard Gothic                           Decorative                          18 x 40   40 %
    Shruti                                    Swiss       Regular                        14 x 54   40 %
    SimHei                                    Modern                              16 x 32   40 %
    SimHei                                    Modern               (2312)        16 x 32   40 %
    Simplified Arabic Fixed                   Modern      Regular                        19 x 35   40 %
    Simplified Arabic Fixed                   Modern      Regular                        19 x 35   40 %
    Simplified Arabic                         Roman       Regular                        13 x 53   40 %
    Simplified Arabic                         Roman       Regular                        13 x 53   40 %
    SimSun                                    Special     Regular                        16 x 32   40 %
    SimSun                                    Special     Regular         (2312)        16 x 32   40 %
    SimSun-ExtB                               Modern                              16 x 32   40 %
    SimSun-ExtB                               Modern               (2312)        16 x 32   40 %
    Small Fonts                               Swiss                                   1 x 3   40 %
    Snap ITC                                  Decorative                          19 x 41   40 %
    Stencil                                   Decorative                          18 x 38   40 %
    Sylfaen                                   Roman                             13 x 42   40 %
    Sylfaen                                   Roman                              13 x 42   40 %
    Sylfaen                                   Roman                               13 x 42   40 %
    Sylfaen                                   Roman                          13 x 42   40 %
    Sylfaen                                   Roman                               13 x 42   40 %
    Sylfaen                                   Roman                  13 x 42   40 %
    Symbol                                    Roman                             19 x 39   40 %
    System                                    Swiss                                  7 x 16   70 %
    Tahoma                                    Swiss                               14 x 39   40 %
    Tahoma                                    Swiss                             14 x 39   40 %
    Tahoma                                    Swiss                            14 x 39   40 %
    Tahoma                                    Swiss                              14 x 39   40 %
    Tahoma                                    Swiss                               14 x 39   40 %
    Tahoma                                    Swiss                                  14 x 39   40 %
    Tahoma                                    Swiss                          14 x 39   40 %
    Tahoma                                    Swiss                                14 x 39   40 %
    Tahoma                                    Swiss                               14 x 39   40 %
    Tahoma                                    Swiss                  14 x 39   40 %
    Tempus Sans ITC                           Decorative                          13 x 42   40 %
    Terminal                                  Modern                     OEM/DOS                  8 x 12   40 %
    Times New Roman                           Roman                               13 x 35   40 %
    Times New Roman                           Roman                             13 x 35   40 %
    Times New Roman                           Roman                            13 x 35   40 %
    Times New Roman                           Roman                              13 x 35   40 %
    Times New Roman                           Roman                               13 x 35   40 %
    Times New Roman                           Roman                                  13 x 35   40 %
    Times New Roman                           Roman                          13 x 35   40 %
    Times New Roman                           Roman                               13 x 35   40 %
    Times New Roman                           Roman                  13 x 35   40 %
    Traditional Arabic                        Roman       Regular                        15 x 48   40 %
    Traditional Arabic                        Roman       Regular                        15 x 48   40 %
    Trebuchet MS                              Swiss                             15 x 37   40 %
    Trebuchet MS                              Swiss                              15 x 37   40 %
    Trebuchet MS                              Swiss                               15 x 37   40 %
    Trebuchet MS                              Swiss                          15 x 37   40 %
    Trebuchet MS                              Swiss                               15 x 37   40 %
    Trebuchet MS                              Swiss                  15 x 37   40 %
    Tunga                                     Swiss       Regular                        18 x 53   40 %
    Tw Cen MT Condensed Extra Bold            Swiss                               12 x 35   40 %
    Tw Cen MT Condensed Extra Bold            Swiss                  12 x 35   40 %
    Tw Cen MT Condensed                       Swiss                               10 x 34   40 %
    Tw Cen MT Condensed                       Swiss                  10 x 34   40 %
    Tw Cen MT                                 Swiss                          12 x 35   70 %
    Tw Cen MT                                 Swiss             12 x 35   70 %
    Utsaah                                    Swiss       Regular                        13 x 36   40 %
    Vani                                      Swiss       Regular                        23 x 54   40 %
    Verdana                                   Swiss                             16 x 39   40 %
    Verdana                                   Swiss                            16 x 39   40 %
    Verdana                                   Swiss                              16 x 39   40 %
    Verdana                                   Swiss                               16 x 39   40 %
    Verdana                                   Swiss                          16 x 39   40 %
    Verdana                                   Swiss                               16 x 39   40 %
    Verdana                                   Swiss                  16 x 39   40 %
    Vijaya                                    Swiss       Regular                        19 x 32   40 %
    Viner Hand ITC                            Script                              15 x 52   40 %
    Vivaldi                                   Script                                9 x 38   40 %
    Vladimir Script                           Script                              10 x 39   40 %
    Vrinda                                    Swiss       Regular                        20 x 44   40 %
    Webdings                                  Roman                             31 x 32   40 %
    Wide Latin                                Roman                               26 x 39   40 %
    Wingdings 2                               Roman       Regular                      27 x 34   40 %
    Wingdings 3                               Roman       Regular                      25 x 36   40 %
    Wingdings                                 Special     Regular                      28 x 36   40 %


--------[  Windows ]-----------------------------------------------------------------------------------------------

    midi-out.0   0001 001B  Microsoft GS Wavetable Synth
    mixer.0      0001 0068   (Realtek High Definiti
    mixer.1      0001 0068  Realtek Digital Output (Realtek
    mixer.2      0001 0068  Realtek Digital Output(Optical)
    wave-out.0   0001 0064   (Realtek High Definiti
    wave-out.1   0001 0064  Realtek Digital Output (Realtek
    wave-out.2   0001 0064  Realtek Digital Output(Optical)


--------[  PCI / PnP ]---------------------------------------------------------------------------------------------

    Realtek ALC887 @ ATI SB700 - High Definition Audio Controller                     PCI
     High Definition Audio (Microsoft) [10DE-0BEE] [NoDB]                   PCI


--------[ HD Audio ]----------------------------------------------------------------------------------------------------

  [ ATI SB700 - High Definition Audio Controller ]

     :
                                      ATI SB700 - High Definition Audio Controller
        (Windows)                      High Definition Audio (Microsoft)
                                                 PCI
       /  /                        0 / 20 / 2
      ID                                      1002-4383
                               1043-837B
                                                  00
       ID                                     PCI\VEN_1002&DEV_4383&SUBSYS_837B1043&REV_00

     :
                                                   Advanced Micro Devices, Inc.
                                     http://ati.amd.com/products/integrated.html
                                       http://ati.amd.com/support/driver.html
       BIOS                                   http://www.aida64.com/bios-updates
                                     http://www.aida64.com/driver-updates

  [ Realtek ALC887 ]

     :
                                      Realtek ALC887
        (Windows)                     Realtek High Definition Audio
                                           Audio
                                                 HDAUDIO
      ID                                      10EC-0887
                               10EC-0887
                                                  1002
       ID                                     HDAUDIO\FUNC_01&VEN_10EC&DEV_0887&SUBSYS_10EC0887&REV_1002

     :
                                                   Realtek Semiconductor Corp.
                                     http://www.realtek.com.tw/products/productsView.aspx?Langid=1&PNid=8&PFid=14&Level=3&Conn=2
                                       http://www.realtek.com.tw/downloads
                                     http://www.aida64.com/driver-updates

  [  High Definition Audio (Microsoft) [10DE-0BEE] [NoDB] ]

     :
                                       High Definition Audio (Microsoft) [10DE-0BEE] [NoDB]
        (Windows)                      High Definition Audio (Microsoft)
                                                 PCI
       /  /                        1 / 0 / 1
      ID                                      10DE-0BEE
                               1462-809D
                                                  A1
       ID                                     PCI\VEN_10DE&DEV_0BEE&SUBSYS_809D1462&REV_A1

  [ nVIDIA Unknown ]

     :
                                      nVIDIA Unknown
        (Windows)                     NVIDIA High Definition Audio
                                           Audio
                                                 HDAUDIO
      ID                                      10DE-0015
                               10DE-0101
                                                  1001
       ID                                     HDAUDIO\FUNC_01&VEN_10DE&DEV_0015&SUBSYS_10DE0101&REV_1001

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ nVIDIA Unknown ]

     :
                                      nVIDIA Unknown
        (Windows)                     NVIDIA High Definition Audio
                                           Audio
                                                 HDAUDIO
      ID                                      10DE-0015
                               10DE-0101
                                                  1001
       ID                                     HDAUDIO\FUNC_01&VEN_10DE&DEV_0015&SUBSYS_10DE0101&REV_1001

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ nVIDIA Unknown ]

     :
                                      nVIDIA Unknown
        (Windows)                     NVIDIA High Definition Audio
                                           Audio
                                                 HDAUDIO
      ID                                      10DE-0015
                               10DE-0101
                                                  1001
       ID                                     HDAUDIO\FUNC_01&VEN_10DE&DEV_0015&SUBSYS_10DE0101&REV_1001

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ nVIDIA Unknown ]

     :
                                      nVIDIA Unknown
        (Windows)                     NVIDIA High Definition Audio
                                           Audio
                                                 HDAUDIO
      ID                                      10DE-0015
                               10DE-0101
                                                  1001
       ID                                     HDAUDIO\FUNC_01&VEN_10DE&DEV_0015&SUBSYS_10DE0101&REV_1001

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates


--------[   ]------------------------------------------------------------------------------------------------

  [ AC-3 ACM Codec ]

      ACM:
                                        AC-3 ACM Codec
      Copyright-                                   2005 by fccHandler
                                  GNU General Public License
                                         Dolby Digital AC-3 codec for Windows ACM
                                          2.00

  [ Fraunhofer IIS MPEG Layer-3 Codec (decode only) ]

      ACM:
                                        Fraunhofer IIS MPEG Layer-3 Codec (decode only)
      Copyright-                                  Copyright  1996-1999 Fraunhofer Institut Integrierte Schaltungen IIS
                                         decoder only version
                                          1.09

  [ Fraunhofer IIS MPEG Layer-3 Codec (professional) ]

      ACM:
                                        Fraunhofer IIS MPEG Layer-3 Codec (professional)
      Copyright-                                  Copyright (C) 1996-2004 Fraunhofer IIS
                                         all bitrates, mono and stereo codec (professional)
                                          3.04

  [  ADPCM (Microsoft) ]

      ACM:
                                         ADPCM (Microsoft)
      Copyright-                                    , 1992-1996.
                                             Microsoft ADPCM.
                                          4.00

  [  CCITT G.711 A-Law  u-Law (Microsoft) ]

      ACM:
                                         CCITT G.711 A-Law  u-Law (Microsoft)
      Copyright-                                  ()  , 1993-1996.
                                             CCITT G.711 A-Law / u-Law.
                                          4.00

  [  GSM 6.10 (Microsoft) ]

      ACM:
                                         GSM 6.10 (Microsoft)
      Copyright-                                  ()  , 1993-1996.
                                                 ETSI-GSM (European Telecommunications Standards Institute-Groupe Special Mobile)  6.10.
                                          4.00

  [  IMA ADPCM (Microsoft) ]

      ACM:
                                         IMA ADPCM (Microsoft)
      Copyright-                                    , 1992-1996.
                                             IMA ADPCM.
                                          4.00

  [  PCM Microsoft ]

      ACM:
                                         PCM Microsoft
      Copyright-                                    , 1992-1996.
                                                PCM.
                                          5.00


--------[   ]------------------------------------------------------------------------------------------------

    ff_vfw.dll                 1.3.4515.0                          ffdshow video encoder
    iccvid.dll                 1.10.0.11                            Cinepak
    iyuv_32.dll                6.1.7600.16385 (win7_rtm.090713-1255)  Intel Indeo(R) Video YUV 
    lagarith.dll               1.3.27                              Lagarith lossless codec
    msrle32.dll                6.1.7600.16385 (win7_rtm.090713-1255)  Microsoft RLE Compressor
    msvidc32.dll               6.1.7600.16385 (win7_rtm.090713-1255)    Microsoft Video 1
    msyuv.dll                  6.1.7600.16490 (win7_gdr.091218-1705)  Microsoft UYVY Video Decompressor
    rtvcvfw32.dll                                                  RivaTuner Video Codec
    tsbyuv.dll                 6.1.7600.16490 (win7_gdr.091218-1705)  Toshiba Video Codec
    x264vfw.dll                38_2274bm_36885                     x264 H.264 Video Codec
    xvidvfw.dll                                                    Xvid MPEG-4 Video Codec 1.3.2


--------[ MCI ]---------------------------------------------------------------------------------------------------------

  [ AVIVideo ]

      MCI:
                                              AVIVideo
                                                       Windows
                                                 MCI Video  Windows
                                                     Digital Video Device
                                                 mciavi32.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                 
                                                  
                                        
      ''                             
                                      
                                         
                                         
                                            
                                          
                                          
                                

  [ CDAudio ]

      MCI:
                                              CDAudio
                                                     -
                                                 MCI   cdaudio
                                                     CD Audio Device
                                                 mcicda.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                                  
                                        
                                          
                                          

  [ MPEGVideo ]

      MCI:
                                              MPEGVideo
                                                     DirectShow
                                                 MCI DirectShow
                                                     Digital Video Device
                                                 mciqtz32.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                 
                                                  
                                        
      ''                             
                                      
                                         
                                         
                                            
                                          
                                          
                                

  [ Sequencer ]

      MCI:
                                              Sequencer
                                                      MIDI
                                                 MCI   MIDI
                                                     Sequencer Device
                                                 mciseq.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                                  
                                        
                                          
                                          

  [ WaveAudio ]

      MCI:
                                              WaveAudio
                                                     Sound
                                                 MCI   
                                                     Waveform Audio Device
                                                 mciwave.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                                  
                                        
                                          
                                          


--------[   Windows ]-------------------------------------------------------------------------------------

  [ Generic- Compact Flash USB Device ]

     :
                                        Generic- Compact Flash USB Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf

  [ Generic- MS/MS-Pro USB Device ]

     :
                                        Generic- MS/MS-Pro USB Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf

  [ Generic- SD/MMC USB Device ]

     :
                                        Generic- SD/MMC USB Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf

  [ Generic- SM/xD-Picture USB Device ]

     :
                                        Generic- SM/xD-Picture USB Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf

  [ Generic USB Flash Disk USB Device ]

     :
                                        Generic USB Flash Disk USB Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf

  [ TOSHIBA MQ01ABD050 USB Device ]

     :
                                        TOSHIBA MQ01ABD050 USB Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf

     :
                                                   Toshiba Corp., Storage Device Division
                                     http://sdd.toshiba.com

  [ WDC WD5000AAKX-001CA0 ATA Device ]

     :
                                        WDC WD5000AAKX-001CA0 ATA Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf

     :
                                                   Western Digital Corporation
                                     http://www.wdc.com/en

  [ PIONEER DVD-RW  DVR-221L ATA Device ]

     :
                                        PIONEER DVD-RW  DVR-221L ATA Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          cdrom.inf

     :
                                                   Pioneer Corporation
                                     http://www.pioneer-eur.com/eur/productgroups.jsp
       firmware                                 http://www.pioneer.eu/eur/support/

  [ TSSTcorp DVD-ROM SH-D163B ATA Device ]

     :
                                        TSSTcorp DVD-ROM SH-D163B ATA Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          cdrom.inf

      :
                                           Toshiba-Samsung
                                           DVD-ROM
                                               SATA

     :
      DVD-ROM                                           16x
      CD-ROM                                            48x

     :
                                                   Toshiba Samsung Storage Technology
                                     http://www.tsstorage.com/tsst/index_e.html
       firmware                                 http://www.samsungodd.com/eng/LiveUpdate/LiveUpdate.asp

  [ ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf

  [ ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf

     :
      IRQ                                               14
                                                    01F0-01F7
                                                    03F6-03F6

  [ ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf

  [ ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf

     :
      IRQ                                               15
                                                    0170-0177
                                                    0376-0376

  [    PCI IDE ]

     :
                                           PCI IDE
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf

     :
                                                    FF00-FF0F

  [    PCI IDE ]

     :
                                           PCI IDE
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf

     :
      IRQ                                               22
                                                  F7FFFC00-F7FFFFFF
                                                    8000-800F
                                                    9000-9003
                                                    A000-A007
                                                    B000-B003
                                                    C000-C007


--------[   ]--------------------------------------------------------------------------------------------

    C:                                               NTFS          99899       34450       65449    66 %  06F4-779C
    D:                                               NTFS         376937       79223      297714    79 %  9666-2F27
    E:                                                                                                               
    F:                                                                                                               
    G: (SmartBuy500)                                 NTFS         476937      375368      101569    21 %  3462-7056
    H:                                                                                                                     
    I:                                                                                                                     
    J:                                                                                                                     
    K:                                                                                                                     
    L: (MULTIBOOT)                                     FAT32          1921           0        1921   100 %  8CBE-AAF2


--------[   ]--------------------------------------------------------------------------------------------

  [  #1 - WDC WD5000AAKX-001CA0 (465 ) ]

    #1 ()    NTFS                                                             1 MB      100 MB
    #2               NTFS             C:                                            101 MB    99900 MB
    #3               NTFS             D:                                         100001 MB   376938 MB

  [  #6 - TOSHIBA MQ01ABD050 (465 ) ]

    #1               NTFS             G: (SmartBuy500)                                1 MB   476938 MB

  [  #7 - Generic USB Flash Disk (1926 ) ]

    #1 ()    FAT32            L:                                              0 MB     1925 MB


--------[ ATA ]---------------------------------------------------------------------------------------------------------

  [ WDC WD5000AAKX-001CA0 (WD-WMAYUN573283) ]

      ATA:
      ID                                          WDC WD5000AAKX-001CA0
                                           WD-WMAYUN573283
                                                  15.01H15
      World Wide Name                                   5-0014EE-159FBFD6B
                                           SATA-III
                                               : 969021, : 16,   : 63,   : 512
       LBA                                       976773168
                                                   16 
                                           16
       ECC                                         50
                                476940 
       ATA                                      ATA8-ACS

      ATA:
      48-bit LBA                                        
       (APM)                             
      Automatic Acoustic Management                      
      Device Configuration Overlay                      
      DMA Setup Auto-Activate                           , 
      General Purpose Logging                           
      Host Protected Area                               , 
      In-Order Data Delivery                             
      Native Command Queuing                            
      Phy Event Counters                                
                                          , 
      Power-Up In Standby                               , 
      Read Look-Ahead                                   , 
      Release Interrupt                                  
                                       , 
      SMART                                             , 
      SMART Error Logging                               
      SMART Self-Test                                   
      Software Settings Preservation                    , 
      Streaming                                          
      Tagged Command Queuing                             
                                               , 

     SSD:
      Data Set Management                                
      Deterministic Read After TRIM                      
       TRIM                                       

     ATA-:
                                                   Western Digital Corporation
                                     http://www.wdc.com/en
                                     http://www.aida64.com/driver-updates

  [ TOSHIBA MQ01ABD050 (83KLT734T) ]

      ATA:
      ID                                          TOSHIBA MQ01ABD050
                                           83KLT734T
                                                  AX001U
      World Wide Name                                   5-000039-4F1A0781A
                                           SATA-II @ Oxford
                                               : 969021, : 16,   : 63,   : 512
       LBA                                       976773168
                                                   8 
                                           16
       ECC                                         0
                                476940 
       ATA                                      ATA8-ACS

      ATA:
      48-bit LBA                                        
       (APM)                            , 
      Automatic Acoustic Management                      
      Device Configuration Overlay                      
      DMA Setup Auto-Activate                           , 
      General Purpose Logging                           
      Host Protected Area                               , 
      In-Order Data Delivery                             
      Native Command Queuing                            
      Phy Event Counters                                
                                          , 
      Power-Up In Standby                                
      Read Look-Ahead                                   , 
      Release Interrupt                                  
                                       , 
      SMART                                             , 
      SMART Error Logging                               
      SMART Self-Test                                   
      Software Settings Preservation                    , 
      Streaming                                          
      Tagged Command Queuing                             
                                               , 

     SSD:
      Data Set Management                                
      Deterministic Read After TRIM                      
       TRIM                                       

     ATA-:
                                                   Toshiba Corp., Storage Device Division
                                     http://sdd.toshiba.com
                                     http://www.aida64.com/driver-updates


--------[ SMART ]-------------------------------------------------------------------------------------------------------

  [ WDC WD5000AAKX-001CA0 (WD-WMAYUN573283) ]

    01  Raw Read Error Rate                  51   200  200          45  OK:  
    03  Spinup Time                          21   139  139        4025  OK:  
    04  Start/Stop Count                     0    100  100         702  OK:  
    05  Reallocated Sector Count             140  200  200           0  OK:  
    07  Seek Error Rate                      0    100  253           0  OK:  
    09  Power-On Time Count                  0    90   90         7792  OK:  
    0A  Spinup Retry Count                   0    100  100           0  OK:  
    0B  Calibration Retry Count              0    100  100           0  OK:  
    0C  Power Cycle Count                    0    100  100         695  OK:  
    C0  Power-Off Retract Count              0    200  200         127  OK:  
    C1  Load/Unload Cycle Count              0    200  200         574  OK:  
    C2  Temperature                          0    99   83           44  OK:  
    C4  Reallocation Event Count             0    200  200           0  OK:  
    C5  Current Pending Sector Count         0    200  200           0  OK:  
    C6  Offline Uncorrectable Sector Count   0    200  200           0  OK:  
    C7  Ultra ATA CRC Error Rate             0    200  200           5  OK:  
    C8  Write Error Rate                     0    200  200           2  OK:  

  [ TOSHIBA MQ01ABD050 (83KLT734T) ]

    01  Raw Read Error Rate                  50   100  100           0  OK:  
    02  Throughput Performance               50   100  100           0  OK:  
    03  Spinup Time                          1    100  100        1529  OK:  
    04  Start/Stop Count                     0    100  100         215  OK:  
    05  Reallocated Sector Count             50   100  100          72  OK:  
    07  Seek Error Rate                      50   100  100           0  OK:  
    08  Seek Time Performance                50   100  100           0  OK:  
    09  Power-On Time Count                  0    98   98          890  OK:  
    0A  Spinup Retry Count                   30   104  100           0  OK:  
    0C  Power Cycle Count                    0    100  100         154  OK:  
    BF  Mechanical Shock                     0    100  100           2  OK:  
    C0  Power-Off Retract Count              0    100  100          35  OK:  
    C1  Load/Unload Cycle Count              0    100  100        3157  OK:  
    C2  Temperature                          0    100  100  47, 15, 38  OK:  
    C4  Reallocation Event Count             0    100  100           9  OK:  
    C5  Current Pending Sector Count         0    100  100           0  OK:  
    C6  Offline Uncorrectable Sector Count   0    100  100           0  OK:  
    C7  Ultra ATA CRC Error Rate             0    200  200           0  OK:  
    DC  Disk Shift                           0    100  100           0  OK:  
    DE  Loaded Hours                         0    100  100         153  OK:  
    DF  Load/Unload Retry Count              0    100  100           0  OK:  
    E0  Load Friction                        0    100  100           0  OK:  
    E2  Load-In Time                         0    100  100         260  OK:  
    F0  Head Flying Hours                    1    100  100           0  OK:  


--------[  Windows ]------------------------------------------------------------------------------------------------

  [   Realtek RTL8168B/8111B Family PCI-E Gigabit Ethernet NIC (NDIS 6.20) ]

      :
                                            Realtek RTL8168B/8111B Family PCI-E Gigabit Ethernet NIC (NDIS 6.20)
                                           Gigabit Ethernet
                                         90-E6-BA-C0-9C-C4
                                                 
                                      100 Mbps
      MTU                                               1500 
      DHCP-                               08.01.2014 0:00:18
      DHCP-                               08.01.2014 2:00:18
                                            3705266 (3.5 )
                                          924149 (902.5 )

      :
       IP /                                 192.168.0.100 / 255.255.255.0
                                                    192.168.0.1
      DHCP                                              192.168.0.1
      DNS                                               192.168.1.1
      DNS                                               192.168.0.1

      :
                                                   Realtek Semiconductor Corp.
                                     http://www.realtek.com.tw/products/productsView.aspx?Langid=1&PNid=7&PFid=10&Level=3&Conn=2
                                       http://www.realtek.com.tw/downloads
                                     http://www.aida64.com/driver-updates


--------[  PCI / PnP ]----------------------------------------------------------------------------------------------

    Realtek RTL8168B/8111B PCI-E Gigabit Ethernet Adapter (PHY: Realtek RTL8211/8212)  PCI


--------[ IAM ]---------------------------------------------------------------------------------------------------------

  [ Microsoft Communities ]

      :
                                        Microsoft Communities
      ID                                   account{08F91603-7B43-4CD4-8EF6-03145948E7A9}.oeaccount
                                         ( )
                                                (IE  )
      NNTP-                                       msnews.microsoft.com

      :
        NNTP                                
        NNTP                     
        NNTP                        
         NNTP             
       NNTP                
       NNTP   HTML                         

  [ Active Directory ]

      :
                                        Active Directory
      ID                                   account{32B76516-EC20-45CF-8E71-E945BB73D9A9}.oeaccount
                                        LDAP
                                                (IE  )
      LDAP-                                       NULL:3268
        LDAP                             NULL
        LDAP                               NULL
        LDAP                               1 

      :
        LDAP                      
        LDAP                     
        LDAP                        
         LDAP                     

  [    VeriSign ]

      :
                                           VeriSign
      ID                                   account{1B3BB2F3-72C0-4330-A1A2-C3EFE50B2AEE}.oeaccount
                                        LDAP
                                                (IE  )
      LDAP-                                       directory.verisign.com
      LDAP URL                                          http://www.verisign.com
        LDAP                               NULL
        LDAP                               1 

      :
        LDAP                      
        LDAP                     
        LDAP                        
         LDAP                     


--------[  ]----------------------------------------------------------------------------------------------------

     :
                                        http://go.microsoft.com/fwlink/?LinkId=69157
                                          http://go.microsoft.com/fwlink/?LinkId=54896
                               

     :
                                            

    LAN-:
                                            


--------[  ]----------------------------------------------------------------------------------------------------

                  0.0.0.0          0.0.0.0      192.168.0.1  20   192.168.0.100 ()
                127.0.0.0        255.0.0.0        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
                127.0.0.1  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
          127.255.255.255  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
              192.168.0.0    255.255.255.0    192.168.0.100  276  192.168.0.100 ()
            192.168.0.100  255.255.255.255    192.168.0.100  276  192.168.0.100 ()
            192.168.0.255  255.255.255.255    192.168.0.100  276  192.168.0.100 ()
                224.0.0.0        240.0.0.0        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
                224.0.0.0        240.0.0.0    192.168.0.100  276  192.168.0.100 ()
          255.255.255.255  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
          255.255.255.255  255.255.255.255    192.168.0.100  276  192.168.0.100 ()


--------[ IE Cookie ]---------------------------------------------------------------------------------------------------

    2014-01-07 04:38:21  @onlinestores.metaservices.microsoft.com/serviceswitching/
    2014-01-07 15:26:13  @objorka.com/


--------[   ]--------------------------------------------------------------------------------------------

    2014-01-06 16:36:58  %D0%90%D0%B4%D0%BC%D0%B8%D0%BD%D0%B8%D1%81%D1%82%D1%80%D0%B0%D1%82%D0%BE%D1%80@mshelp://windows/?id=d063548a-3fc9-4723-99f3-b12a0c4354a8
    2014-01-07 00:32:38  %D0%90%D0%B4%D0%BC%D0%B8%D0%BD%D0%B8%D1%81%D1%82%D1%80%D0%B0%D1%82%D0%BE%D1%80@http://www.nvidia.ru/object/eve-gfe-holiday-bundle-gsync-banners-ru.html?t=D:1244L:1049O:6.1_0LC:rus
    2014-01-07 04:38:03  %D0%90%D0%B4%D0%BC%D0%B8%D0%BD%D0%B8%D1%81%D1%82%D1%80%D0%B0%D1%82%D0%BE%D1%80@file:///L:/Starshaya.Sestra.SATRip.[www.riper.am].avi
    2014-01-07 15:34:09  %D0%90%D0%B4%D0%BC%D0%B8%D0%BD%D0%B8%D1%81%D1%82%D1%80%D0%B0%D1%82%D0%BE%D1%80@mshelp://windows/?id=9ad405d9-f05c-4317-acc7-08d13867e614
    2014-01-07 18:24:36  %D0%90%D0%B4%D0%BC%D0%B8%D0%BD%D0%B8%D1%81%D1%82%D1%80%D0%B0%D1%82%D0%BE%D1%80@file:///D:/Program%20Files/Steam/SteamApps/common/Bioshock/Builds/Release/Version.ini
    2014-01-07 21:22:31  %D0%90%D0%B4%D0%BC%D0%B8%D0%BD%D0%B8%D1%81%D1%82%D1%80%D0%B0%D1%82%D0%BE%D1%80@file:///D:/%D0%97%D0%B0%D0%B3%D1%80%D1%83%D0%B7%D0%BA%D0%B8/interny.160.seriya.WEBDL720P.FreeRutor.mkv


--------[  DirectX ]-----------------------------------------------------------------------------------------------

    amstream.dll                              6.06.7600.16385   Final Retail                         70656  14.07.2009 5:14:53
    bdaplgin.ax                               6.01.7600.16385   Final Retail                         74240  14.07.2009 5:14:10
    d3d8.dll                                  6.01.7600.16385   Final Retail                    1036800  14.07.2009 5:15:08
    d3d8thk.dll                               6.01.7600.16385   Final Retail                      11264  14.07.2009 5:15:08
    d3d9.dll                                  6.01.7600.16385   Final Retail                    1826816  14.07.2009 5:15:08
    d3dim.dll                                 6.01.7600.16385   Final Retail                     386048  14.07.2009 5:15:08
    d3dim700.dll                              6.01.7600.16385   Final Retail                     817664  14.07.2009 5:15:08
    d3dramp.dll                               6.01.7600.16385   Final Retail                     593920  14.07.2009 5:15:08
    d3dxof.dll                                6.01.7600.16385   Final Retail                      53760  14.07.2009 5:15:08
    ddraw.dll                                 6.01.7600.16385   Final Retail                        531968  14.07.2009 5:15:10
    ddrawex.dll                               6.01.7600.16385   Final Retail                      30208  14.07.2009 5:15:10
    devenum.dll                               6.06.7600.16385   Final Retail                         66560  14.07.2009 5:15:10
    dinput.dll                                6.01.7600.16385   Final Retail                        136704  14.07.2009 5:15:11
    dinput8.dll                               6.01.7600.16385   Final Retail                        145408  14.07.2009 5:15:11
    dmband.dll                                6.01.7600.16385   Final Retail                      30720  14.07.2009 5:15:12
    dmcompos.dll                              6.01.7600.16385   Final Retail                      63488  14.07.2009 5:15:12
    dmime.dll                                 6.01.7600.16385   Final Retail                     179712  14.07.2009 5:15:12
    dmloader.dll                              6.01.7600.16385   Final Retail                      38400  14.07.2009 5:15:12
    dmscript.dll                              6.01.7600.16385   Final Retail                      86016  14.07.2009 5:15:12
    dmstyle.dll                               6.01.7600.16385   Final Retail                     105984  14.07.2009 5:15:12
    dmsynth.dll                               6.01.7600.16385   Final Retail                     105472  14.07.2009 5:15:12
    dmusic.dll                                6.01.7600.16385   Final Retail                        101376  14.07.2009 5:15:12
    dplaysvr.exe                              6.01.7600.16385   Final Retail                         29184  14.07.2009 5:14:18
    dplayx.dll                                6.01.7600.16385   Final Retail                     213504  14.07.2009 5:15:12
    dpmodemx.dll                              6.01.7600.16385   Final Retail                         23040  14.07.2009 5:15:12
    dpnaddr.dll                               6.01.7600.16385   Final Retail                       2048  14.07.2009 5:04:52
    dpnet.dll                                 6.01.7600.17157   Final Retail                        376832  02.11.2012 8:48:28
    dpnhpast.dll                              6.01.7600.16385   Final Retail                       7168  14.07.2009 5:15:12
    dpnhupnp.dll                              6.01.7600.16385   Final Retail                       7168  14.07.2009 5:15:12
    dpnlobby.dll                              6.01.7600.16385   Final Retail                       2560  14.07.2009 5:04:52
    dpnsvr.exe                                6.01.7600.16385   Final Retail                         33280  14.07.2009 5:14:18
    dpwsockx.dll                              6.01.7600.16385   Final Retail                         44032  14.07.2009 5:15:12
    dsdmo.dll                                 6.01.7600.16385   Final Retail                     173568  14.07.2009 5:15:13
    dsound.dll                                6.01.7600.16385   Final Retail                        453632  14.07.2009 5:15:13
    dswave.dll                                6.01.7600.16385   Final Retail                      20992  14.07.2009 5:15:13
    dxapi.sys                                 6.01.7600.16385   Final Retail                      13312  14.07.2009 3:25:26
    dxdiagn.dll                               6.01.7600.16385   Final Retail                        210432  14.07.2009 5:15:13
    dxmasf.dll                                12.00.7600.16385  Final Retail                       4096  14.07.2009 5:16:14
    encapi.dll                                6.01.7600.16385   Final Retail                      20992  14.07.2009 5:15:14
    gcdef.dll                                 6.01.7600.16385   Final Retail                        120832  14.07.2009 5:15:22
    iac25_32.ax                               2.00.0005.0053    Final Retail                        197632  14.07.2009 5:14:10
    ir41_32.ax                                4.51.0016.0003    Final Retail                        839680  14.07.2009 5:14:10
    ir41_qc.dll                               4.30.0062.0002    Final Retail                     120320  14.07.2009 5:15:34
    ir41_qcx.dll                              4.30.0062.0002    Final Retail                     120320  14.07.2009 5:15:34
    ir50_32.dll                               5.2562.0015.0055  Final Retail                        746496  14.07.2009 5:15:34
    ir50_qc.dll                               5.00.0063.0048    Final Retail                     200192  14.07.2009 5:15:34
    ir50_qcx.dll                              5.00.0063.0048    Final Retail                     200192  14.07.2009 5:15:34
    ivfsrc.ax                                 5.10.0002.0051    Final Retail                        146944  14.07.2009 5:14:10
    joy.cpl                                   6.01.7600.16385   Final Retail                        138240  14.07.2009 5:14:09
    ks.sys                                    6.01.7600.16385   Final Retail                        190976  14.07.2009 3:45:15
    ksproxy.ax                                6.01.7600.16385   Final Retail                        194048  14.07.2009 5:14:11
    kstvtune.ax                               6.01.7600.16385   Final Retail                         84480  14.07.2009 5:14:11
    ksuser.dll                                6.01.7600.16385   Final Retail                          4608  14.07.2009 5:15:35
    kswdmcap.ax                               6.01.7600.16385   Final Retail                        107008  14.07.2009 5:14:11
    ksxbar.ax                                 6.01.7600.16385   Final Retail                         48640  14.07.2009 5:14:11
    mciqtz32.dll                              6.06.7600.16385   Final Retail                         36352  14.07.2009 5:15:37
    mfc40.dll                                 4.01.0000.6151    Beta Retail                         954752  31.08.2010 8:32:30
    mfc42.dll                                 6.06.8064.0000    Beta Retail                        1137664  11.03.2011 9:40:24
    Microsoft.DirectX.AudioVideoPlayback.dll  5.04.0000.2904    Final Retail                      53248  07.01.2014 23:15:18
    Microsoft.DirectX.Diagnostics.dll         5.04.0000.2904    Final Retail                      12800  07.01.2014 23:15:19
    Microsoft.DirectX.Direct3D.dll            9.05.0132.0000    Final Retail                     473600  07.01.2014 23:15:20
    Microsoft.DirectX.Direct3DX.dll           5.04.0000.3900    Final Retail                    2676224  07.01.2014 23:15:12
    Microsoft.DirectX.Direct3DX.dll           9.04.0091.0000    Final Retail                    2846720  07.01.2014 23:15:14
    Microsoft.DirectX.Direct3DX.dll           9.05.0132.0000    Final Retail                     563712  07.01.2014 23:15:14
    Microsoft.DirectX.Direct3DX.dll           9.06.0168.0000    Final Retail                     567296  07.01.2014 23:15:15
    Microsoft.DirectX.Direct3DX.dll           9.07.0239.0000    Final Retail                     576000  07.01.2014 23:15:15
    Microsoft.DirectX.Direct3DX.dll           9.08.0299.0000    Final Retail                     577024  07.01.2014 23:15:16
    Microsoft.DirectX.Direct3DX.dll           9.09.0376.0000    Final Retail                     577536  07.01.2014 23:15:16
    Microsoft.DirectX.Direct3DX.dll           9.10.0455.0000    Final Retail                     577536  07.01.2014 23:15:17
    Microsoft.DirectX.Direct3DX.dll           9.11.0519.0000    Final Retail                     578560  07.01.2014 23:15:18
    Microsoft.DirectX.Direct3DX.dll           9.12.0589.0000    Final Retail                     578560  07.01.2014 23:15:20
    Microsoft.DirectX.DirectDraw.dll          5.04.0000.2904    Final Retail                     145920  07.01.2014 23:15:21
    Microsoft.DirectX.DirectInput.dll         5.04.0000.2904    Final Retail                     159232  07.01.2014 23:15:21
    Microsoft.DirectX.DirectPlay.dll          5.04.0000.2904    Final Retail                     364544  07.01.2014 23:15:21
    Microsoft.DirectX.DirectSound.dll         5.04.0000.2904    Final Retail                     178176  07.01.2014 23:15:21
    Microsoft.DirectX.dll                     5.04.0000.2904    Final Retail                     223232  07.01.2014 23:15:18
    mpeg2data.ax                              6.06.7600.16867   Final Retail                         72704  17.08.2011 8:22:23
    mpg2splt.ax                               6.06.7600.16724   Final Retail                     199680  23.12.2010 9:24:02
    msdmo.dll                                 6.06.7600.16385   Final Retail                      30208  14.07.2009 5:15:43
    msdvbnp.ax                                6.06.7600.16867   Final Retail                         59904  17.08.2011 8:22:23
    mskssrv.sys                               6.01.7600.16385   Final Retail                          8320  14.07.2009 3:45:08
    mspclock.sys                              6.01.7600.16385   Final Retail                          5888  14.07.2009 3:45:08
    mspqm.sys                                 6.01.7600.16385   Final Retail                          5504  14.07.2009 3:45:07
    mstee.sys                                 6.01.7600.16385   Final Retail                          6144  14.07.2009 3:45:08
    msvidctl.dll                              6.05.7600.16385   Final Retail                       2291712  14.07.2009 5:15:50
    msyuv.dll                                 6.01.7600.16490   Final Retail                      22016  19.12.2009 13:02:46
    pid.dll                                   6.01.7600.16385   Final Retail                      36352  14.07.2009 5:16:12
    psisdecd.dll                              6.06.7600.16867   Final Retail                        465408  17.08.2011 8:26:02
    psisrndr.ax                               6.06.7600.16867   Final Retail                         75776  17.08.2011 8:22:23
    qasf.dll                                  12.00.7600.16385  Final Retail                     206848  14.07.2009 5:16:12
    qcap.dll                                  6.06.7600.16385   Final Retail                        190976  14.07.2009 5:16:12
    qdv.dll                                   6.06.7600.16385   Final Retail                        283136  14.07.2009 5:16:12
    qdvd.dll                                  6.06.7600.16905   Final Retail                        514560  26.10.2011 8:28:25
    qedit.dll                                 6.06.7600.16385   Final Retail                        509440  14.07.2009 5:16:12
    qedwipes.dll                              6.06.7600.16385   Final Retail                     733184  14.07.2009 5:09:35
    quartz.dll                                6.06.7600.16905   Final Retail                       1328640  26.10.2011 8:28:26
    stream.sys                                6.01.7600.16385   Final Retail                         53632  14.07.2009 3:50:57
    swenum.sys                                6.01.7600.16385   Final Retail                         12240  14.07.2009 5:19:10
    vbisurf.ax                                6.01.7600.16385   Final Retail                      33280  14.07.2009 5:14:11
    vfwwdm32.dll                              6.01.7600.16385   Final Retail                         56832  14.07.2009 5:16:17
    wsock32.dll                               6.01.7600.16385   Final Retail                         15360  14.07.2009 5:16:20


--------[ DirectX -  ]---------------------------------------------------------------------------------------------

  [   ]

     DirectDraw:
        DirectDraw                           display
        DirectDraw                       
                                       nvd3dum.dll (9.18.13.3182 - nVIDIA Detonator 31.82)
                                      NVIDIA GeForce GTX 550 Ti

     Direct3D:
      /                         1024  / 916 
                                8, 16, 32
        Z-                          16, 24, 32
      Multisample Anti-Aliasing Modes                   MSAA 2x, MSAA 4x, MSAA 8x, CSAA 8x, CSAA 8xQ, CSAA 16x, CSAA 16xQ
                               1 x 1
                              16384 x 16384
                              5.0
        DirectX                      DirectX v11.0

     Direct3D:
      Additive Texture Blending                         
      AGP Texturing                                     
      Anisotropic Filtering                             
      Automatic Mipmap Generation                       
      Bilinear Filtering                                
      Compute Shader                                    
      Cubic Environment Mapping                         
      Cubic Filtering                                    
      Decal-Alpha Texture Blending                      
      Decal Texture Blending                            
      DirectX Texture Compression                        
      DirectX Volumetric Texture Compression             
      Dithering                                         
      Dot3 Texture Blending                             
      Double-Precision Floating-Point                   
      Driver Concurrent Creates                         
      Driver Command Lists                              
      Dynamic Textures                                  
      Edge Anti-Aliasing                                
      Environmental Bump Mapping                        
      Environmental Bump Mapping + Luminance            
      Factor Alpha Blending                             
      Geometric Hidden-Surface Removal                   
      Geometry Shader                                   
      Guard Band                                        
      Hardware Scene Rasterization                      
      Hardware Transform & Lighting                     
      Legacy Depth Bias                                 
      Mipmap LOD Bias Adjustments                       
      Mipmapped Cube Textures                           
      Mipmapped Volume Textures                         
      Modulate-Alpha Texture Blending                   
      Modulate Texture Blending                         
      Non-Square Textures                               
      N-Patches                                          
      Perspective Texture Correction                    
      Point Sampling                                    
      Projective Textures                               
      Quintic Bezier Curves & B-Splines                  
      Range-Based Fog                                   
      Rectangular & Triangular Patches                   
      Rendering In Windowed Mode                        
      Scissor Test                                      
      Slope-Scale Based Depth Bias                      
      Specular Flat Shading                             
      Specular Gouraud Shading                          
      Specular Phong Shading                             
      Spherical Mapping                                 
      Stencil Buffers                                   
      Sub-Pixel Accuracy                                
      Subtractive Texture Blending                      
      Table Fog                                         
      Texture Alpha Blending                            
      Texture Clamping                                  
      Texture Mirroring                                 
      Texture Transparency                              
      Texture Wrapping                                  
      Triangle Culling                                   
      Trilinear Filtering                               
      Two-Sided Stencil Test                            
      Vertex Alpha Blending                             
      Vertex Fog                                        
      Vertex Tweening                                    
      Volume Textures                                   
      W-Based Fog                                       
      W-Buffering                                        
      Z-Based Fog                                       
      Z-Bias                                            
      Z-Test                                            

      FourCC:
      3x11                                              
      3x16                                              
      AI44                                              
      AIP8                                              
      ATOC                                              
      AV12                                              
      AYUV                                              
      NV12                                              
      NV24                                              
      NVDB                                              
      NVDP                                              
      NVMD                                              
      PLFF                                              
      SSAA                                              
      UYVY                                              
      YUY2                                              
      YV12                                              

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates


--------[ DirectX -  ]----------------------------------------------------------------------------------------------

  [    ]

     DirectSound:
                                        
                                          
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    

  [  (Realtek High Definition Audio) ]

     DirectSound:
                                       (Realtek High Definition Audio)
                                          {0.0.0.00000000}.{0915f372-9eba-40cf-a584-42665c1d1831}
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    

  [ Realtek Digital Output (Realtek High Definition Audio) ]

     DirectSound:
                                      Realtek Digital Output (Realtek High Definition Audio)
                                          {0.0.0.00000000}.{828ff51d-978b-47fb-9046-bd8bfb12bb68}
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    

  [ Realtek Digital Output(Optical) (Realtek High Definition Audio) ]

     DirectSound:
                                      Realtek Digital Output(Optical) (Realtek High Definition Audio)
                                          {0.0.0.00000000}.{8c353d88-9d8d-4c10-8aab-6c8470732c62}
                                         1
      ./.          100 / 200000 
                             8 , 16 , , 
                             8 , 16 , , 
       /                   1 / 0
       /        1 / 0
       /           1 / 0
       /   3D-                0 / 0
       /    3D-    0 / 0
       /    3D-       0 / 0

     DirectSound:
                                
                                      
                                    
      DirectSound3D                                      
      Creative EAX 1.0                                   
      Creative EAX 2.0                                   
      Creative EAX 3.0                                   
      Creative EAX 4.0                                   
      Creative EAX 5.0                                   
      I3DL2                                              
      Sensaura ZoomFX                                    


--------[ DirectX -  ]----------------------------------------------------------------------------------------------

  [  ]

     DirectInput:
                                      
                                           
                                        
                                                     3
      /                                    3

     DirectInput:
                                      
      Alias Device                                      
      Polled Device                                     
      Polled Data Format                                
      Attack Force Feedback                              
      Deadband Force Feedback                            
      Fade Force Feedback                                
      Force Feedback                                     
      Saturation Force Feedback                          
      +/- Force Feedback Coefficients                    
      +/- Force Feedback Saturation                      

  [  ]

     DirectInput:
                                      
                                           
                                        
      /                                    128

     DirectInput:
                                      
      Alias Device                                      
      Polled Device                                     
      Polled Data Format                                
      Attack Force Feedback                              
      Deadband Force Feedback                            
      Fade Force Feedback                                
      Force Feedback                                     
      Saturation Force Feedback                          
      +/- Force Feedback Coefficients                    
      +/- Force Feedback Saturation                      

  [ USB Keyboard ]

     DirectInput:
                                      USB Keyboard
                                           
                                        
      /                                    573

     DirectInput:
                                      
      Alias Device                                      
      Polled Device                                     
      Polled Data Format                                
      Attack Force Feedback                              
      Deadband Force Feedback                            
      Fade Force Feedback                                
      Force Feedback                                     
      Saturation Force Feedback                          
      +/- Force Feedback Coefficients                    
      +/- Force Feedback Saturation                      

  [ USB Keyboard ]

     DirectInput:
                                      USB Keyboard
                                           
                                        
      /                                    3

     DirectInput:
                                      
      Alias Device                                      
      Polled Device                                     
      Polled Data Format                                
      Attack Force Feedback                              
      Deadband Force Feedback                            
      Fade Force Feedback                                
      Force Feedback                                     
      Saturation Force Feedback                          
      +/- Force Feedback Coefficients                    
      +/- Force Feedback Saturation                      


--------[  Windows ]------------------------------------------------------------------------------------------

  [  ]

    DVD  CD-ROM :
      PIONEER DVD-RW  DVR-221L ATA Device               6.1.7600.16385
      TSSTcorp DVD-ROM SH-D163B ATA Device              6.1.7600.16385

    IDE ATA/ATAPI :
      ATA Channel 0                                     6.1.7600.16385
      ATA Channel 0                                     6.1.7600.16385
      ATA Channel 1                                     6.1.7600.16385
      ATA Channel 1                                     6.1.7600.16385
         PCI IDE      6.1.7600.16385
         PCI IDE      6.1.7600.16385

    Unknown:
                                              

    :
      NVIDIA GeForce GTX 550 Ti                         9.18.13.3182

     :
      Generic- Compact Flash USB Device                 6.1.7600.16385
      Generic- MS/MS-Pro USB Device                     6.1.7600.16385
      Generic- SD/MMC USB Device                        6.1.7600.16385
      Generic- SM/xD-Picture USB Device                 6.1.7600.16385
      Generic USB Flash Disk USB Device                 6.1.7600.16385
      TOSHIBA MQ01ABD050 USB Device                     6.1.7600.16385
      WDC WD5000AAKX-001CA0 ATA Device                  6.1.7600.16385

      :
      adgnetworktdi                                     
      Ancillary Function Driver for Winsock             
      AODDriver4.2.0                                    
      Beep                                              
      CNG                                               
      FinalWire AIDA64 Kernel Driver                    
      Hardware Policy Driver                            
      HTTP                                              
      Kaspersky Anti-Virus NDIS 6 Filter                
      Kernel Mode Driver Frameworks service             
      kl1                                               
      klpd                                              
      kltdi                                             
      kneps                                             
      KSecDD                                            
      KSecPkg                                           
      LDDM Graphics Subsystem                           
      Link-Layer Topology Discovery Mapper I/O Driver   
      Link-Layer Topology Discovery Responder           
      MSICDSetup                                        
      msisadrv                                          
      NDProxy                                           
      NETBT                                             
      NSI proxy service driver.                         
      Null                                              
      Parvdm                                            
      PEAUTH                                            
      Performance Counters for Windows Driver           
      PnkBstrK                                          
      RDP Encoder Mirror Driver                         
      RDPCDD                                            
      Reflector Display Driver used to gain access to graphics data
      RTCore32                                          
      Security Driver                                   
      Security Processor Loader Driver                  
      System Attribute Cache                            
      TCP/IP Registry Compatibility                     
      User Mode Driver Frameworks Platform Driver       
      VgaSave                                           
      WFP Lightweight Filter                            
            
                              
                               
                                 
         Windows           
        NetIO Legacy TDI                
        TCP/IP                          
         IPv6 ARP               
          Bitlocker        
        (CLFS)                               
        QoS                           
        NDIS                            
                               

    ,    :
      NVIDIA High Definition Audio                      1.3.26.4
      NVIDIA High Definition Audio                      1.3.26.4
      NVIDIA High Definition Audio                      1.3.26.4
      NVIDIA High Definition Audio                      1.3.26.4
      NVIDIA Virtual Audio Device (Wave Extensible) (WDM)1.2.19.0
      Realtek High Definition Audio                     6.0.1.7083

    :
       HID                                    6.1.7600.16385

    :
      ACPI    x86                        6.1.7600.16385

     USB:
         USB                   6.1.7600.16385
         USB                   6.1.7600.16385
         USB                   6.1.7600.16385
       USB-                         6.1.7600.16385
       USB-                         6.1.7600.16385
       USB-                         6.1.7600.16385
       USB-                         6.1.7600.16385
       USB-                         6.1.7600.16385
       USB-                         6.1.7600.16385
       USB-                         6.1.7600.16385
       USB                           6.1.7600.16385
       OpenHCD USB -           6.1.7600.16385
       OpenHCD USB -           6.1.7600.16385
       OpenHCD USB -           6.1.7600.16385
       OpenHCD USB -           6.1.7600.16385
       OpenHCD USB -           6.1.7600.16385
        PCI - USB - 6.1.7600.16385
        PCI - USB - 6.1.7600.16385

    :
        PnP                         6.1.7600.16385

        :
      HID-                               6.1.7600.16385

     :
      H:\                                               6.1.7600.16385
      I:\                                               6.1.7600.16385
      J:\                                               6.1.7600.16385
      K:\                                               6.1.7600.16385
      MULTIBOOT                                         6.1.7600.16385

     (COM  LPT):
        (LPT1)                              6.1.7600.16385
        (COM1)                      6.1.7600.16385

    :
      AMD Athlon(tm) II X3 425 Processor                6.1.7600.16385
      AMD Athlon(tm) II X3 425 Processor                6.1.7600.16385
      AMD Athlon(tm) II X3 425 Processor                6.1.7600.16385

     :
      Teredo Tunneling Pseudo-Interface                 6.1.7600.16385
      WAN Miniport (IKEv2)                              6.1.7600.16385
       Microsoft ISATAP                          6.1.7600.16385
       WAN (IP)                                 6.1.7600.16385
       WAN (IPv6)                               6.1.7600.16385
       WAN (L2TP)                               6.1.7600.16385
       WAN (PPPoE)                              6.1.7600.16385
       WAN (PPTP)                               6.1.7600.16385
      - WAN (SSTP)                              6.1.7600.16385
       WAN ( )                    6.1.7600.16385
        Realtek RTL8168B/8111B Family PCI-E Gigabit Ethernet NIC (NDIS 6.20)7.2.1127.2008

     :
      CMOS                                         6.1.7600.16385
      Microsoft ACPI-                 6.1.7600.16385
      Microsoft System Management BIOS           6.1.7600.16385
      Remote Desktop Device Redirector Bus              6.1.7600.16385
      UMBus                    6.1.7600.16385
      UMBus                                6.1.7600.16385
      UMBus                                6.1.7600.16385
                               6.1.7600.16385
                                       6.1.7600.16385
                               6.1.7600.16385
                                          6.1.7600.16385
                      6.1.7600.16385
                            6.1.7600.16385
          ()6.1.7600.16385
                               6.1.7600.16385
         ACPI Microsoft Windows   6.1.7600.16385
        ACPI                               6.1.7600.16385
       High Definition Audio (Microsoft)      6.1.7600.16385
       High Definition Audio (Microsoft)      6.1.7600.16385
       SMBus    - ATI6.1.7600.16385
                         6.1.7600.16385
        PCI    - ATI6.1.7600.16385
                        6.1.7600.16385
                            6.1.7600.16385
         Plug and Play 6.1.7600.16385
                     6.1.7600.16385
                                   6.1.7600.16385
                                   6.1.7600.16385
                                   6.1.7600.16385
                                   6.1.7600.16385
                                          6.1.7600.16385
                                         6.1.7600.16385
        PCI  - CPU                       6.1.7600.16385
        PCI  - CPU                       6.1.7600.16385
        PCI  - CPU                       6.1.7600.16385
        PCI  - CPU                       6.1.7600.16385
        PCI  - CPU                       6.1.7600.16385
        PCI  - CPU                       6.1.7600.16385
        PCI - ISA                        6.1.7600.16385
        PCI - PCI                        6.1.7600.16385
        PCI - PCI                        6.1.7600.16385
         ACPI          6.1.7600.16385
       PCI                                          6.1.7600.16385

        :
                           6.1.7600.16385
                           6.1.7600.16385
                           6.1.7600.16385
                           6.1.7600.16385
                           6.1.7600.16385

      :
                                        6.1.7600.16385
                                        6.1.7600.16385
                                        6.1.7600.16385
                                        6.1.7600.16385
                                        6.1.7600.16385
                                        6.1.7600.16385
                                        6.1.7600.16385
                                        6.1.7600.16385
                                        6.1.7600.16385

     HID (Human Interface Devices):
      HID-               6.1.7600.16385
      HID-                         6.1.7600.16385
      USB-                               6.1.7600.16385
      USB-                               6.1.7600.16385
      USB-                               6.1.7600.16385

  [ DVD  CD-ROM  / PIONEER DVD-RW  DVR-221L ATA Device ]

     :
                                        PIONEER DVD-RW  DVR-221L ATA Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          cdrom.inf
       ID                                     IDE\CdRomPIONEER_DVD-RW__DVR-221L________________1.00____
                                     Channel 0, Target 1, Lun 0

     :
                                                   Pioneer Corporation
                                     http://www.pioneer-eur.com/eur/productgroups.jsp
       firmware                                 http://www.pioneer.eu/eur/support/
                                     http://www.aida64.com/driver-updates

  [ DVD  CD-ROM  / TSSTcorp DVD-ROM SH-D163B ATA Device ]

     :
                                        TSSTcorp DVD-ROM SH-D163B ATA Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          cdrom.inf
       ID                                     IDE\CdRomTSSTcorp_DVD-ROM_SH-D163B_______________SB00____
                                     Channel 1, Target 1, Lun 0

     :
                                                   Toshiba Samsung Storage Technology
                                     http://www.tsstorage.com/tsst/index_e.html
       firmware                                 http://www.samsungodd.com/eng/LiveUpdate/LiveUpdate.asp
                                     http://www.aida64.com/driver-updates

  [ IDE ATA/ATAPI  / ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf
       ID                                     1002-4390
                                     Channel 0

  [ IDE ATA/ATAPI  / ATA Channel 0 ]

     :
                                        ATA Channel 0
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf
       ID                                     1002-439c
                                     Channel 0

     :
      IRQ                                               14
                                                    01F0-01F7
                                                    03F6-03F6

  [ IDE ATA/ATAPI  / ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf
       ID                                     1002-4390
                                     Channel 1

  [ IDE ATA/ATAPI  / ATA Channel 1 ]

     :
                                        ATA Channel 1
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf
       ID                                     1002-439c
                                     Channel 1

     :
      IRQ                                               15
                                                    0170-0177
                                                    0376-0376

  [ IDE ATA/ATAPI  /    PCI IDE ]

     :
                                           PCI IDE
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf
       ID                                     PCI\VEN_1002&DEV_439C&SUBSYS_82EF1043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,20,1)
      PCI-                                    ATI SB700 - IDE Controller

     :
                                                    FF00-FF0F

  [ IDE ATA/ATAPI  /    PCI IDE ]

     :
                                           PCI IDE
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          mshdc.inf
       ID                                     PCI\VEN_1002&DEV_4390&SUBSYS_82EF1043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,17,0)
      PCI-                                    ATI SB700 - SATA Controller

     :
      IRQ                                               22
                                                  F7FFFC00-F7FFFFFF
                                                    8000-800F
                                                    9000-9003
                                                    A000-A007
                                                    B000-B003
                                                    C000-C007

  [ Unknown / Unknown ]

     :
                                        Unknown
       ID                                     ACPI\ATK0110
      PnP-                                    Asus ATK-110 ACPI Utility

  [  / NVIDIA GeForce GTX 550 Ti ]

     :
                                        NVIDIA GeForce GTX 550 Ti
                                            11.11.2013
                                          9.18.13.3182
                                       NVIDIA
      INF-                                          oem5.inf
       ID                                     PCI\VEN_10DE&DEV_1244&SUBSYS_809D1462&REV_A1
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(1,0,0)
      PCI-                                    NVIDIA GeForce GTX 550 Ti [10DE-1244] [NoDB]

     :
      IRQ                                               18
                                                  000A0000-000BFFFF
                                                  D4000000-D7FFFFFF
                                                  D8000000-DFFFFFFF
                                                  F8000000-F9FFFFFF
                                                    03B0-03BB
                                                    03C0-03DF
                                                    DC00-DC7F

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [   / Generic- Compact Flash USB Device ]

     :
                                        Generic- Compact Flash USB Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf
       ID                                     USBSTOR\DiskGeneric-Compact_Flash___1.00

  [   / Generic- MS/MS-Pro USB Device ]

     :
                                        Generic- MS/MS-Pro USB Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf
       ID                                     USBSTOR\DiskGeneric-MS/MS-Pro_______1.00

  [   / Generic- SD/MMC USB Device ]

     :
                                        Generic- SD/MMC USB Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf
       ID                                     USBSTOR\DiskGeneric-SD/MMC__________1.00

  [   / Generic- SM/xD-Picture USB Device ]

     :
                                        Generic- SM/xD-Picture USB Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf
       ID                                     USBSTOR\DiskGeneric-SM/xD-Picture___1.00

  [   / Generic USB Flash Disk USB Device ]

     :
                                        Generic USB Flash Disk USB Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf
       ID                                     USBSTOR\DiskGeneric_USB_Flash_Disk__8.07

  [   / TOSHIBA MQ01ABD050 USB Device ]

     :
                                        TOSHIBA MQ01ABD050 USB Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf
       ID                                     USBSTOR\DiskTOSHIBA_MQ01ABD050______AX00

     :
                                                   Toshiba Corp., Storage Device Division
                                     http://sdd.toshiba.com
                                     http://www.aida64.com/driver-updates

  [   / WDC WD5000AAKX-001CA0 ATA Device ]

     :
                                        WDC WD5000AAKX-001CA0 ATA Device
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          disk.inf
       ID                                     IDE\DiskWDC_WD5000AAKX-001CA0___________________15.01H15
                                     Channel 1, Target 0, Lun 0

     :
                                                   Western Digital Corporation
                                     http://www.wdc.com/en
                                     http://www.aida64.com/driver-updates

  [    / adgnetworktdi ]

     :
                                        adgnetworktdi

  [    / Ancillary Function Driver for Winsock ]

     :
                                        Ancillary Function Driver for Winsock

  [    / AODDriver4.2.0 ]

     :
                                        AODDriver4.2.0

  [    / Beep ]

     :
                                        Beep

  [    / CNG ]

     :
                                        CNG

  [    / FinalWire AIDA64 Kernel Driver ]

     :
                                        FinalWire AIDA64 Kernel Driver

  [    / Hardware Policy Driver ]

     :
                                        Hardware Policy Driver

  [    / HTTP ]

     :
                                        HTTP

  [    / Kaspersky Anti-Virus NDIS 6 Filter ]

     :
                                        Kaspersky Anti-Virus NDIS 6 Filter

  [    / Kernel Mode Driver Frameworks service ]

     :
                                        Kernel Mode Driver Frameworks service

  [    / kl1 ]

     :
                                        kl1

  [    / klpd ]

     :
                                        klpd

  [    / kltdi ]

     :
                                        kltdi

  [    / kneps ]

     :
                                        kneps

  [    / KSecDD ]

     :
                                        KSecDD

  [    / KSecPkg ]

     :
                                        KSecPkg

  [    / LDDM Graphics Subsystem ]

     :
                                        LDDM Graphics Subsystem

  [    / Link-Layer Topology Discovery Mapper I/O Driver ]

     :
                                        Link-Layer Topology Discovery Mapper I/O Driver

  [    / Link-Layer Topology Discovery Responder ]

     :
                                        Link-Layer Topology Discovery Responder

  [    / MSICDSetup ]

     :
                                        MSICDSetup

  [    / msisadrv ]

     :
                                        msisadrv

  [    / NDProxy ]

     :
                                        NDProxy

  [    / NETBT ]

     :
                                        NETBT

  [    / NSI proxy service driver. ]

     :
                                        NSI proxy service driver.

  [    / Null ]

     :
                                        Null

  [    / Parvdm ]

     :
                                        Parvdm

  [    / PEAUTH ]

     :
                                        PEAUTH

  [    / Performance Counters for Windows Driver ]

     :
                                        Performance Counters for Windows Driver

  [    / PnkBstrK ]

     :
                                        PnkBstrK

  [    / RDP Encoder Mirror Driver ]

     :
                                        RDP Encoder Mirror Driver

  [    / RDPCDD ]

     :
                                        RDPCDD

  [    / Reflector Display Driver used to gain access to graphics data ]

     :
                                        Reflector Display Driver used to gain access to graphics data

  [    / RTCore32 ]

     :
                                        RTCore32

  [    / Security Driver ]

     :
                                        Security Driver

  [    / Security Processor Loader Driver ]

     :
                                        Security Processor Loader Driver

  [    / System Attribute Cache ]

     :
                                        System Attribute Cache

  [    / TCP/IP Registry Compatibility ]

     :
                                        TCP/IP Registry Compatibility

  [    / User Mode Driver Frameworks Platform Driver ]

     :
                                        User Mode Driver Frameworks Platform Driver

  [    / VgaSave ]

     :
                                        VgaSave

  [    / WFP Lightweight Filter ]

     :
                                        WFP Lightweight Filter

  [    /        ]

     :
                                              

  [    /    ]

     :
                                          

  [    /    ]

     :
                                          

  [    /    ]

     :
                                          

  [    /    Windows ]

     :
                                           Windows

  [    /   NetIO Legacy TDI ]

     :
                                          NetIO Legacy TDI

  [    /   TCP/IP ]

     :
                                          TCP/IP

  [    /    IPv6 ARP ]

     :
                                           IPv6 ARP

  [    /     Bitlocker ]

     :
                                            Bitlocker

  [    /   (CLFS) ]

     :
                                          (CLFS)

  [    /   QoS ]

     :
                                          QoS

  [    /   NDIS ]

     :
                                          NDIS

  [    /    ]

     :
                                          

  [ ,     / NVIDIA High Definition Audio ]

     :
                                        NVIDIA High Definition Audio
                                            16.06.2013
                                          1.3.26.4
                                       NVIDIA Corporation
      INF-                                          oem6.inf
       ID                                     HDAUDIO\FUNC_01&VEN_10DE&DEV_0015&SUBSYS_10DE0101&REV_1001
                                       High Definition Audio

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ ,     / NVIDIA High Definition Audio ]

     :
                                        NVIDIA High Definition Audio
                                            16.06.2013
                                          1.3.26.4
                                       NVIDIA Corporation
      INF-                                          oem6.inf
       ID                                     HDAUDIO\FUNC_01&VEN_10DE&DEV_0015&SUBSYS_10DE0101&REV_1001
                                       High Definition Audio

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ ,     / NVIDIA High Definition Audio ]

     :
                                        NVIDIA High Definition Audio
                                            16.06.2013
                                          1.3.26.4
                                       NVIDIA Corporation
      INF-                                          oem6.inf
       ID                                     HDAUDIO\FUNC_01&VEN_10DE&DEV_0015&SUBSYS_10DE0101&REV_1001
                                       High Definition Audio

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ ,     / NVIDIA High Definition Audio ]

     :
                                        NVIDIA High Definition Audio
                                            16.06.2013
                                          1.3.26.4
                                       NVIDIA Corporation
      INF-                                          oem6.inf
       ID                                     HDAUDIO\FUNC_01&VEN_10DE&DEV_0015&SUBSYS_10DE0101&REV_1001
                                       High Definition Audio

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ ,     / NVIDIA Virtual Audio Device (Wave Extensible) (WDM) ]

     :
                                        NVIDIA Virtual Audio Device (Wave Extensible) (WDM)
                                            05.12.2013
                                          1.2.19.0
                                       NVIDIA
      INF-                                          oem9.inf
       ID                                     USB\VID_0955&PID_9000

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/mobo.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ ,     / Realtek High Definition Audio ]

     :
                                        Realtek High Definition Audio
                                            05.11.2013
                                          6.0.1.7083
                                       Realtek Semiconductor Corp.
      INF-                                          oem11.inf
       ID                                     HDAUDIO\FUNC_01&VEN_10EC&DEV_0887&SUBSYS_10EC0887&REV_1002
                                       High Definition Audio

     :
                                                   Realtek Semiconductor Corp.
                                     http://www.realtek.com.tw/products/productsView.aspx?Langid=1&PNid=8&PFid=14&Level=3&Conn=2
                                       http://www.realtek.com.tw/downloads
                                     http://www.aida64.com/driver-updates

  [  /  HID ]

     :
                                         HID
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          keyboard.inf
       ID                                     HID\VID_1C4F&PID_0026&REV_0110&MI_00

  [  / ACPI    x86 ]

     :
                                        ACPI    x86
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          hal.inf
       ID                                     acpiapic

  [  USB /    USB ]

     :
                                           USB
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbstor.inf
       ID                                     USB\VID_0BDA&PID_0151&REV_5195
                                     Port_#0001.Hub_#0006

  [  USB /    USB ]

     :
                                           USB
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbstor.inf
       ID                                     USB\VID_152D&PID_2329&REV_0100
                                     Port_#0006.Hub_#0003

  [  USB /    USB ]

     :
                                           USB
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbstor.inf
       ID                                     USB\VID_3538&PID_0070&REV_0100
                                     Port_#0002.Hub_#0006

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB&VID1002&PID4397&REV0000

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB&VID1002&PID4399&REV0000

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB&VID1002&PID4397&REV0000

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB&VID1002&PID4398&REV0000

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB&VID1002&PID4398&REV0000

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB20&VID1002&PID4396&REV0000

  [  USB /  USB- ]

     :
                                         USB-
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     USB\ROOT_HUB20&VID1002&PID4396&REV0000

  [  USB /  USB  ]

     :
                                         USB 
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usb.inf
       ID                                     USB\VID_1C4F&PID_0026&REV_0110
                                     Port_#0002.Hub_#0001

  [  USB /  OpenHCD USB - ]

     :
                                         OpenHCD USB -
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_1002&DEV_4397&SUBSYS_82EF1043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,18,0)
      PCI-                                    ATI SB700 - OHCI USB Controller

     :
      IRQ                                               16
                                                  F7FFE000-F7FFEFFF

  [  USB /  OpenHCD USB - ]

     :
                                         OpenHCD USB -
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_1002&DEV_4397&SUBSYS_82EF1043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,19,0)
      PCI-                                    ATI SB700 - OHCI USB Controller

     :
      IRQ                                               18
                                                  F7FFC000-F7FFCFFF

  [  USB /  OpenHCD USB - ]

     :
                                         OpenHCD USB -
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_1002&DEV_4398&SUBSYS_82EF1043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,18,1)
      PCI-                                    ATI SB700 - OHCI USB Controller

     :
      IRQ                                               16
                                                  F7FFD000-F7FFDFFF

  [  USB /  OpenHCD USB - ]

     :
                                         OpenHCD USB -
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_1002&DEV_4398&SUBSYS_82EF1043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,19,1)
      PCI-                                    ATI SB700 - OHCI USB Controller

     :
      IRQ                                               18
                                                  F7FFB000-F7FFBFFF

  [  USB /  OpenHCD USB - ]

     :
                                         OpenHCD USB -
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_1002&DEV_4399&SUBSYS_82EF1043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,20,5)
      PCI-                                    ATI SB700 - OHCI USB Controller

     :
      IRQ                                               18
                                                  F7FFA000-F7FFAFFF

  [  USB /   PCI - USB - ]

     :
                                          PCI - USB -
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_1002&DEV_4396&SUBSYS_82EF1043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,18,2)
      PCI-                                    ATI SB700 - EHCI USB 2.0 Controller

     :
      IRQ                                               17
                                                  F7FFF800-F7FFF8FF

  [  USB /   PCI - USB - ]

     :
                                          PCI - USB -
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          usbport.inf
       ID                                     PCI\VEN_1002&DEV_4396&SUBSYS_82EF1043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,19,2)
      PCI-                                    ATI SB700 - EHCI USB 2.0 Controller

     :
      IRQ                                               19
                                                  F7FFF400-F7FFF4FF

  [  /   PnP ]

     :
                                          PnP
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          monitor.inf
       ID                                     MONITOR\BNQ783C

  [      / HID-  ]

     :
                                        HID- 
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          msmouse.inf
       ID                                     HID\VID_093A&PID_2510&REV_0100

  [   / H:\ ]

     :
                                        H:\
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          wpdfs.inf

  [   / I:\ ]

     :
                                        I:\
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          wpdfs.inf

  [   / J:\ ]

     :
                                        J:\
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          wpdfs.inf

  [   / K:\ ]

     :
                                        K:\
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          wpdfs.inf

  [   / MULTIBOOT ]

     :
                                        MULTIBOOT
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          wpdfs.inf

  [  (COM  LPT) /   (LPT1) ]

     :
                                          (LPT1)
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          msports.inf
       ID                                     ACPI\PNP0400
      PnP-                                    Parallel Port

     :
                                                    0378-037F

  [  (COM  LPT) /   (COM1) ]

     :
                                          (COM1)
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          msports.inf
       ID                                     ACPI\PNP0501
      PnP-                                    16550A-compatible UART Serial Port

     :
      IRQ                                               04
                                                    03F8-03FF

  [  / AMD Athlon(tm) II X3 425 Processor ]

     :
                                        AMD Athlon(tm) II X3 425 Processor
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          cpu.inf
       ID                                     ACPI\AuthenticAMD_-_x86_Family_16_Model_5

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us-en/Processors/ProductInformation/0,,30_118,00.html
                                     http://www.aida64.com/driver-updates

  [  / AMD Athlon(tm) II X3 425 Processor ]

     :
                                        AMD Athlon(tm) II X3 425 Processor
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          cpu.inf
       ID                                     ACPI\AuthenticAMD_-_x86_Family_16_Model_5

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us-en/Processors/ProductInformation/0,,30_118,00.html
                                     http://www.aida64.com/driver-updates

  [  / AMD Athlon(tm) II X3 425 Processor ]

     :
                                        AMD Athlon(tm) II X3 425 Processor
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          cpu.inf
       ID                                     ACPI\AuthenticAMD_-_x86_Family_16_Model_5

     :
                                                   Advanced Micro Devices, Inc.
                                     http://www.amd.com/us-en/Processors/ProductInformation/0,,30_118,00.html
                                     http://www.aida64.com/driver-updates

  [   / Teredo Tunneling Pseudo-Interface ]

     :
                                        Teredo Tunneling Pseudo-Interface
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          nettun.inf
       ID                                     *TEREDO

  [   / WAN Miniport (IKEv2) ]

     :
                                        WAN Miniport (IKEv2)
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          netavpna.inf
       ID                                     ms_agilevpnminiport

  [   /  Microsoft ISATAP ]

     :
                                         Microsoft ISATAP
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          nettun.inf
       ID                                     *ISATAP

  [   /  WAN (IP) ]

     :
                                        WAN Miniport (IP)
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_ndiswanip

  [   /  WAN (IPv6) ]

     :
                                        WAN Miniport (IPv6)
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_ndiswanipv6

  [   /  WAN (L2TP) ]

     :
                                        WAN Miniport (L2TP)
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_l2tpminiport

  [   /  WAN (PPPoE) ]

     :
                                        WAN Miniport (PPPOE)
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_pppoeminiport

  [   /  WAN (PPTP) ]

     :
                                        WAN Miniport (PPTP)
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_pptpminiport

  [   / - WAN (SSTP) ]

     :
                                        WAN Miniport (SSTP)
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          netsstpa.inf
       ID                                     ms_sstpminiport

  [   /  WAN ( ) ]

     :
                                        WAN Miniport (Network Monitor)
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          netrasa.inf
       ID                                     ms_ndiswanbh

  [   /   Realtek RTL8168B/8111B Family PCI-E Gigabit Ethernet NIC (NDIS 6.20) ]

     :
                                          Realtek RTL8168B/8111B Family PCI-E Gigabit Ethernet NIC (NDIS 6.20)
                                            26.02.2008
                                          7.2.1127.2008
                                       Microsoft
      INF-                                          netrtx32.inf
       ID                                     PCI\VEN_10EC&DEV_8168&SUBSYS_83851043&REV_01
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(2,0,0)
      PCI-                                    Realtek RTL8168B/8111B PCI-E Gigabit Ethernet Adapter

     :
      IRQ                                               18
                                                  FBFFF000-FBFFFFFF
                                                    E800-E8FF

      :
                                                   Realtek Semiconductor Corp.
                                     http://www.realtek.com.tw/products/productsView.aspx?Langid=1&PNid=7&PFid=10&Level=3&Conn=2
                                       http://www.realtek.com.tw/downloads
                                     http://www.aida64.com/driver-updates

  [   / CMOS   ]

     :
                                        CMOS  
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0B00
      PnP-                                    Real-Time Clock

     :
      IRQ                                               08
                                                    0070-0071

  [   / Microsoft ACPI-  ]

     :
                                        Microsoft ACPI- 
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          acpi.inf
       ID                                     ACPI_HAL\PNP0C08
      PnP-                                    ACPI Driver/BIOS

     :
      IRQ                                               100
      IRQ                                               101
      IRQ                                               102
      IRQ                                               103
      IRQ                                               104
      IRQ                                               105
      IRQ                                               106
      IRQ                                               107
      IRQ                                               108
      IRQ                                               109
      IRQ                                               110
      IRQ                                               111
      IRQ                                               112
      IRQ                                               113
      IRQ                                               114
      IRQ                                               115
      IRQ                                               116
      IRQ                                               117
      IRQ                                               118
      IRQ                                               119
      IRQ                                               120
      IRQ                                               121
      IRQ                                               122
      IRQ                                               123
      IRQ                                               124
      IRQ                                               125
      IRQ                                               126
      IRQ                                               127
      IRQ                                               128
      IRQ                                               129
      IRQ                                               130
      IRQ                                               131
      IRQ                                               132
      IRQ                                               133
      IRQ                                               134
      IRQ                                               135
      IRQ                                               136
      IRQ                                               137
      IRQ                                               138
      IRQ                                               139
      IRQ                                               140
      IRQ                                               141
      IRQ                                               142
      IRQ                                               143
      IRQ                                               144
      IRQ                                               145
      IRQ                                               146
      IRQ                                               147
      IRQ                                               148
      IRQ                                               149
      IRQ                                               150
      IRQ                                               151
      IRQ                                               152
      IRQ                                               153
      IRQ                                               154
      IRQ                                               155
      IRQ                                               156
      IRQ                                               157
      IRQ                                               158
      IRQ                                               159
      IRQ                                               160
      IRQ                                               161
      IRQ                                               162
      IRQ                                               163
      IRQ                                               164
      IRQ                                               165
      IRQ                                               166
      IRQ                                               167
      IRQ                                               168
      IRQ                                               169
      IRQ                                               170
      IRQ                                               171
      IRQ                                               172
      IRQ                                               173
      IRQ                                               174
      IRQ                                               175
      IRQ                                               176
      IRQ                                               177
      IRQ                                               178
      IRQ                                               179
      IRQ                                               180
      IRQ                                               181
      IRQ                                               182
      IRQ                                               183
      IRQ                                               184
      IRQ                                               185
      IRQ                                               186
      IRQ                                               187
      IRQ                                               188
      IRQ                                               189
      IRQ                                               190
      IRQ                                               81
      IRQ                                               82
      IRQ                                               83
      IRQ                                               84
      IRQ                                               85
      IRQ                                               86
      IRQ                                               87
      IRQ                                               88
      IRQ                                               89
      IRQ                                               90
      IRQ                                               91
      IRQ                                               92
      IRQ                                               93
      IRQ                                               94
      IRQ                                               95
      IRQ                                               96
      IRQ                                               97
      IRQ                                               98
      IRQ                                               99

  [   / Microsoft System Management BIOS  ]

     :
                                        Microsoft System Management BIOS 
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ROOT\mssmbios

  [   / Remote Desktop Device Redirector Bus ]

     :
                                        Remote Desktop Device Redirector Bus
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          rdpbus.inf
       ID                                     ROOT\RDPBUS

  [   / UMBus    ]

     :
                                        UMBus   
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          umbus.inf
       ID                                     root\umbus

  [   / UMBus  ]

     :
                                        UMBus 
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          umbus.inf
       ID                                     UMB\UMBUS

  [   / UMBus  ]

     :
                                        UMBus 
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          umbus.inf
       ID                                     UMB\UMBUS

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C04
      PnP-                                    Numeric Data Processor

     :
      IRQ                                               13
                                                    00F0-00FF

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0800
      PnP-                                    PC Speaker

     :
                                                    0061-0061

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0103
      PnP-                                    High Precision Event Timer

     :
                                                  FED00000-FED003FF

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ROOT\VOLMGR

  [   /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ROOT\RDP_KBD

  [   /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ROOT\RDP_MOU

  [   /     () ]

     :
                                            ()
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ROOT\vdrvroot

  [   /      ]

     :
                                            
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          blbdrive.inf
       ID                                     ROOT\BLBDRIVE

  [   /    ACPI Microsoft Windows ]

     :
                                           ACPI Microsoft Windows
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          acpi.inf
       ID                                     ACPI\PNP0C14
      PnP-                                    ACPI Management Interface

  [   /   ACPI ]

     :
                                          ACPI
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C0C
      PnP-                                    Power Button

  [   /  High Definition Audio (Microsoft) ]

     :
                                         High Definition Audio (Microsoft)
                                            13.07.2009
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          hdaudbus.inf
       ID                                     PCI\VEN_1002&DEV_4383&SUBSYS_837B1043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,20,2)
      PCI-                                    ATI SB700 - High Definition Audio Controller

     :
      IRQ                                               16
                                                  F7FF4000-F7FF7FFF

  [   /  High Definition Audio (Microsoft) ]

     :
                                         High Definition Audio (Microsoft)
                                            13.07.2009
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          hdaudbus.inf
       ID                                     PCI\VEN_10DE&DEV_0BEE&SUBSYS_809D1462&REV_A1
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(1,0,1)
      PCI-                                     High Definition Audio (Microsoft) [10DE-0BEE] [NoDB]

     :
      IRQ                                               19
                                                  FBE7C000-FBE7FFFF

  [   /  SMBus    - ATI ]

     :
                                         SMBus    - ATI
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1002&DEV_4385&SUBSYS_82EF1043&REV_3A
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,20,0)
      PCI-                                    ATI SB700 - SMBus Controller

  [   /      ]

     :
                                            
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0200
      PnP-                                    DMA Controller

     :
      DMA                                               04
                                                    0000-000F
                                                    0081-0083
                                                    0087-0087
                                                    0089-008B
                                                    008F-008F
                                                    00C0-00DF

  [   /   PCI    - ATI ]

     :
                                          PCI    - ATI
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1002&DEV_4384&SUBSYS_00000000&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,20,4)
      PCI-                                    ATI SB700 - PCI-PCI Bridge

  [   /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     LPTENUM\MicrosoftRawPort958A
                                     LPT1

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          compositebus.inf
       ID                                     ROOT\CompositeBus

  [   /    Plug and Play ]

     :
                                           Plug and Play
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     root\swenum

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0000
      PnP-                                    Programmable Interrupt Controller

     :
                                                    0020-0021
                                                    00A0-00A1

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C02
      PnP-                                    Thermal Monitoring ACPI Device

     :
                                                  E0000000-EFFFFFFF

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C02
      PnP-                                    Thermal Monitoring ACPI Device

     :
                                                  FEC00000-FEC00FFF
                                                  FEE00000-FEE00FFF
                                                    0060-0060
                                                    0064-0064

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C02
      PnP-                                    Thermal Monitoring ACPI Device

     :
                                                  FEC10000-FEC1001F
                                                  FFB80000-FFBFFFFF
                                                    0010-001F
                                                    0022-003F
                                                    0060-0060
                                                    0062-0063
                                                    0064-0064
                                                    0065-006F
                                                    0072-007F
                                                    0080-0080
                                                    0084-0086
                                                    0088-0088
                                                    008C-008E
                                                    0090-009F
                                                    00A2-00BF
                                                    00B1-00B1
                                                    00E0-00EF
                                                    040B-040B
                                                    04D0-04D1
                                                    04D6-04D6
                                                    0800-089F
                                                    0900-090F
                                                    0910-091F
                                                    0B00-0B0F
                                                    0B20-0B3F
                                                    0C00-0C01
                                                    0C14-0C14
                                                    0C50-0C51
                                                    0C52-0C52
                                                    0C6C-0C6C
                                                    0C6F-0C6F
                                                    0CD0-0CD1
                                                    0CD2-0CD3
                                                    0CD4-0CD5
                                                    0CD6-0CD7
                                                    0CD8-0CDF
                                                    FE00-FEFE

  [   /    ]

     :
                                          
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C02
      PnP-                                    Thermal Monitoring ACPI Device

     :
                                                    0290-0297
                                                    02A0-02AF

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0C01
      PnP-                                    System Board Extension

     :
                                                  00000000-0009FFFF
                                                  000C0000-000CFFFF
                                                  000E0000-000FFFFF
                                                  00100000-CFFFFFFF
                                                  FEC00000-FFFFFFFF

  [   /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0100
      PnP-                                    System Timer

     :
      IRQ                                               00
                                                    0040-0043

  [   /   PCI  - CPU ]

     :
                                          PCI  - CPU
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1200&SUBSYS_00000000&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,24,0)
      PCI-                                    AMD K10 - HyperTransport Technology Configuration

  [   /   PCI  - CPU ]

     :
                                          PCI  - CPU
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1201&SUBSYS_00000000&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,24,1)
      PCI-                                    AMD K10 - Address Map

  [   /   PCI  - CPU ]

     :
                                          PCI  - CPU
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1202&SUBSYS_00000000&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,24,2)
      PCI-                                    AMD K10 - DRAM Controller

  [   /   PCI  - CPU ]

     :
                                          PCI  - CPU
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1203&SUBSYS_00000000&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,24,3)
      PCI-                                    AMD K10 - Miscellaneous Control

  [   /   PCI  - CPU ]

     :
                                          PCI  - CPU
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1022&DEV_1204&SUBSYS_00000000&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,24,4)
      PCI-                                    AMD K10 - Link Control

  [   /   PCI  - CPU ]

     :
                                          PCI  - CPU
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1002&DEV_5957&SUBSYS_83531043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,0,0)
      PCI-                                    ATI RX780 Chipset - Host Bridge

  [   /   PCI - ISA ]

     :
                                          PCI - ISA
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1002&DEV_439D&SUBSYS_82EF1043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,20,3)
      PCI-                                    ATI SB700 - PCI-LPC Bridge

  [   /   PCI - PCI ]

     :
                                          PCI - PCI
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1002&DEV_5978&SUBSYS_83531043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,2,0)
      PCI-                                    ATI RX780 Chipset - PCI Express Graphics 0 Port A

     :
      IRQ                                               18
                                                  000A0000-000BFFFF
                                                  D4000000-DFFFFFFF
                                                  F8000000-FBEFFFFF
                                                    03B0-03BB
                                                    03C0-03DF
                                                    D000-DFFF

  [   /   PCI - PCI ]

     :
                                          PCI - PCI
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     PCI\VEN_1002&DEV_597C&SUBSYS_83531043&REV_00
                                     @system32\DRIVERS\pci.sys,#65536;PCI bus %1, device %2, function %3;(0,6,0)
      PCI-                                    ATI RX780 Chipset - PCI Express Port C

     :
      IRQ                                               18
                                                  FBF00000-FBFFFFFF
                                                    E000-EFFF

  [   /    ACPI ]

     :
                                           ACPI
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\FixedButton

  [   /  PCI ]

     :
                                         PCI
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          machine.inf
       ID                                     ACPI\PNP0A03
      PnP-                                    PCI Bus

     :
                                                  000A0000-000BFFFF
                                                  000D0000-000DFFFF
                                                  D0000000-DFFFFFFF
                                                  F0000000-FEBFFFFF
                                                    0000-0CF7
                                                    0D00-FFFF

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
       ID                                     STORAGE\VolumeSnapshot

  [      /     ]

     :
                                           
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volsnap.inf
       ID                                     STORAGE\VolumeSnapshot

  [    /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volume.inf
       ID                                     STORAGE\Volume

  [    /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volume.inf
       ID                                     STORAGE\Volume

  [    /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volume.inf
       ID                                     STORAGE\Volume

  [    /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volume.inf
       ID                                     STORAGE\Volume

  [    /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volume.inf
       ID                                     STORAGE\Volume

  [    /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volume.inf
       ID                                     STORAGE\Volume

  [    /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volume.inf
       ID                                     STORAGE\Volume

  [    /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volume.inf
       ID                                     STORAGE\Volume

  [    /   ]

     :
                                         
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          volume.inf
       ID                                     STORAGE\Volume

  [  HID (Human Interface Devices) / HID-   ]

     :
                                        HID-  
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          hidserv.inf
       ID                                     HID\VID_1C4F&PID_0026&REV_0110&MI_01&Col01

  [  HID (Human Interface Devices) / HID-  ]

     :
                                        HID- 
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          input.inf
       ID                                     HID\VID_1C4F&PID_0026&REV_0110&MI_01&Col02

  [  HID (Human Interface Devices) / USB-  ]

     :
                                        USB- 
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          input.inf
       ID                                     USB\VID_093A&PID_2510&REV_0100
                                     Port_#0003.Hub_#0001

  [  HID (Human Interface Devices) / USB-  ]

     :
                                        USB- 
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          input.inf
       ID                                     USB\VID_1C4F&PID_0026&REV_0110&MI_00
                                     0000.0012.0000.002.000.000.000.000.000

  [  HID (Human Interface Devices) / USB-  ]

     :
                                        USB- 
                                            21.06.2006
                                          6.1.7600.16385
                                       Microsoft
      INF-                                          input.inf
       ID                                     USB\VID_1C4F&PID_0026&REV_0110&MI_01
                                     0000.0012.0000.002.000.000.000.000.000


--------[   ]---------------------------------------------------------------------------------------

     PCI:
       0,  24,  1                  AMD K10 - Address Map
       0,  24,  2                  AMD K10 - DRAM Controller
       0,  24,  0                  AMD K10 - HyperTransport Technology Configuration
       0,  24,  4                  AMD K10 - Link Control
       0,  24,  3                  AMD K10 - Miscellaneous Control
       0,  0,  0                   ATI RX780 Chipset - Host Bridge
       0,  2,  0                   ATI RX780 Chipset - PCI Express Graphics 0 Port A
       0,  6,  0                   ATI RX780 Chipset - PCI Express Port C
       0,  18,  2                  ATI SB700 - EHCI USB 2.0 Controller
       0,  19,  2                  ATI SB700 - EHCI USB 2.0 Controller
       0,  20,  2                  ATI SB700 - High Definition Audio Controller
       0,  20,  1                  ATI SB700 - IDE Controller
       0,  18,  0                  ATI SB700 - OHCI USB Controller
       0,  18,  1                  ATI SB700 - OHCI USB Controller
       0,  19,  0                  ATI SB700 - OHCI USB Controller
       0,  19,  1                  ATI SB700 - OHCI USB Controller
       0,  20,  5                  ATI SB700 - OHCI USB Controller
       0,  20,  3                  ATI SB700 - PCI-LPC Bridge
       0,  20,  4                  ATI SB700 - PCI-PCI Bridge
       0,  17,  0                  ATI SB700 - SATA Controller
       0,  20,  0                  ATI SB700 - SMBus Controller
       1,  0,  0                   NVIDIA GeForce GTX 550 Ti [10DE-1244] [NoDB]
       2,  0,  0                   Realtek RTL8168B/8111B PCI-E Gigabit Ethernet Adapter
       1,  0,  1                    High Definition Audio (Microsoft) [10DE-0BEE] [NoDB]

     PnP:
      PNP0501                                           16550A-compatible UART Serial Port
      PNP0C08                                           ACPI Driver/BIOS
      PNP0C14                                           ACPI Management Interface
      AUTHENTICAMD_-_X86_FAMILY_16_MODEL_5_-_AMD_ATHLON(TM)_II_X3_425_PROCESSORAMD Athlon(tm) II X3 425 Processor
      AUTHENTICAMD_-_X86_FAMILY_16_MODEL_5_-_AMD_ATHLON(TM)_II_X3_425_PROCESSORAMD Athlon(tm) II X3 425 Processor
      AUTHENTICAMD_-_X86_FAMILY_16_MODEL_5_-_AMD_ATHLON(TM)_II_X3_425_PROCESSORAMD Athlon(tm) II X3 425 Processor
      ATK0110                                           Asus ATK-110 ACPI Utility
      PNP0200                                           DMA Controller
      PNP0103                                           High Precision Event Timer
      PNP0C04                                           Numeric Data Processor
      PNP0400                                           Parallel Port
      PNP0800                                           PC Speaker
      PNP0A03                                           PCI Bus
      PNP0C0C                                           Power Button
      PNP0000                                           Programmable Interrupt Controller
      PNP0B00                                           Real-Time Clock
      PNP0C01                                           System Board Extension
      PNP0100                                           System Timer
      TEREDO                                            Teredo Tunneling Pseudo-Interface
      PNP0C02                                           Thermal Monitoring ACPI Device
      PNP0C02                                           Thermal Monitoring ACPI Device
      PNP0C02                                           Thermal Monitoring ACPI Device
      PNP0C02                                           Thermal Monitoring ACPI Device
      ISATAP                                             Microsoft ISATAP
      FIXEDBUTTON                                          ACPI

     LPT PnP:
      MICROSOFTRAWPORT                                     

     USB:
      093A 2510                                         USB- 
      1C4F 0026                                         USB- 
      1C4F 0026                                         USB- 
      0BDA 0151                                            USB
      152D 2329                                            USB
      3538 0070                                            USB
      1C4F 0026                                          USB 

    :
      COM1                                                (COM1)
      LPT1                                                (LPT1)


--------[  PCI ]----------------------------------------------------------------------------------------------

  [ AMD K10 - Address Map ]

     :
                                      AMD K10 - Address Map
                                                 PCI
       /  /                        0 / 24 / 1
      ID                                      1022-1201
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K10 - DRAM Controller ]

     :
                                      AMD K10 - DRAM Controller
                                                 PCI
       /  /                        0 / 24 / 2
      ID                                      1022-1202
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K10 - HyperTransport Technology Configuration ]

     :
                                      AMD K10 - HyperTransport Technology Configuration
                                                 PCI
       /  /                        0 / 24 / 0
      ID                                      1022-1200
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

    HyperTransport LDT0:
       HyperTransport                             3.00
                                                 
                                             
      .  /                    16  / 16 
        /          16  / 16 
                                2000 
                                     2000 
       /                     0 / 0
      Isochronous Flow Control Mode                     , 
      CRC Error Detected                                
      CRC Test Mode                                      
      Extended CTL Required                             
      Extended Register Set                              
      HyperTransport Stop Mode                          
      Link Failure Detected                             

  [ AMD K10 - Link Control ]

     :
                                      AMD K10 - Link Control
                                                 PCI
       /  /                        0 / 24 / 4
      ID                                      1022-1204
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ AMD K10 - Miscellaneous Control ]

     :
                                      AMD K10 - Miscellaneous Control
                                                 PCI
       /  /                        0 / 24 / 3
      ID                                      1022-1203
                               0000-0000
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ ATI RX780 Chipset - Host Bridge ]

     :
                                      ATI RX780 Chipset - Host Bridge
                                                 PCI
       /  /                        0 / 0 / 0
      ID                                      1002-5957
                               1043-8353
                                         0600 (Host/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                    
      Bus Mastering                                     

  [ ATI RX780 Chipset - PCI Express Graphics 0 Port A ]

     :
                                      ATI RX780 Chipset - PCI Express Graphics 0 Port A
                                                 PCI
       /  /                        0 / 2 / 0
      ID                                      1002-5978
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ ATI RX780 Chipset - PCI Express Port C ]

     :
                                      ATI RX780 Chipset - PCI Express Port C
                                                 PCI
       /  /                        0 / 6 / 0
      ID                                      1002-597C
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ ATI SB700 - EHCI USB 2.0 Controller ]

     :
                                      ATI SB700 - EHCI USB 2.0 Controller
                                                 PCI
       /  /                        0 / 18 / 2
      ID                                      1002-4396
                               1043-82EF
                                         0C03 (USB Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ ATI SB700 - EHCI USB 2.0 Controller ]

     :
                                      ATI SB700 - EHCI USB 2.0 Controller
                                                 PCI
       /  /                        0 / 19 / 2
      ID                                      1002-4396
                               1043-82EF
                                         0C03 (USB Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ ATI SB700 - High Definition Audio Controller ]

     :
                                      ATI SB700 - High Definition Audio Controller
                                                 PCI
       /  /                        0 / 20 / 2
      ID                                      1002-4383
                               1043-837B
                                         0403 (High Definition Audio)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

  [ ATI SB700 - IDE Controller ]

     :
                                      ATI SB700 - IDE Controller
                                                 PCI
       /  /                        0 / 20 / 1
      ID                                      1002-439C
                               1043-82EF
                                         0101 (IDE Controller)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                    
      Bus Mastering                                     

  [ ATI SB700 - OHCI USB Controller ]

     :
                                      ATI SB700 - OHCI USB Controller
                                                 PCI
       /  /                        0 / 18 / 0
      ID                                      1002-4397
                               1043-82EF
                                         0C03 (USB Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ ATI SB700 - OHCI USB Controller ]

     :
                                      ATI SB700 - OHCI USB Controller
                                                 PCI
       /  /                        0 / 18 / 1
      ID                                      1002-4398
                               1043-82EF
                                         0C03 (USB Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ ATI SB700 - OHCI USB Controller ]

     :
                                      ATI SB700 - OHCI USB Controller
                                                 PCI
       /  /                        0 / 19 / 0
      ID                                      1002-4397
                               1043-82EF
                                         0C03 (USB Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ ATI SB700 - OHCI USB Controller ]

     :
                                      ATI SB700 - OHCI USB Controller
                                                 PCI
       /  /                        0 / 19 / 1
      ID                                      1002-4398
                               1043-82EF
                                         0C03 (USB Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ ATI SB700 - OHCI USB Controller ]

     :
                                      ATI SB700 - OHCI USB Controller
                                                 PCI
       /  /                        0 / 20 / 5
      ID                                      1002-4399
                               1043-82EF
                                         0C03 (USB Controller)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ ATI SB700 - PCI-LPC Bridge ]

     :
                                      ATI SB700 - PCI-LPC Bridge
                                                 PCI
       /  /                        0 / 20 / 3
      ID                                      1002-439D
                               1043-82EF
                                         0601 (PCI/ISA Bridge)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                    
      Bus Mastering                                     

  [ ATI SB700 - PCI-PCI Bridge ]

     :
                                      ATI SB700 - PCI-PCI Bridge
                                                 PCI
       /  /                        0 / 20 / 4
      ID                                      1002-4384
                               0000-0000
                                         0604 (PCI/PCI Bridge)
                                                  00
      Fast Back-to-Back Transactions                    , 

     :
      66-                                    
      Bus Mastering                                     

  [ ATI SB700 - SATA Controller ]

     :
                                      ATI SB700 - SATA Controller
                                                 PCI
       /  /                        0 / 17 / 0
      ID                                      1002-4390
                               1043-82EF
                                         0101 (IDE Controller)
                                                  00
      Fast Back-to-Back Transactions                     

     :
      66-                                    
      Bus Mastering                                     

  [ ATI SB700 - SMBus Controller ]

     :
                                      ATI SB700 - SMBus Controller
                                                 PCI
       /  /                        0 / 20 / 0
      ID                                      1002-4385
                               1043-82EF
                                         0C05 (SMBus Controller)
                                                  3A
      Fast Back-to-Back Transactions                     

     :
      66-                                    
      Bus Mastering                                     

  [ NVIDIA GeForce GTX 550 Ti [10DE-1244] [NoDB] ]

     :
                                      NVIDIA GeForce GTX 550 Ti [10DE-1244] [NoDB]
                                                 PCI Express 2.0 x16
       /  /                        1 / 0 / 0
      ID                                      10DE-1244
                               1462-809D
                                         0300 (VGA Display Controller)
                                                  A1
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

     :
                                                   NVIDIA Corporation
                                     http://www.nvidia.com/page/products.html
                                       http://www.nvidia.com/content/drivers/drivers.asp
                                     http://www.aida64.com/driver-updates

  [ Realtek RTL8168B/8111B PCI-E Gigabit Ethernet Adapter ]

     :
                                      Realtek RTL8168B/8111B PCI-E Gigabit Ethernet Adapter
                                                 PCI Express 1.0 x1
       /  /                        2 / 0 / 0
      ID                                      10EC-8168
                               1043-8385
                                         0200 (Ethernet Controller)
                                                  01
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     

      :
                                                   Realtek Semiconductor Corp.
                                     http://www.realtek.com.tw/products/productsView.aspx?Langid=1&PNid=7&PFid=10&Level=3&Conn=2
                                       http://www.realtek.com.tw/downloads
                                     http://www.aida64.com/driver-updates

  [  High Definition Audio (Microsoft) [10DE-0BEE] [NoDB] ]

     :
                                       High Definition Audio (Microsoft) [10DE-0BEE] [NoDB]
                                                 PCI Express 2.0 x16
       /  /                        1 / 0 / 1
      ID                                      10DE-0BEE
                               1462-809D
                                         0403 (High Definition Audio)
                                                  A1
      Fast Back-to-Back Transactions                     

     :
      66-                                     
      Bus Mastering                                     


--------[  USB ]----------------------------------------------------------------------------------------------

  [  USB  (USB Keyboard) ]

     :
                                       USB 
      ID                                      1C4F-0026
                                         03 / 01 (Human Interface Device)
                                      01
                                           SIGMACHIP
                                                 USB Keyboard
        USB                         1.10
                                         Low  (USB 1.1)

  [ USB-  (USB OPTICAL MOUSE) ]

     :
                                      USB- 
      ID                                      093A-2510
                                         03 / 01 (Human Interface Device)
                                      02
                                           PIXART
                                                 USB OPTICAL MOUSE
        USB                         1.10
                                         Low  (USB 1.1)

  [    USB (USB to ATA/ATAPI bridge) ]

     :
                                         USB
      ID                                      152D-2329
                                         08 / 06 (Mass Storage)
                                      50
                                           JMicron
                                                 USB to ATA/ATAPI bridge
                                           835647344
        USB                         2.00
                                         High  (USB 2.0)

  [    USB (USB2.0-CRW) ]

     :
                                         USB
      ID                                      0BDA-0151
                                         08 / 06 (Mass Storage)
                                      50
                                           Generic
                                                 USB2.0-CRW
                                           20060413092100000
        USB                         2.00
                                         High  (USB 2.0)

  [    USB (PQI USB Flash drive) ]

     :
                                         USB
      ID                                      3538-0070
                                         08 / 06 (Mass Storage)
                                      50
                                           PQI
                                                 PQI USB Flash drive
                                           DT83Z5DZ
        USB                         2.00
                                         High  (USB 2.0)


--------[   ]-------------------------------------------------------------------------------------------

    DMA 04                                   
    IRQ 00                                
    IRQ 04                                 (COM1)
    IRQ 08                               CMOS  
    IRQ 100                              Microsoft ACPI- 
    IRQ 101                              Microsoft ACPI- 
    IRQ 102                              Microsoft ACPI- 
    IRQ 103                              Microsoft ACPI- 
    IRQ 104                              Microsoft ACPI- 
    IRQ 105                              Microsoft ACPI- 
    IRQ 106                              Microsoft ACPI- 
    IRQ 107                              Microsoft ACPI- 
    IRQ 108                              Microsoft ACPI- 
    IRQ 109                              Microsoft ACPI- 
    IRQ 110                              Microsoft ACPI- 
    IRQ 111                              Microsoft ACPI- 
    IRQ 112                              Microsoft ACPI- 
    IRQ 113                              Microsoft ACPI- 
    IRQ 114                              Microsoft ACPI- 
    IRQ 115                              Microsoft ACPI- 
    IRQ 116                              Microsoft ACPI- 
    IRQ 117                              Microsoft ACPI- 
    IRQ 118                              Microsoft ACPI- 
    IRQ 119                              Microsoft ACPI- 
    IRQ 120                              Microsoft ACPI- 
    IRQ 121                              Microsoft ACPI- 
    IRQ 122                              Microsoft ACPI- 
    IRQ 123                              Microsoft ACPI- 
    IRQ 124                              Microsoft ACPI- 
    IRQ 125                              Microsoft ACPI- 
    IRQ 126                              Microsoft ACPI- 
    IRQ 127                              Microsoft ACPI- 
    IRQ 128                              Microsoft ACPI- 
    IRQ 129                              Microsoft ACPI- 
    IRQ 13                                
    IRQ 130                              Microsoft ACPI- 
    IRQ 131                              Microsoft ACPI- 
    IRQ 132                              Microsoft ACPI- 
    IRQ 133                              Microsoft ACPI- 
    IRQ 134                              Microsoft ACPI- 
    IRQ 135                              Microsoft ACPI- 
    IRQ 136                              Microsoft ACPI- 
    IRQ 137                              Microsoft ACPI- 
    IRQ 138                              Microsoft ACPI- 
    IRQ 139                              Microsoft ACPI- 
    IRQ 14                               ATA Channel 0
    IRQ 140                              Microsoft ACPI- 
    IRQ 141                              Microsoft ACPI- 
    IRQ 142                              Microsoft ACPI- 
    IRQ 143                              Microsoft ACPI- 
    IRQ 144                              Microsoft ACPI- 
    IRQ 145                              Microsoft ACPI- 
    IRQ 146                              Microsoft ACPI- 
    IRQ 147                              Microsoft ACPI- 
    IRQ 148                              Microsoft ACPI- 
    IRQ 149                              Microsoft ACPI- 
    IRQ 15                               ATA Channel 1
    IRQ 150                              Microsoft ACPI- 
    IRQ 151                              Microsoft ACPI- 
    IRQ 152                              Microsoft ACPI- 
    IRQ 153                              Microsoft ACPI- 
    IRQ 154                              Microsoft ACPI- 
    IRQ 155                              Microsoft ACPI- 
    IRQ 156                              Microsoft ACPI- 
    IRQ 157                              Microsoft ACPI- 
    IRQ 158                              Microsoft ACPI- 
    IRQ 159                              Microsoft ACPI- 
    IRQ 16                                         OpenHCD USB -
    IRQ 16                                         OpenHCD USB -
    IRQ 16                                         High Definition Audio (Microsoft)
    IRQ 160                              Microsoft ACPI- 
    IRQ 161                              Microsoft ACPI- 
    IRQ 162                              Microsoft ACPI- 
    IRQ 163                              Microsoft ACPI- 
    IRQ 164                              Microsoft ACPI- 
    IRQ 165                              Microsoft ACPI- 
    IRQ 166                              Microsoft ACPI- 
    IRQ 167                              Microsoft ACPI- 
    IRQ 168                              Microsoft ACPI- 
    IRQ 169                              Microsoft ACPI- 
    IRQ 17                                          PCI - USB -
    IRQ 170                              Microsoft ACPI- 
    IRQ 171                              Microsoft ACPI- 
    IRQ 172                              Microsoft ACPI- 
    IRQ 173                              Microsoft ACPI- 
    IRQ 174                              Microsoft ACPI- 
    IRQ 175                              Microsoft ACPI- 
    IRQ 176                              Microsoft ACPI- 
    IRQ 177                              Microsoft ACPI- 
    IRQ 178                              Microsoft ACPI- 
    IRQ 179                              Microsoft ACPI- 
    IRQ 18                                          Realtek RTL8168B/8111B Family PCI-E Gigabit Ethernet NIC (NDIS 6.20)
    IRQ 18                                        NVIDIA GeForce GTX 550 Ti
    IRQ 18                                         OpenHCD USB -
    IRQ 18                                         OpenHCD USB -
    IRQ 18                                         OpenHCD USB -
    IRQ 18                                          PCI - PCI
    IRQ 18                                          PCI - PCI
    IRQ 180                              Microsoft ACPI- 
    IRQ 181                              Microsoft ACPI- 
    IRQ 182                              Microsoft ACPI- 
    IRQ 183                              Microsoft ACPI- 
    IRQ 184                              Microsoft ACPI- 
    IRQ 185                              Microsoft ACPI- 
    IRQ 186                              Microsoft ACPI- 
    IRQ 187                              Microsoft ACPI- 
    IRQ 188                              Microsoft ACPI- 
    IRQ 189                              Microsoft ACPI- 
    IRQ 19                                          PCI - USB -
    IRQ 19                                         High Definition Audio (Microsoft)
    IRQ 190                              Microsoft ACPI- 
    IRQ 22                                           PCI IDE
    IRQ 81                               Microsoft ACPI- 
    IRQ 82                               Microsoft ACPI- 
    IRQ 83                               Microsoft ACPI- 
    IRQ 84                               Microsoft ACPI- 
    IRQ 85                               Microsoft ACPI- 
    IRQ 86                               Microsoft ACPI- 
    IRQ 87                               Microsoft ACPI- 
    IRQ 88                               Microsoft ACPI- 
    IRQ 89                               Microsoft ACPI- 
    IRQ 90                               Microsoft ACPI- 
    IRQ 91                               Microsoft ACPI- 
    IRQ 92                               Microsoft ACPI- 
    IRQ 93                               Microsoft ACPI- 
    IRQ 94                               Microsoft ACPI- 
    IRQ 95                               Microsoft ACPI- 
    IRQ 96                               Microsoft ACPI- 
    IRQ 97                               Microsoft ACPI- 
    IRQ 98                               Microsoft ACPI- 
    IRQ 99                               Microsoft ACPI- 
     00000000-0009FFFF              
     000A0000-000BFFFF                      NVIDIA GeForce GTX 550 Ti
     000A0000-000BFFFF                       PCI
     000A0000-000BFFFF                 PCI - PCI
     000C0000-000CFFFF              
     000D0000-000DFFFF                       PCI
     000E0000-000FFFFF              
     00100000-CFFFFFFF              
     D0000000-DFFFFFFF                       PCI
     D4000000-D7FFFFFF             NVIDIA GeForce GTX 550 Ti
     D4000000-DFFFFFFF               PCI - PCI
     D8000000-DFFFFFFF             NVIDIA GeForce GTX 550 Ti
     E0000000-EFFFFFFF               
     F0000000-FEBFFFFF                       PCI
     F7FF4000-F7FF7FFF              High Definition Audio (Microsoft)
     F7FFA000-F7FFAFFF              OpenHCD USB -
     F7FFB000-F7FFBFFF              OpenHCD USB -
     F7FFC000-F7FFCFFF              OpenHCD USB -
     F7FFD000-F7FFDFFF              OpenHCD USB -
     F7FFE000-F7FFEFFF              OpenHCD USB -
     F7FFF400-F7FFF4FF               PCI - USB -
     F7FFF800-F7FFF8FF               PCI - USB -
     F7FFFC00-F7FFFFFF                PCI IDE
     F8000000-F9FFFFFF             NVIDIA GeForce GTX 550 Ti
     F8000000-FBEFFFFF               PCI - PCI
     FBE7C000-FBE7FFFF              High Definition Audio (Microsoft)
     FBF00000-FBFFFFFF               PCI - PCI
     FBFFF000-FBFFFFFF               Realtek RTL8168B/8111B Family PCI-E Gigabit Ethernet NIC (NDIS 6.20)
     FEC00000-FEC00FFF               
     FEC00000-FFFFFFFF              
     FEC10000-FEC1001F               
     FED00000-FED003FF               
     FEE00000-FEE00FFF               
     FFB80000-FFBFFFFF               
     0000-000F                           
     0000-0CF7                                 PCI
     0010-001F                         
     0020-0021                         
     0022-003F                         
     0040-0043                        
     0060-0060                         
     0060-0060                         
     0061-0061                        
     0062-0063                         
     0064-0064                         
     0064-0064                         
     0065-006F                         
     0070-0071                       CMOS  
     0072-007F                         
     0080-0080                         
     0081-0083                           
     0084-0086                         
     0087-0087                           
     0088-0088                         
     0089-008B                           
     008C-008E                         
     008F-008F                           
     0090-009F                         
     00A0-00A1                         
     00A2-00BF                         
     00B1-00B1                         
     00C0-00DF                           
     00E0-00EF                         
     00F0-00FF                        
     0170-0177                       ATA Channel 1
     01F0-01F7                       ATA Channel 0
     0290-0297                         
     02A0-02AF                         
     0376-0376                       ATA Channel 1
     0378-037F                         (LPT1)
     03B0-03BB                                NVIDIA GeForce GTX 550 Ti
     03B0-03BB                           PCI - PCI
     03C0-03DF                                NVIDIA GeForce GTX 550 Ti
     03C0-03DF                           PCI - PCI
     03F6-03F6                       ATA Channel 0
     03F8-03FF                         (COM1)
     040B-040B                         
     04D0-04D1                         
     04D6-04D6                         
     0800-089F                         
     0900-090F                         
     0910-091F                         
     0B00-0B0F                         
     0B20-0B3F                         
     0C00-0C01                         
     0C14-0C14                         
     0C50-0C51                         
     0C52-0C52                         
     0C6C-0C6C                         
     0C6F-0C6F                         
     0CD0-0CD1                         
     0CD2-0CD3                         
     0CD4-0CD5                         
     0CD6-0CD7                         
     0CD8-0CDF                         
     0D00-FFFF                                 PCI
     8000-800F                          PCI IDE
     9000-9003                          PCI IDE
     A000-A007                          PCI IDE
     B000-B003                          PCI IDE
     C000-C007                          PCI IDE
     D000-DFFF                         PCI - PCI
     DC00-DC7F                       NVIDIA GeForce GTX 550 Ti
     E000-EFFF                         PCI - PCI
     E800-E8FF                         Realtek RTL8168B/8111B Family PCI-E Gigabit Ethernet NIC (NDIS 6.20)
     FE00-FEFE                         
     FF00-FF0F                          PCI IDE


--------[  ]--------------------------------------------------------------------------------------------------------

  [  HID ]

     :
                                       HID
                                           IBM enhanced (101- or 102-key) keyboard
                                     Russian
        ANSI                             1251 - @%SystemRoot%\system32\mlang.dll,-4611
        OEM                              866 - @%SystemRoot%\system32\mlang.dll,-4645
                                         1
                                         31

  [ HID-  ]

     :
                                            HID- 
                                         3
                                              
                                         1
                                     500 msec
       X / Y                                       6 / 10
                                 3

     :
                               
      ''                                
                
                                            
                   
                                              
      Sonar                                             


--------[  ]----------------------------------------------------------------------------------------------------

  [ Canon LBP6000/LBP6018 ( ) ]

     :
                                             Canon LBP6000/LBP6018
                                      
                                  
                                            USB001
                                         Canon LBP6000/LBP6018 (v1.00)
                                           Canon LBP6000/LBP6018
                                         winprint
                                     
                                             
                                               1
                                 1
                                                  

     :
                                            A4, 210 x 297 mm
                                              
                                          600 dpi

     :
                                                   Canon U.S.A.,Inc.
                                     http://consumer.usa.canon.com/ir/controller?act=ProductCatIndexAct&fcategoryid=103
                                     http://www.aida64.com/driver-updates

  [ Fax ]

     :
                                             Fax
                                      
                                  
                                            SHRFAX:
                                         Microsoft Shared Fax Driver (v4.00)
                                           Fax
                                         winprint
                                     
                                             5:00 - 5:00
                                               1
                                 0
                                                  

     :
                                            Letter, 8.5 x 11 in
                                              
                                          200 x 200 dpi Mono

  [ Microsoft XPS Document Writer ]

     :
                                             Microsoft XPS Document Writer
                                      
                                  
                                            XPSPort:
                                         Microsoft XPS Document Writer (v6.00)
                                           Microsoft XPS Document Writer
                                         winprint
                                     
                                             5:00 - 5:00
                                               1
                                 0
                                                  

     :
                                            A4, 210 x 297 mm
                                              
                                          600 x 600 dpi Color

  [   OneNote 2007 ]

     :
                                               OneNote 2007
                                      
                                  
                                            Send To Microsoft OneNote Port:
                                         Send To Microsoft OneNote Driver (v4.00)
                                             OneNote 2007
                                         OneNotePrint2007
                                     
                                             
                                               1
                                 0
                                                  

     :
                                            A4, 210 x 297 mm
                                              
                                          300 x 300 dpi Color


--------[  ]------------------------------------------------------------------------------------------------

    Adobe ARM                          Registry\Common\Run      C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe 
    Adobe Reader Speed Launcher        Registry\Common\Run      D:\\Adobe Reader\Reader\Reader_sl.exe 
    CNAP2 Launcher                     Registry\Common\Run      C:\Windows\system32\spool\DRIVERS\W32X86\3\CNAP2LAK.EXE 
    GrooveMonitor                      Registry\Common\Run      D:\\Microsoft Office\Office12\GrooveMonitor.exe 
    MediaGet2                          Registry\User\Run        C:\Users\\AppData\Local\MediaGet2\mediaget.exe --minimized
    NvBackend                          Registry\Common\Run      C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe 
    Nvtmru                             Registry\Common\Run      C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe 
    Praetorian                         Registry\User\Run        C:\Users\\AppData\Local\Yandex\Updater\praetorian.exe 
    RTHDVCPL                           Registry\Common\Run      C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe -s
    ShadowPlay                         Registry\Common\Run      C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
    Sidebar                            Registry\User\Run        C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    StartCCC                           Registry\Common\Run      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe MSRun
          OneNote 2007  StartMenu\User           D:\\Microsoft Office\Office12\ONENOTEM.EXE /tsr


--------[  ]---------------------------------------------------------------------------------------------

  [ Adobe Flash Player Updater ]

     :
                                               Adobe Flash Player Updater
                                                  
                                           C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
                                     
                                            
                                                  Adobe Flash Player        .      , Adobe Flash Player           .
                                        
                                               Adobe Systems Incorporated
                                         07.01.2014 23:55:00
                                         08.01.2014 0:55:00

     :
       #1                                         1 .  3:55  24 . ,   01.01.2000


--------[   ]-------------------------------------------------------------------------------------

    Adguard [ ()]                                                           5.8.1008.5204  
    Adguard                                                                              5.8.1008.5204  
    Adobe Flash Player 11 Plugin                                                          11.9.900.170  
    Adobe Reader X - Russian [ ()]                                                 10.0.0  
    AIMP3                                                                             v3.55.1332, 21.12.2013  
    Alien Swarm                                                                                         
    AMD Catalyst Control Center                                                       2013.1206.1603.28764  
    AMD Catalyst Install Manager                                                             8.0.915.0  
    AMD Fuel                                                                          2013.1206.1603.28764  
    BioShock 2                                                                                          
    BioShock                                                                                            
    Canon LBP6000/LBP6018                                                                               
    Catalyst Control Center - Branding                                                       1.00.0000  
    Catalyst Control Center Graphics Previews Common                                  2013.1206.1603.28764  
    Catalyst Control Center InstallProxy                                              2013.1206.1603.28764  
    Catalyst Control Center Localization All                                          2013.1206.1603.28764  
    CCC Help Chinese Standard                                                         2013.1206.1602.28764  
    CCC Help Chinese Traditional                                                      2013.1206.1602.28764  
    CCC Help Czech                                                                    2013.1206.1602.28764  
    CCC Help Danish                                                                   2013.1206.1602.28764  
    CCC Help Dutch                                                                    2013.1206.1602.28764  
    CCC Help English                                                                  2013.1206.1602.28764  
    CCC Help Finnish                                                                  2013.1206.1602.28764  
    CCC Help French                                                                   2013.1206.1602.28764  
    CCC Help German                                                                   2013.1206.1602.28764  
    CCC Help Greek                                                                    2013.1206.1602.28764  
    CCC Help Hungarian                                                                2013.1206.1602.28764  
    CCC Help Italian                                                                  2013.1206.1602.28764  
    CCC Help Japanese                                                                 2013.1206.1602.28764  
    CCC Help Korean                                                                   2013.1206.1602.28764  
    CCC Help Norwegian                                                                2013.1206.1602.28764  
    CCC Help Polish                                                                   2013.1206.1602.28764  
    CCC Help Portuguese                                                               2013.1206.1602.28764  
    CCC Help Russian                                                                  2013.1206.1602.28764  
    CCC Help Spanish                                                                  2013.1206.1602.28764  
    CCC Help Swedish                                                                  2013.1206.1602.28764  
    CCC Help Thai                                                                     2013.1206.1602.28764  
    CCC Help Turkish                                                                  2013.1206.1602.28764  
    ccc-utility                                                                       2013.1206.1603.28764  
    CCleaner                                                                                            
    Counter-Strike: Global Offensive                                                                    
    Debugging Tools for Windows (x86)                                                       6.11.1.404  
    Far Cry 3                                                                                          
    FastStone Image Viewer 4.6                                                                     4.6  
    FormatFactory 3.00                                                                            3.00  
    GeForce Experience NvStream Client Components [ ()]                            1.6.28  
    GOM Player                                                                             2.2.56.5183  
    Guard@Mail.Ru                                                                            1.0.0.620  
    IIS 7.5 Express                                                                           7.5.1190  
    Kaspersky Anti-Virus [ ()]                                                14.0.0.4651  
    Kaspersky Anti-Virus                                                                   14.0.0.4651  
    Killing Floor                                                                                       
    K-Lite Mega Codec Pack 9.9.9                                                                 9.9.9  
    Lansweeper                                                                                     5.1  
    Left 4 Dead 2                                                                                       
    MediaGet                                                                                            
    Microsoft .NET Framework 4.5.1 (RUS) [ ()]                                  4.5.50938  
    Microsoft .NET Framework 4.5.1 ()                                                 4.5.50938  
    Microsoft .NET Framework 4.5.1                                                           4.5.50938  
    Microsoft .NET Framework 4.5.1                                                           4.5.50938  
    Microsoft Office Access MUI (Russian) 2007 [ ()]                     12.0.4518.1022 - Office 2007 Retail  
    Microsoft Office Enterprise 2007                                                  12.0.4518.1014 - Office 2007 Retail  
    Microsoft Office Enterprise 2007                                                  12.0.4518.1014 - Office 2007 Retail  
    Microsoft Office Excel MUI (Russian) 2007 [ ()]                      12.0.4518.1022 - Office 2007 Retail  
    Microsoft Office Groove MUI (Russian) 2007 [ ()]                     12.0.4518.1022 - Office 2007 Retail  
    Microsoft Office InfoPath MUI (Russian) 2007 [ ()]                   12.0.4518.1022 - Office 2007 Retail  
    Microsoft Office OneNote MUI (Russian) 2007 [ ()]                    12.0.4518.1022 - Office 2007 Retail  
    Microsoft Office Outlook MUI (Russian) 2007 [ ()]                    12.0.4518.1022 - Office 2007 Retail  
    Microsoft Office PowerPoint MUI (Russian) 2007 [ ()]                 12.0.4518.1022 - Office 2007 Retail  
    Microsoft Office Proof (English) 2007                                             12.0.4518.1014 - Office 2007 Retail  
    Microsoft Office Proof (German) 2007 [ ()]                        12.0.4518.1014 - Office 2007 Retail  
    Microsoft Office Proof (Russian) 2007 [ ()]                          12.0.4518.1022 - Office 2007 Retail  
    Microsoft Office Proof (Ukrainian) 2007 [ ()]                    12.0.4518.1022 - Office 2007 Retail  
    Microsoft Office Proofing (Russian) 2007 [ ()]                       12.0.4518.1022 - Office 2007 Retail  
    Microsoft Office Publisher MUI (Russian) 2007 [ ()]                  12.0.4518.1022 - Office 2007 Retail  
    Microsoft Office Shared MUI (Russian) 2007 [ ()]                     12.0.4518.1022 - Office 2007 Retail  
    Microsoft Office Word MUI (Russian) 2007 [ ()]                       12.0.4518.1022 - Office 2007 Retail  
    Microsoft Visual C++ 2005 Redistributable                                                8.0.56336  
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17                             9.0.30729  
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219                             10.0.40219  
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727                          11.0.50727.1  
    Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727                           11.0.50727  
    Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727                              11.0.50727  
    Microsoft Windows SDK for Windows 7 (7.1)                                                7.1.30514  
    Microsoft Windows SDK for Windows 7 (7.1)                                         7.1.7600.0.30514  
    Mozilla Firefox 26.0 (x86 ru)                                                                 26.0  
    Mozilla Maintenance Service                                                                   26.0  
    MSI Afterburner 2.3.0                                                                        2.3.0  
    NVIDIA GeForce Experience 1.8.1 [ ()]                                           1.8.1  
    NVIDIA Install Application [ ()]                                       2.1002.142.992  
    NVIDIA LED Visualizer 1.0 [ ()]                                                   1.0  
    NVIDIA Network Service [ ()]                                                      1.0  
    NVIDIA PhysX                                                                             9.13.0725  
    NVIDIA ShadowPlay 10.11.15 [ ()]                                             10.11.15  
    NVIDIA Stereoscopic 3D Driver                                                         7.17.13.3182  
    NVIDIA Update Core [ ()]                                                     10.11.15  
    NVIDIA Virtual Audio 1.2.19 [ ()]                                              1.2.19  
    NVIDIA  HD 1.3.26.4 [ ()]                                        1.3.26.4  
    NVIDIA   331.82 [ ()]                                        331.82  
    NVIDIA  3D Vision 331.82 [ ()]                                          331.82  
    NVIDIA   3D Vision 331.82 [ ()]                              331.82  
    NVIDIA    PhysX 9.13.0725 [ ()]              9.13.0725  
    PunkBuster Services                                                                                 
    Realtek High Definition Audio Driver []                                          6.0.1.7083  
    SHIELD Streaming [ ()]                                                         1.6.85  
    Steam                                                                                               
    Uplay                                                                                          2.0  
    VLC media player 2.0.6                                                                       2.0.6  
    WinRAR 5.01 (32-)                                                                  5.01.0  
     NVIDIA 10.11.15 [ ()]                                             10.11.15  
      NVIDIA 331.82 [ ()]                                          331.82  
      7.2  Internet Explorer                                              7.2.5.3111  


--------[  ]----------------------------------------------------------------------------------------------------

    Microsoft Internet Explorer 9.0.8112.16421                              D4F6K-QK3RD-TMVMJ-BBMRX-3MBMV
    Microsoft Office Enterprise 2007                                        P3BMW-4MX9J-JTK2W-4XC4V-QRHD8
    Microsoft Windows 7 Ultimate                                            D4F6K-QK3RD-TMVMJ-BBMRX-3MBMV


--------[   ]-------------------------------------------------------------------------------------------------

    386               Virtual Device Driver                                            
    3G2               VLC media file (.3g2)                                            video/3gpp2
    3GA               VLC media file (.3ga)                                            
    3GP               VLC media file (.3gp)                                            video/3gpp
    3GP2              VLC media file (.3gp2)                                           video/3gpp2
    3GPP              VLC media file (.3gpp)                                           video/3gpp
    669               VLC media file (.669)                                            
    7Z                 WinRAR                                                     
    A52               VLC media file (.a52)                                            
    AAC               VLC media file (.aac)                                            audio/vnd.dlna.adts
    AC3               VLC media file (.ac3)                                            
    ACCDA             Microsoft Office Access Add-in                                   application/msaccess
    ACCDB             Microsoft Office Access 2007                           application/msaccess
    ACCDC             Microsoft Office Access Signed Package                           application/msaccess
    ACCDE             Microsoft Office Access ACCDE Database                           application/msaccess
    ACCDR             Microsoft Office Access Runtime Application                      application/msaccess
    ACCDT             Microsoft Office Access Template                                 application/msaccess
    ACCDU             Microsoft Office Access Add-in Data                              
    ACE                WinRAR                                                     
    ACL               AutoCorrect List File                                            
    ACROBATSECURITYSETTINGS  Adobe Acrobat Security Settings Document                         application/vnd.adobe.acrobat-security-settings
    ADE               Microsoft Office Access Project Extension                        application/msaccess
    ADN               Microsoft Office Access Blank Project Template                   
    ADP               Microsoft Office Access Project                                  application/msaccess
    ADT               VLC media file (.adt)                                            audio/vnd.dlna.adts
    ADTS              VLC media file (.adts)                                           audio/vnd.dlna.adts
    AIF               VLC media file (.aif)                                            audio/aiff
    AIFC              VLC media file (.aifc)                                           audio/aiff
    AIFF              VLC media file (.aiff)                                           audio/aiff
    ALAC              ALAC Audio File                                                  
    AMR               VLC media file (.amr)                                            
    AMV               VLC media file (.amv)                                            
    ANI               Animated Cursor                                                  
    AOB               VLC media file (.aob)                                            
    APE               VLC media file (.ape)                                            
    API               API File                                                         
    APPLICATION       Application Manifest                                             application/x-ms-application
    APPREF-MS         Application Reference                                            
    ARJ                WinRAR                                                     
    ASA               ASA File                                                         
    ASF               VLC media file (.asf)                                            video/x-ms-asf
    ASP               ASP File                                                         
    ASX               VLC media file (.asx)                                            video/x-ms-asf
    AU                VLC media file (.au)                                             audio/basic
    AVI               VLC media file (.avi)                                            video/avi
    AW                Answer Wizard File                                               
    B4S               VLC media file (.b4s)                                            
    BAT               Windows Batch File                                               
    BDMV              Blu-ray File                                                     
    BIN               VLC media file (.bin)                                            
    BLG               Performance Monitor File                                         
    BMP               Bitmap Image                                                     image/bmp
    BSP               BSP File                                                         
    BZ                 WinRAR                                                     
    BZ2                WinRAR                                                     
    C2R               C2R File                                                         
    CAB                WinRAR                                                     
    CAF               VLC media file (.caf)                                            
    CAMP              WCS Viewing Condition Profile                                    
    CAT               Security Catalog                                                 application/vnd.ms-pki.seccat
    CDA               VLC media file (.cda)                                            
    CDMP              WCS Device Profile                                               
    CDX               CDX File                                                         
    CER               Security Certificate                                             application/x-x509-ca-cert
    CHESSTITANSSAVE-MS  .ChessTitansSave-ms                                              
    CHK               Recovered File Fragments                                         
    CHM               Compiled HTML Help file                                          
    CMD               Windows Command Script                                           
    COM               MS-DOS Application                                               
    COMFYCAKESSAVE-MS  .ComfyCakesSave-ms                                               
    COMPOSITEFONT     Composite Font File                                              
    CONTACT           Contact File                                                     text/x-ms-contact
    CPL               Control Panel Item                                               
    CRD               Information Card                                                 
    CRDS              Information Card Store                                           
    CRL               Certificate Revocation List                                      application/pkix-crl
    CRT               Security Certificate                                             application/x-x509-ca-cert
    CRTX               Microsoft Office Chart                                    
    CSS               Cascading Style Sheet Document                                   text/css
    CSV                Microsoft Office Excel                                        
    CUE               VLC media file (.cue)                                            
    CUR               Cursor                                                           
    DB                Data Base File                                                   
    DEM               DEM File                                                         
    DER               Security Certificate                                             application/x-x509-ca-cert
    DESKLINK          Desktop Shortcut                                                 
    DET               Office Data File                                                 
    DIAGCAB           Diagnostic Cabinet                                               
    DIAGCFG           Diagnostic Configuration                                         
    DIAGPKG           Diagnostic Document                                              
    DIB               Bitmap Image                                                     image/bmp
    DIC               Text Document                                                    
    DIVX              VLC media file (.divx)                                           
    DLL               Application Extension                                            application/x-msdownload
    DMB               GOM  (.dmb)                                             
    DMSKM             GOM  (.dmskm)                                           
    DOC                Microsoft Office Word 97 - 2003                         application/msword
    DOCHTML            Microsoft Word   HTML                           
    DOCM               Microsoft Office Word                application/vnd.ms-word.document.macroEnabled.12
    DOCMHTML          DOCMHTML File                                                    
    DOCX               Microsoft Office Word                                   application/vnd.openxmlformats-officedocument.wordprocessingml.document
    DOCXML             Microsoft Word   XML                            
    DOT                Microsoft Office Word 97 - 2003                           application/msword
    DOTHTML            Microsoft Word   HTML                             
    DOTM              Microsoft Office Word Macro-Enabled Template                     application/vnd.ms-word.template.macroEnabled.12
    DOTX               Microsoft Office Word                                     application/vnd.openxmlformats-officedocument.wordprocessingml.template
    DQY               Microsoft Office Excel ODBC Query files                          
    DRC               VLC media file (.drc)                                            
    DRV               Device Driver                                                    
    DSN               Microsoft OLE DB Provider for ODBC Drivers                       
    DTS               VLC media file (.dts)                                            
    DV                VLC media file (.dv)                                             
    DVR               Microsoft Recorded TV Show                                       
    DVR-MS            Microsoft Recorded TV Show                                       
    DWFX              XPS Document                                                     model/vnd.dwfx+xps
    EASMX             XPS Document                                                     model/vnd.easmx+xps
    EDRWX             XPS Document                                                     model/vnd.edrwx+xps
    ELM               Microsoft Office Themes File                                     
    EMF               EMF File                                                         
    EMPTYBINARYREGISTRY  URL:OneNote Protocol                                             
    EPF               Exchange Certificate File                                        
    EPRTX             XPS Document                                                     model/vnd.eprtx+xps
    EVO               EVO Video File                                                   
    EVT               EVT File                                                         
    EVTX              EVTX File                                                        
    EXC               Text Document                                                    
    EXE               Application                                                      application/x-msdownload
    F4V               VLC media file (.f4v)                                            
    FAD               Office Data File                                                 
    FDF                 Adobe Acrobat                                      application/vnd.fdf
    FDM               Microsoft Office Outlook Form Definition                         
    FLAC              VLC media file (.flac)                                           
    FLV               VLC media file (.flv)                                            
    FON               Font file                                                        
    FREECELLSAVE-MS   .FreeCellSave-ms                                                 
    GADGET            Windows Gadget                                                   
    GCSX                 Microsoft Office SmartArt                  
    GFS                 Microsoft Office Groove                           
    GIF               GIF Image                                                        image/gif
    GLK                Microsoft Office Groove                                    
    GLOX                Microsoft Office SmartArt                          
    GMMP              WCS Gamut Mapping Profile                                        
    GOM               GOM  (.gom)                                             
    GPS               Gomplayer Skin File                                              application/x-gom-skin
    GQSX              -  Microsoft Office SmartArt                 
    GRA                Microsoft Graph                                        
    GROUP             Contact Group File                                               text/x-ms-group
    GRP               Microsoft Program Group                                          
    GRV                Microsoft Office Groove                                     application/vnd.groove-injector
    GSA                  Microsoft Office Groove                    
    GTA                 Microsoft Office Groove                       
    GXF               VLC media file (.gxf)                                            
    GZ                 WinRAR                                                     
    H1C               Windows Help Collection Definition File                          
    H1D               Windows Help Validator File                                      
    H1F               Windows Help Include File                                        
    H1H               Windows Help Merged Hierarchy                                    
    H1K               Windows Help Index File                                          
    H1Q               Windows Help Merged Query Index                                  
    H1S               Compiled Windows Help file                                       
    H1T               Windows Help Table of Contents File                              
    H1V               Windows Help Virtual Topic Definition File                       
    H1W               Windows Help Merged Keyword Index                                
    HDMOV             HDMOV Video File                                                 
    HEARTSSAVE-MS     .HeartsSave-ms                                                   
    HLP               Help File                                                        
    HOL               Microsoft Office Outlook Holidays                                
    HTA               HTML Application                                                 application/hta
    HTM               HTM File                                                         text/html
    HTML              HTML File                                                        text/html
    HXA               Microsoft Help Attribute Definition File                         application/xml
    HXC               Microsoft Help Collection Definition File                        application/xml
    HXD               Microsoft Help Validator File                                    application/octet-stream
    HXE               Microsoft Help Samples Definition File                           application/xml
    HXF               Microsoft Help Include File                                      application/xml
    HXH               Microsoft Help Merged Hierarchy File                             application/octet-stream
    HXI               Microsoft Help Compiled Index File                               application/octet-stream
    HXK               Microsoft Help Index File                                        application/xml
    HXQ               Microsoft Help Merged Query Index File                           application/octet-stream
    HXR               Microsoft Help Merged Attribute Index File                       application/octet-stream
    HXS               Microsoft Help Compiled Storage File                             application/octet-stream
    HXT               Microsoft Help Table of Contents File                            application/xml
    HXV               Microsoft Help Virtual Topic Definition File                     application/xml
    HXW               Microsoft Help Attribute Definition File                         application/octet-stream
    IBC               InterConnect Bizcard File                                        
    ICC               ICC Profile                                                      
    ICL               Icon Library                                                     
    ICM               ICC Profile                                                      
    ICO               Icon                                                             image/x-icon
    ICS               iCalendar File                                                   
    IFO               VLC media file (.ifo)                                            
    IMG               Disc Image File                                                  
    INF               Setup Information                                                
    INFOPATHXML       Microsoft Office InfoPath Form                                   application/ms-infopath.xml
    INI               Configuration Settings                                           
    IQY               Microsoft Office Excel Web Query File                            text/x-ms-iqy
    ISO                WinRAR                                                     
    IT                VLC media file (.it)                                             
    JAR                WinRAR                                                     
    JFIF              JPEG Image                                                       image/jpeg
    JNT               Journal Document                                                 
    JOB               Task Scheduler Task Object                                       
    JOD               Microsoft.Jet.OLEDB.4.0                                          
    JPE               JPEG Image                                                       image/jpeg
    JPEG              JPEG Image                                                       image/jpeg
    JPG               JPEG Image                                                       image/jpeg
    JPS               JPS File                                                         image/jps
    JS                JScript Script File                                              
    JSE               JScript Encoded File                                             
    JTP               Journal Template                                                 
    JTX               XPS Document                                                     application/x-jtx+xps
    K3G               GOM  (.k3g)                                             
    LABEL             Property List                                                    
    LACCDB            Microsoft Office Access Record-Locking Information               
    LDB               Microsoft Office Access Record-Locking Information               
    LEX               Dictionary File                                                  
    LHA                WinRAR                                                     
    LIBRARY-MS        Library Folder                                                   application/windows-library+xml
    LMP4              GOM  (.lmp4)                                            
    LNK               Shortcut                                                         
    LOG               Text Document                                                    
    LZH                WinRAR                                                     
    M1V               VLC media file (.m1v)                                            video/mpeg
    M2P               MPEG Video File                                                  
    M2T               VLC media file (.m2t)                                            video/vnd.dlna.mpeg-tts
    M2TS              VLC media file (.m2ts)                                           video/vnd.dlna.mpeg-tts
    M2V               VLC media file (.m2v)                                            video/mpeg
    M3U               VLC media file (.m3u)                                            audio/x-mpegurl
    M3U8              VLC media file (.m3u8)                                           
    M4A               VLC media file (.m4a)                                            audio/mp4
    M4P               VLC media file (.m4p)                                            
    M4V               VLC media file (.m4v)                                            video/mp4
    MAD               Microsoft Office Access Module Shortcut                          
    MAF               Microsoft Office Access Form Shortcut                            
    MAG               Microsoft Office Access Diagram Shortcut                         
    MAHJONGTITANSSAVE-MS  .MahjongTitansSave-ms                                            
    MAM               Microsoft Office Access Macro Shortcut                           
    MAPIMAIL          Mail Service                                                     
    MAQ               Microsoft Office Access Query Shortcut                           
    MAR               Microsoft Office Access Report Shortcut                          
    MAS               Microsoft Office Access Stored Procedure Shortcut                
    MAT               Microsoft Office Access Table Shortcut                           
    MAU               MAU File                                                         
    MAV               Microsoft Office Access View Shortcut                            
    MAW               Microsoft Office Access Data Access Page Shortcut                
    MCL               MCL File                                                         
    MDA               Microsoft Office Access Add-in                                   application/msaccess
    MDB               Microsoft Office Access Database                                 application/msaccess
    MDBHTML           Microsoft Office Access HTML Document                            
    MDE               Microsoft Office Access MDE Database                             application/msaccess
    MDN               Microsoft Office Access Blank Database Template                  
    MDT               Microsoft Office Access Add-in Data                              
    MDW               Microsoft Office Access Workgroup Information                    
    MGC               Media Catalog File                                               
    MHT               MHTML Document                                                   message/rfc822
    MHTML             MHTML Document                                                   message/rfc822
    MID               VLC media file (.mid)                                            audio/mid
    MIDI              MIDI Sequence                                                    audio/mid
    MIG               Migration Store                                                  
    MINESWEEPERSAVE-MS  .MinesweeperSave-ms                                              
    MKA               VLC media file (.mka)                                            
    MKV               VLC media file (.mkv)                                            
    MLC               Language Pack File_                                              
    MLP               VLC media file (.mlp)                                            
    MML               Media Catalog File                                               
    MMW               Media Catalog File                                               
    MOD               VLC media file (.mod)                                            video/mpeg
    MOV               VLC media file (.mov)                                            video/quicktime
    MP1               VLC media file (.mp1)                                            
    MP2               VLC media file (.mp2)                                            audio/mpeg
    MP2V              VLC media file (.mp2v)                                           video/mpeg
    MP3               VLC media file (.mp3)                                            audio/mpeg
    MP4               VLC media file (.mp4)                                            video/mp4
    MP4V              VLC media file (.mp4v)                                           video/mp4
    MPA               VLC media file (.mpa)                                            video/mpeg
    MPC               VLC media file (.mpc)                                            
    MPCPL             MPC Playlist File                                                
    MPE               VLC media file (.mpe)                                            video/mpeg
    MPEG              VLC media file (.mpeg)                                           video/mpeg
    MPEG1             VLC media file (.mpeg1)                                          
    MPEG2             VLC media file (.mpeg2)                                          
    MPEG4             VLC media file (.mpeg4)                                          
    MPF               Clip Organizer Media Package File                                application/vnd.ms-mediapackage
    MPG               VLC media file (.mpg)                                            video/mpeg
    MPL               DVD Audio File                                                   
    MPLS              Blu-ray Playlist File                                            
    MPO               MPO File                                                         image/mpo
    MPV2              VLC media file (.mpv2)                                           video/mpeg
    MPV4              MPV4 Video File                                                  
    MQV               GOM  (.mqv)                                             
    MSC               Microsoft Common Console Document                                
    MSDVD             MSDVD File                                                       
    MSG                Outlook                                                  
    MSI               Windows Installer Package                                        
    MSP               Windows Installer Patch                                          
    MSRCINCIDENT      Windows Remote Assistance Invitation                             
    MSSTYLES          Windows Visual Style File                                        
    MSU               Microsoft Update Standalone Package                              
    MTS               VLC media file (.mts)                                            video/vnd.dlna.mpeg-tts
    MTV               VLC media file (.mtv)                                            
    MXF               VLC media file (.mxf)                                            
    MYDOCS            MyDocs Drop Target                                               
    NFO               MSInfo Configuration File                                        
    NICK              Office Data File                                                 
    NK2               Office Data File                                                 
    NSV               VLC media file (.nsv)                                            
    NUV               VLC media file (.nuv)                                            
    OCX               ActiveX control                                                  
    ODC               Microsoft Office Data Connection                                 text/x-ms-odc
    ODCCUBEFILE       ODCCUBEFILE File                                                 
    ODCDATABASEFILE   ODCDATABASEFILE File                                             
    ODCNEWFILE        ODCNEWFILE File                                                  
    ODCTABLEFILE      ODCTABLEFILE File                                                
    ODT               ODT File                                                         
    OFR               OptimFrog Audio File                                             
    OFS               OptimFrog Audio File                                             
    OFT               Outlook Item Template                                            
    OGA               VLC media file (.oga)                                            
    OGG               VLC media file (.ogg)                                            
    OGM               VLC media file (.ogm)                                            
    OGV               VLC media file (.ogv)                                            
    OGX               VLC media file (.ogx)                                            
    OLS               Microsoft Office List Shortcut                                   application/vnd.ms-publisher
    OMA               VLC media file (.oma)                                            
    ONE                Microsoft Office OneNote                                  application/msonenote
    ONEPKG            Microsoft Office OneNote Single File Package                     application/msonenote
    ONETOC            Microsoft Office OneNote 2003 Table Of Contents                  
    ONETOC2           Microsoft Office OneNote Table Of Contents                       
    OPC               Microsoft Clean-up Wizard File                                   
    OPUS              VLC media file (.opus)                                           
    OQY               Microsoft Office Excel OLAP Query File                           
    OSDX              OpenSearch Description File                                      application/opensearchdescription+xml
    OST               Microsoft Office Outlook Offline Folders                         
    OTF               OpenType Font file                                               
    OTM               Outlook VBA Project File                                         
    P10               Certificate Request                                              application/pkcs10
    P12               Personal Information Exchange                                    application/x-pkcs12
    P7B               PKCS #7 Certificates                                             application/x-pkcs7-certificates
    P7C               Digital ID File                                                  application/pkcs7-mime
    P7M               PKCS #7 MIME Message                                             application/pkcs7-mime
    P7R               Certificate Request Response                                     application/x-pkcs7-certreqresp
    P7S               PKCS #7 Signature                                                application/pkcs7-signature
    PAB               Office Data File                                                 
    PARTIAL           Partial Download                                                 
    PBK               Dial-Up Phonebook                                                
    PDF               Adobe Acrobat Document                                           application/pdf
    PDFXML            Adobe Acrobat PDFXML Document                                    application/vnd.adobe.pdfxml
    PDX                Acrobat Catalog                                           application/vnd.adobe.pdx
    PERFMONCFG        Performance Monitor Configuration                                
    PFM               Type 1 Font file                                                 
    PFX               Personal Information Exchange                                    application/x-pkcs12
    PIF               Shortcut to MS-DOS Program                                       
    PIP               Microsoft Office Settings File                                   
    PKO               Public Key Security Object                                       application/vnd.ms-pki.pko
    PLS               VLC media file (.pls)                                            
    PNF               Precompiled Setup Information                                    
    PNG               PNG Image                                                        image/png
    PNS               PNS File                                                         image/pns
    POT                Microsoft Office PowerPoint 97-2003                       application/vnd.ms-powerpoint
    POTHTML           Microsoft Office PowerPoint HTML Template                        
    POTM                Microsoft Office PowerPoint     application/vnd.ms-powerpoint.template.macroEnabled.12
    POTX               Microsoft Office PowerPoint                               application/vnd.openxmlformats-officedocument.presentationml.template
    PPA               Microsoft Office PowerPoint 97-2003 Addin                        application/vnd.ms-powerpoint
    PPAM              Microsoft Office PowerPoint Addin                                application/vnd.ms-powerpoint.addin.macroEnabled.12
    PPS               Microsoft Office PowerPoint 97-2003 Slide Show                   application/vnd.ms-powerpoint
    PPSM              Microsoft Office PowerPoint Macro-Enabled Slide Show             application/vnd.ms-powerpoint.slideshow.macroEnabled.12
    PPSX                Microsoft Office PowerPoint                        application/vnd.openxmlformats-officedocument.presentationml.slideshow
    PPT                Microsoft Office PowerPoint 97-2003                  application/vnd.ms-powerpoint
    PPTHTML           Microsoft Office PowerPoint HTML Document                        
    PPTM               Microsoft Office PowerPoint       application/vnd.ms-powerpoint.presentation.macroEnabled.12
    PPTMHTML          PPTMHTML File                                                    
    PPTX               Microsoft Office PowerPoint                          application/vnd.openxmlformats-officedocument.presentationml.presentation
    PPTXML            Microsoft Office PowerPoint XML Presentation                     
    PRF               PICS Rules File                                                  application/pics-rules
    PRINTEREXPORT     Printer Migration File                                           
    PS1               PS1 File                                                         
    PS1XML            PS1XML File                                                      
    PSC1              PSC1 File                                                        application/PowerShell
    PSD1              PSD1 File                                                        
    PSM1              PSM1 File                                                        
    PST               Microsoft Office Outlook Personal Folders                        
    PUB                Microsoft Office Publisher                              application/vnd.ms-publisher
    PUBHTML           PUBHTML File                                                     
    PUBMHTML          PUBMHTML File                                                    
    PURBLEPAIRSSAVE-MS  .PurblePairsSave-ms                                              
    PURBLESHOPSAVE-MS  .PurbleShopSave-ms                                               
    PWZ               Microsoft PowerPoint Wizard                                      application/vnd.ms-powerpoint
    QCP               VLC media file (.qcp)                                            
    QDS               Directory Query                                                  
    R00                WinRAR                                                     
    R01                WinRAR                                                     
    R02                WinRAR                                                     
    R03                WinRAR                                                     
    R04                WinRAR                                                     
    R05                WinRAR                                                     
    R06                WinRAR                                                     
    R07                WinRAR                                                     
    R08                WinRAR                                                     
    R09                WinRAR                                                     
    R10                WinRAR                                                     
    R11                WinRAR                                                     
    R12                WinRAR                                                     
    R13                WinRAR                                                     
    R14                WinRAR                                                     
    R15                WinRAR                                                     
    R16                WinRAR                                                     
    R17                WinRAR                                                     
    R18                WinRAR                                                     
    R19                WinRAR                                                     
    R20                WinRAR                                                     
    R21                WinRAR                                                     
    R22                WinRAR                                                     
    R23                WinRAR                                                     
    R24                WinRAR                                                     
    R25                WinRAR                                                     
    R26                WinRAR                                                     
    R27                WinRAR                                                     
    R28                WinRAR                                                     
    R29                WinRAR                                                     
    RA                RealMedia Audio File                                             
    RAM               VLC media file (.ram)                                            
    RAR                WinRAR                                                     
    RAT               Rating System File                                               application/rat-file
    RDP               Remote Desktop Connection                                        
    REC               VLC media file (.rec)                                            
    REG               Registration Entries                                             
    RELS              XML Document                                                     
    RESMONCFG         Resource Monitor Configuration                                   
    REV                RAR                                         
    RLE               RLE File                                                         
    RLL               Application Extension                                            
    RM                VLC media file (.rm)                                             
    RMI               VLC media file (.rmi)                                            audio/mid
    RMVB              VLC media file (.rmvb)                                           
    RQY               Microsoft Office Excel OLE DB Query files                        text/x-ms-rqy
    RTF               Rich Text Format                                                 application/msword
    RWZ               Office Data File                                                 
    S3M               VLC media file (.s3m)                                            
    SAV               SAV File                                                         
    SCF               Windows Explorer Command                                         
    SCP               Text Document                                                    
    SCR               Screen saver                                                     
    SCT               Windows Script Component                                         text/scriptlet
    SDP               VLC media file (.sdp)                                            
    SEARCHCONNECTOR-MS  Search Connector Folder                                          application/windows-search-connector+xml
    SEARCH-MS         Saved Search                                                     
    SECSTORE          SECSTORE File                                                    
    SFCACHE           ReadyBoost Cache File                                            
    SHTML             SHTML File                                                       text/html
    SKM               GOM  (.skm)                                             
    SLDM               Microsoft Office PowerPoint             application/vnd.ms-powerpoint.slide.macroEnabled.12
    SLDX               Microsoft Office PowerPoint                                application/vnd.openxmlformats-officedocument.presentationml.slide
    SLK                  Microsoft Office Excel SLK                 application/vnd.ms-excel
    SLUPKG-MS         XrML Digital License Package                                     application/x-ms-license
    SND               VLC media file (.snd)                                            audio/basic
    SOLITAIRESAVE-MS  .SolitaireSave-ms                                                
    SPC               PKCS #7 Certificates                                             application/x-pkcs7-certificates
    SPIDERSOLITAIRESAVE-MS  .SpiderSolitaireSave-ms                                          
    SPX               VLC media file (.spx)                                            
    SST               Microsoft Serialized Certificate Store                           application/vnd.ms-pki.certstore
    STL               Certificate Trust List                                           application/vnd.ms-pki.stl
    SVG               SVG Document                                                     image/svg+xml
    SVI               GOM  (.svi)                                             
    SWF               GOM  (.swf)                                             
    SYS               System file                                                      
    TAK               TAK Audio File                                                   
    TAR                WinRAR                                                     
    TAZ                WinRAR                                                     
    TBZ                WinRAR                                                     
    TBZ2               WinRAR                                                     
    TGZ                WinRAR                                                     
    THEME             Windows Theme File                                               
    THEMEPACK         Windows Theme Pack                                               
    THMX              Microsoft Office Theme                                           application/vnd.ms-officetheme
    TIF               TIF File                                                         image/tiff
    TIFF              TIFF File                                                        image/tiff
    TOD               VLC media file (.tod)                                            
    TP                MPEG-TS Video File                                               
    TPS               MPEG-TS Video File                                               
    TRP               MPEG-TS Video File                                               
    TS                VLC media file (.ts)                                             video/vnd.dlna.mpeg-tts
    TTA               VLC media file (.tta)                                            
    TTC               TrueType Collection Font file                                    
    TTF               TrueType Font file                                               
    TTS               VLC media file (.tts)                                            video/vnd.dlna.mpeg-tts
    TXT               Text Document                                                    text/plain
    TXZ                WinRAR                                                     
    UDL               Microsoft Data Link                                              
    URL               URL File                                                         
    UU                 WinRAR                                                     
    UUE                WinRAR                                                     
    UXDC              UXDC File                                                        
    VBE               VBScript Encoded File                                            
    VBS               VBScript Script File                                             
    VCF               vCard File                                                       text/x-vcard
    VCG                VCard Microsoft Office Groove                           application/vnd.groove-vcard
    VCS               vCalendar File                                                   
    VDX               Microsoft Visio Document                                         application/vnd.ms-visio.viewer
    VLC               VLC media file (.vlc)                                            
    VOB               VLC media file (.vob)                                            
    VOC               VLC media file (.voc)                                            
    VPK               Source Game Add-on                                               
    VQF               VLC media file (.vqf)                                            
    VRO               VLC media file (.vro)                                            
    VSD               Microsoft Visio Document                                         application/vnd.ms-visio.viewer
    VSS               Microsoft Visio Document                                         application/vnd.ms-visio.viewer
    VST               Microsoft Visio Document                                         application/vnd.ms-visio.viewer
    VSX               Microsoft Visio Document                                         application/vnd.ms-visio.viewer
    VTX               Microsoft Visio Document                                         application/vnd.ms-visio.viewer
    VXD               Virtual Device Driver                                            
    W64               VLC media file (.w64)                                            
    WAB               Address Book File                                                
    WAV               VLC media file (.wav)                                            audio/wav
    WAX               Windows Media Audio shortcut                                     audio/x-ms-wax
    WBCAT             Windows Backup Catalog File                                      
    WBK               Microsoft Word Backup Document                                   application/msword
    WCX               Workspace Configuration File                                     
    WDP               Windows Media Photo                                              image/vnd.ms-photo
    WEBPNP            Web Point And Print File                                         
    WEBSITE           Pinned Site Shortcut                                             application/x-mswebsite
    WIZ                Microsoft Word                                            application/msword
    WIZHTML           Microsoft Office Access HTML Template                            
    WM                GOM  (.wm)                                              video/x-ms-wm
    WMA               VLC media file (.wma)                                            audio/x-ms-wma
    WMD               Windows Media Player Download Package                            application/x-ms-wmd
    WMDB              Windows Media Library                                            
    WMF               WMF File                                                         
    WMP               GOM  (.wmp)                                             
    WMS               Windows Media Player Skin File                                   
    WMV               VLC media file (.wmv)                                            video/x-ms-wmv
    WMX               GOM  (.wmx)                                             video/x-ms-wmx
    WMZ               Windows Media Player Skin Package                                application/x-ms-wmz
    WPL               Windows Media playlist                                           application/vnd.ms-wpl
    WSC               Windows Script Component                                         text/scriptlet
    WSF               Windows Script File                                              
    WSH               Windows Script Host Settings File                                
    WTV               Windows Recorded TV Show                                         
    WTX               Text Document                                                    
    WV                VLC media file (.wv)                                             
    WVX               GOM  (.wvx)                                             video/x-ms-wvx
    XA                VLC media file (.xa)                                             
    XAML              Windows Markup File                                              application/xaml+xml
    XBAP              XAML Browser Application                                         application/x-ms-xbap
    XDP                  XML  Adobe Acrobat                         application/vnd.adobe.xdp+xml
    XEVGENXML         XEVGENXML File                                                   
    XFDF                Adobe Acrobat                                      application/vnd.adobe.xfdf
    XHT               XHT File                                                         application/xhtml+xml
    XHTML             XHTML File                                                       application/xhtml+xml
    XLA                Microsoft Office Excel                                application/vnd.ms-excel
    XLAM               Microsoft Office Excel                                application/vnd.ms-excel.addin.macroEnabled.12
    XLK                 Microsoft Office Excel                           application/vnd.ms-excel
    XLL                Microsoft Office Excel XLL                            application/vnd.ms-excel
    XLM                Microsoft Office Excel 4.0                                application/vnd.ms-excel
    XLS                Microsoft Office Excel 97-2003                              application/vnd.ms-excel
    XLSB                Microsoft Office Excel                             application/vnd.ms-excel.sheet.binary.macroEnabled.12
    XLSHTML            Microsoft Office Excel   HTML                   
    XLSM               Microsoft Office Excel                   application/vnd.ms-excel.sheet.macroEnabled.12
    XLSMHTML          XLSMHTML File                                                    
    XLSX               Microsoft Office Excel                                      application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
    XLT                Microsoft Office Excel                                    application/vnd.ms-excel
    XLTHTML            Microsoft Office Excel   HTML                     
    XLTM               Microsoft Office Excel                 application/vnd.ms-excel.template.macroEnabled.12
    XLTX               Microsoft Office Excel                                    application/vnd.openxmlformats-officedocument.spreadsheetml.template
    XLW                 Microsoft Office Excel                           application/vnd.ms-excel
    XLXML             Microsoft Office Excel XML Worksheet                             
    XM                VLC media file (.xm)                                             
    XML               XML Document                                                     text/xml
    XPS               XPS Document                                                     application/vnd.ms-xpsdocument
    XRM-MS            XrML Digital License                                             text/xml
    XSF                  Microsoft Office InfoPath                 
    XSL               XSL Stylesheet                                                   text/xml
    XSN                 Microsoft Office InfoPath                           
    XSPF              VLC media file (.xspf)                                           
    XST               Microsoft Office Outlook Personal Folders                        
    XTP               Microsoft Office InfoPath Template Part File                     
    XXE                WinRAR                                                     
    XZ                 WinRAR                                                     
    Z                  WinRAR                                                     
    ZFSENDTOTARGET    Compressed (zipped) Folder SendTo Target                         
    ZIP                ZIP - WinRAR                                               


--------[    ]--------------------------------------------------------------------------------------

  [ Black Netgraf ]

     :
                                                     Black Netgraf
                                                Shows network usage with history display.
                                                  3.5
                                                   gersma
      Copyright                                          2008
      URL                                               http://gersma.deviantart.com/
                                                   LocalAppData
      XML                                               black_netgraf.gadget\gadget.xml

  [ System Shutdown ]

     :
                                                     System Shutdown
                                                Shutdown, restart or standby the system with a simple click.
                                                  3.0.1.0
                                                   Abe90
      Copyright                                          2010
      URL                                               http://www.abe90.it
                                                   LocalAppData
      XML                                               systemshutdown_rus_by_addgadget_net.gadget\en-US\gadget.xml

  [ System Shutdown ]

     :
                                                     System Shutdown
                                                ,        .   - NextWindows.RU
                                                  3.0.1.0
                                                   Abe90
      Copyright                                          2010
      URL                                               http://www.abe90.it
                                                   LocalAppData
      XML                                               systemshutdown_rus_by_addgadget_net.gadget\ru-RU\gadget.xml

  [ System Shutdown ]

     :
                                                     System Shutdown
                                                Spegni, riavvia o metti in standby il sistema con un semplice click.
                                                  3.0.1.1
                                                   Abe90
      Copyright                                          2010
      URL                                               http://www.abe90.it
                                                   LocalAppData
      XML                                               systemshutdown_rus_by_addgadget_net.gadget\it-IT\gadget.xml

  [ Windows Media Center ]

     :
                                                     Windows Media Center
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               MediaCenter.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Currency.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                     .
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               PicturePuzzle.Gadget\ru-RU\gadget.xml

  [   - ]

     :
                                                       -
                                                   ,     .
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               RSSFeeds.Gadget\ru-RU\gadget.xml

  [   ]

     :
                                                      
                                                      (RAM).
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               CPU.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                  .
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Calendar.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                      .
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Weather.Gadget\ru-RU\gadget.xml

  [   ]

     :
                                                      
                                                     .
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               SlideShow.Gadget\ru-RU\gadget.xml

  [  Live ]

     :
                                                      Live
                                                  .
                                                  1.0.0.0
                                                   Max DELETE
      Copyright                                         2007 Max DELETE Corp.
                                                   LocalAppData
      XML                                               liveclock.gadget\en-US\gadget.xml

  [  ]

     :
                                                     
                                                          .
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Clock.Gadget\ru-RU\gadget.xml


--------[  Windows ]----------------------------------------------------------------------------------------

      :
                                              Microsoft Windows 7 Ultimate
                                       -
      Winlogon Shell                                    explorer.exe
          (UAC)  
                                   

       (DEP, NX, EDB):
                                        
                                        
       ( )                       
       ( )                        


--------[  Windows ]------------------------------------------------------------------------------------------

    (Automatic Update)                                                                             
    Definition Update for Windows Defender - KB915597 (Definition 1.165.1076.0)                   05.01.2014
    Windows Internet Explorer 9  Windows 7                                                     05.01.2014
      Windows 7.6.7600.256                                                         05.01.2014
       Windows (KB958488)                                                          05.01.2014
        .NET Framework 4  Windows XP, Windows Server 2003, Windows Vista, Windows 7  32- (x86)  Windows Server 2008 (KB2604121)              05.01.2014
        .NET Framework 4  Windows XP, Windows Server 2003, Windows Vista, Windows 7  32- (x86)  Windows Server 2008 (KB2656351)              05.01.2014
        .NET Framework 4  Windows XP, Windows Server 2003, Windows Vista, Windows 7  32- (x86)  Windows Server 2008 (KB2729449)              05.01.2014
        .NET Framework 4  Windows XP, Windows Server 2003, Windows Vista, Windows 7  32- (x86)  Windows Server 2008 (KB2737019)              05.01.2014
        .NET Framework 4  Windows XP, Windows Server 2003, Windows Vista, Windows 7  32- (x86)  Windows Server 2008 (KB2742595)              05.01.2014
        .NET Framework 4  Windows XP, Windows Server 2003, Windows Vista, Windows 7  32- (x86)  Windows Server 2008 (KB2789642)              05.01.2014
        Windows 7 (KB2621440)                                     05.01.2014
        Windows 7 (KB979309)                                      05.01.2014
       :  2013 . (KB890830)                            05.01.2014


--------[  ]--------------------------------------------------------------------------------------------------

     Windows                              6.1.7600.16385  


--------[   ]--------------------------------------------------------------------------------------------

    Microsoft Windows Defender                6.1.7600.16385(win7_rtm.090713-1255)


--------[   ]--------------------------------------------------------------------------------------

     :
                                      ()
                            (UTC+04:00) , , -
                               
                                    

    :
       (.)                                      
       (.)                                      Russian
       (ISO 639)                                    ru

    /:
       (.)                                    
       (.)                                    Russia
       (ISO 3166)                                 RU
                                               7

     :
        (.)                          
        (.)                          Russian Ruble
         (.)                   .
         (ISO 4217)                RUB
                                      123456789,00.
                         -123456789,00.

    :
                                           H:mm:ss
                                       dd.MM.yyyy
                                        d MMMM yyyy '.'
                                       123456789,00
                          -123456789,00
                                            first; second; third
                                               0123456789

     :
                                       / 
                                           / 
                                              / 
                                           / 
                                            / 
                                            / 
                                        / 

    :
                                             / 
                                            / 
                                              / 
                                             / 
                                                / 
                                               / 
                                               / 
                                            / 
                                           / 
                                            / 
                                             / 
                                            / 

    :
                                            Gregorian (localized)
                                 A4
                                        

    :
      LCID 0419h ()                              ()


--------[  ]---------------------------------------------------------------------------------------------------

    ALLUSERSPROFILE           C:\ProgramData
    APPDATA                   C:\Users\\AppData\Roaming
    CommonProgramFiles        C:\Program Files\Common Files
    COMPUTERNAME              -
    ComSpec                   C:\Windows\system32\cmd.exe
    FP_NO_HOST_CHECK          NO
    HOMEDRIVE                 C:
    HOMEPATH                  \Users\
    LOCALAPPDATA              C:\Users\\AppData\Local
    LOGONSERVER               \\-
    NUMBER_OF_PROCESSORS      3
    OS                        Windows_NT
    Path                      C:\Program Files\NVIDIA Corporation\PhysX\Common;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static
    PATHEXT                   .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    PROCESSOR_ARCHITECTURE    x86
    PROCESSOR_IDENTIFIER      x86 Family 16 Model 5 Stepping 2, AuthenticAMD
    PROCESSOR_LEVEL           16
    PROCESSOR_REVISION        0502
    ProgramData               C:\ProgramData
    ProgramFiles              C:\Program Files
    PSModulePath              C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
    PUBLIC                    C:\Users\Public
    SESSIONNAME               Console
    SystemDrive               C:
    SystemRoot                C:\Windows
    TEMP                      C:\Users\836D~1\AppData\Local\Temp
    TMP                       C:\Users\836D~1\AppData\Local\Temp
    USERDOMAIN                -
    USERNAME                  
    USERPROFILE               C:\Users\
    windir                    C:\Windows


--------[   ]-------------------------------------------------------------------------------------------

    Flash Player                                Flash Player
    Windows CardSpace                                  -    .
                                         -, DVD  ,      ,  ,   ,  .
                                 
                            .      .
     Windows                           ,       .
                                                Windows.
                                .
                                     ,       .
                .
     Realtek HD                      Realtek HD   
                                  .
                           Windows.
                                   ,         .
     Windows                                 
                                                .
                         ,      .
                                      , ,       .
                                            , ,  ,   ,     .
        ''''                ''''   , ,       .
      NVIDIA                     NVIDIA.
                             
                                    .
                                 ,       .
           RemoteApp          RemoteApp
                                          Microsoft Office Outlook
                                  Windows    .
                                .
                          ,      ,     ,  ,      .
                                 
                             .
                                .
                                               , ,  .
               .   ,   , ,    .
                                           .
                                 ,   .
                                .
                              ,    
                          ,    .
      Windows                       ,    ,   .
                                       .
                                  ( ).
                     .
             ,            .
      BitLocker                       BitLocker.
                                           ,    .
                                                .
                                          .
                      ,  ,  ,   .


--------[  ]-----------------------------------------------------------------------------------------------------

    C:      2097          4      ?  ?
    D:      4881          3      ?  ?
    G:      1487          6      ?  ?


--------[   ]---------------------------------------------------------------------------------------------

  [ autoexec.bat ]

    REM Dummy file for NTVDM

  [ config.sys ]

    FILES=40

  [ autoexec.nt ]

    @echo off
    
    REM AUTOEXEC.BAT is not used to initialize the MS-DOS environment.
    REM AUTOEXEC.NT is used to initialize the MS-DOS environment unless a
    REM different startup file is specified in an application's PIF.
    
    REM Install CD ROM extensions
    lh %SystemRoot%\system32\mscdexnt.exe
    
    REM Install network redirector (load before dosx.exe)
    lh %SystemRoot%\system32\redir
    
    REM Install DPMI support
    lh %SystemRoot%\system32\dosx
    
    REM The following line enables Sound Blaster 2.0 support on NTVDM.
    REM The command for setting the BLASTER environment is as follows:
    REM    SET BLASTER=A220 I5 D1 P330
    REM    where:
    REM        A    specifies the sound blaster's base I/O port
    REM        I    specifies the interrupt request line
    REM        D    specifies the 8-bit DMA channel
    REM        P    specifies the MPU-401 base I/O port
    REM        T    specifies the type of sound blaster card
    REM                 1 - Sound Blaster 1.5
    REM                 2 - Sound Blaster Pro I
    REM                 3 - Sound Blaster 2.0
    REM                 4 - Sound Blaster Pro II
    REM                 6 - SOund Blaster 16/AWE 32/32/64
    REM
    REM    The default value is A220 I5 D1 T3 and P330.  If any of the switches is
    REM    left unspecified, the default value will be used. (NOTE, since all the
    REM    ports are virtualized, the information provided here does not have to
    REM    match the real hardware setting.)  NTVDM supports Sound Blaster 2.0 only.
    REM    The T switch must be set to 3, if specified.
    SET BLASTER=A220 I5 D1 P330 T3
    
    REM To disable the sound blaster 2.0 support on NTVDM, specify an invalid
    REM SB base I/O port address.  For example:
    REM    SET BLASTER=A0

  [ config.nt ]

    REM Windows MS-DOS Startup File
    REM
    REM CONFIG.SYS vs CONFIG.NT
    REM CONFIG.SYS is not used to initialize the MS-DOS environment.
    REM CONFIG.NT is used to initialize the MS-DOS environment unless a
    REM different startup file is specified in an application's PIF.
    REM
    REM ECHOCONFIG
    REM By default, no information is displayed when the MS-DOS environment
    REM is initialized. To display CONFIG.NT/AUTOEXEC.NT information, add
    REM the command echoconfig to CONFIG.NT or other startup file.
    REM
    REM NTCMDPROMPT
    REM When you return to the command prompt from a TSR or while running an
    REM MS-DOS-based application, Windows runs COMMAND.COM. This allows the
    REM TSR to remain active. To run CMD.EXE, the Windows command prompt,
    REM rather than COMMAND.COM, add the command ntcmdprompt to CONFIG.NT or
    REM other startup file.
    REM
    REM DOSONLY
    REM By default, you can start any type of application when running
    REM COMMAND.COM. If you start an application other than an MS-DOS-based
    REM application, any running TSR may be disrupted. To ensure that only
    REM MS-DOS-based applications can be started, add the command dosonly to
    REM CONFIG.NT or other startup file.
    REM
    REM EMM
    REM You can use EMM command line to configure EMM(Expanded Memory Manager).
    REM The syntax is:
    REM
    REM EMM = [A=AltRegSets] [B=BaseSegment] [RAM]
    REM
    REM     AltRegSets
    REM         specifies the total Alternative Mapping Register Sets you
    REM         want the system to support. 1 <= AltRegSets <= 255. The
    REM         default value is 8.
    REM     BaseSegment
    REM         specifies the starting segment address in the Dos conventional
    REM         memory you want the system to allocate for EMM page frames.
    REM         The value must be given in Hexdecimal.
    REM         0x1000 <= BaseSegment <= 0x4000. The value is rounded down to
    REM         16KB boundary. The default value is 0x4000
    REM     RAM
    REM         specifies that the system should only allocate 64Kb address
    REM         space from the Upper Memory Block(UMB) area for EMM page frames
    REM         and leave the rests(if available) to be used by DOS to support
    REM         loadhigh and devicehigh commands. The system, by default, would
    REM         allocate all possible and available UMB for page frames.
    REM
    REM     The EMM size is determined by pif file(either the one associated
    REM     with your application or _default.pif). If the size from PIF file
    REM     is zero, EMM will be disabled and the EMM line will be ignored.
    REM
    dos=high, umb
    device=%SystemRoot%\system32\himem.sys
    files=40

  [ system.ini ]

    ; for 16-bit app support
    [386Enh]
    woafont=dosapp.fon
    EGA80WOA.FON=EGA80WOA.FON
    EGA40WOA.FON=EGA40WOA.FON
    CGA80WOA.FON=CGA80WOA.FON
    CGA40WOA.FON=CGA40WOA.FON
    
    [drivers]
    wave=mmdrv.dll
    timer=timer.drv
    
    [mci]

  [ win.ini ]

    ; for 16-bit app support
    [fonts]
    [extensions]
    [mci extensions]
    [files]
    [Mail]
    MAPI=1
    CMCDLLNAME32=mapi32.dll
    CMC=1
    MAPIX=1
    MAPIXVER=1.0.0.1
    OLEMessaging=1
    [MCI Extensions.BAK]
    3g2=MPEGVideo
    3gp=MPEGVideo
    3gp2=MPEGVideo
    3gpp=MPEGVideo
    aac=MPEGVideo
    adt=MPEGVideo
    adts=MPEGVideo
    m2t=MPEGVideo
    m2ts=MPEGVideo
    m2v=MPEGVideo
    m4a=MPEGVideo
    m4v=MPEGVideo
    mod=MPEGVideo
    mov=MPEGVideo
    mp4=MPEGVideo
    mp4v=MPEGVideo
    mts=MPEGVideo
    ts=MPEGVideo
    tts=MPEGVideo

  [ hosts ]

    

  [ lmhosts.sam ]

    
    
    
    


--------[   ]---------------------------------------------------------------------------------------------

    Administrative Tools         C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    AppData                      C:\Users\\AppData\Roaming
    Cache                        C:\Users\\AppData\Local\Microsoft\Windows\Temporary Internet Files
    CD Burning                   C:\Users\\AppData\Local\Microsoft\Windows\Burn\Burn1
    Common Administrative Tools  C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    Common AppData               C:\ProgramData
    Common Desktop               C:\Users\Public\Desktop
    Common Documents             C:\Users\Public\Documents
    Common Favorites             C:\Users\\Favorites
    Common Files                 C:\Program Files\Common Files
    Common Music                 C:\Users\Public\Music
    Common Pictures              C:\Users\Public\Pictures
    Common Programs              C:\ProgramData\Microsoft\Windows\Start Menu\Programs
    Common Start Menu            C:\ProgramData\Microsoft\Windows\Start Menu
    Common Startup               C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
    Common Templates             C:\ProgramData\Microsoft\Windows\Templates
    Common Video                 C:\Users\Public\Videos
    Cookies                      C:\Users\\AppData\Roaming\Microsoft\Windows\Cookies
    Desktop                      C:\Users\\Desktop
    Device                       C:\Windows\inf
    Favorites                    C:\Users\\Favorites
    Fonts                        C:\Windows\Fonts
    History                      C:\Users\\AppData\Local\Microsoft\Windows\History
    Local AppData                C:\Users\\AppData\Local
    My Documents                 C:\Users\\Documents
    My Music                     C:\Users\\Music
    My Pictures                  C:\Users\\Pictures
    My Video                     C:\Users\\Videos
    NetHood                      C:\Users\\AppData\Roaming\Microsoft\Windows\Network Shortcuts
    PrintHood                    C:\Users\\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
    Profile                      C:\Users\
    Program Files                C:\Program Files
    Programs                     C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
    Recent                       C:\Users\\AppData\Roaming\Microsoft\Windows\Recent
    Resources                    C:\Windows\resources
    SendTo                       C:\Users\\AppData\Roaming\Microsoft\Windows\SendTo
    Start Menu                   C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu
    Startup                      C:\Users\\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
    System                       C:\Windows\system32
    Temp                         C:\Users\836D~1\AppData\Local\Temp\
    Templates                    C:\Users\\AppData\Roaming\Microsoft\Windows\Templates
    Windows                      C:\Windows


--------[   ]-------------------------------------------------------------------------------------------

                       2014-01-05 16:06:14                           Microsoft-Windows-User Profiles Service  1530:  Windows ,        .    .   ,    ,    .        -    1 user registry handles leaked from \Registry\User\S-1-5-21-839303928-1106944401-891866635-1000: Process 408 (\Device\HarddiskVolume2\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000   
                         2014-01-05 16:09:41                                  Software Protection Platform Service  1017:       . 0xC004F015   Pkey=GPDD4  ACID=b92e9980-b9d5-4821-9c94-140f632f6312    [?]    
                         2014-01-05 16:09:53                                  Software Protection Platform Service  1017:       . 0xC004F015   Pkey=QY7MG  ACID=54a09a0d-d57b-4c10-8b69-a842d6590ad5    [?]    
                         2014-01-05 16:10:06                                  Software Protection Platform Service  1017:       . 0xC004F015   Pkey=HVTHH  ACID=ae2ee509-1b34-41c0-acb7-6d4650168915    [?]    
                         2014-01-05 16:10:18                                  Software Protection Platform Service  1017:       . 0xC004F015   Pkey=XCKRJ  ACID=1cb6d605-11b3-4e14-bb30-da91c8e3983a    [?]    
                         2014-01-05 16:10:30                                  Software Protection Platform Service  1017:       . 0xC004F015   Pkey=H9DH4  ACID=46bbed08-9c7b-48fc-a614-95250573f4ea    [?]    
                       2014-01-05 16:10:52                                  Software Protection Platform Service  1015: HRESULT ().  hr=0xC004F022,  hr=0x80049E00  
               1          2014-01-05 16:25:59                                  ASP.NET 4.0.30319.0             1020:    IIS  ,      IIS   ,  .   ASP.NET    IIS,    IIS    ASP.NET  aspnet_regiis.exe /i.  
               1          2014-01-05 16:26:27                                  ASP.NET 4.0.30319.0             1020:    IIS  ,      IIS   ,  .   ASP.NET    IIS,    IIS    ASP.NET  aspnet_regiis.exe /i.  
                         2014-01-05 16:26:55                                  NvStreamSvc                     
                         2014-01-05 16:26:55                                  NvStreamSvc                     
                       2014-01-05 16:44:05                           Microsoft-Windows-User Profiles Service  1530:  Windows ,        .    .   ,    ,    .        -    6 user registry handles leaked from \Registry\User\S-1-5-21-839303928-1106944401-891866635-1000: Process 1044 (\Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000 Process 3944 (\Device\HarddiskVolume2\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000 Process 3944 (\Device\HarddiskVolume2\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\Direct3D Process 1284 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\Windows\CurrentVersion\Explorer Process 1044 (\Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\Windows\CurrentVersion\Explorer Process 3944 (\Device\HarddiskVolume2\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\Windows NT\CurrentVersion   
                       2014-01-05 16:44:06                           Microsoft-Windows-User Profiles Service  1530:  Windows ,        .    .   ,    ,    .        -    1 user registry handles leaked from \Registry\User\S-1-5-21-839303928-1106944401-891866635-1000_Classes: Process 1044 (\Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000_CLASSES   
                         2014-01-05 16:45:06                                  NVNetworkService                
                         2014-01-05 16:45:45                                  NvStreamSvc                     
                         2014-01-05 16:45:45                                  NvStreamSvc                     
                         2014-01-05 17:06:08                                  NvStreamSvc                     
                         2014-01-05 17:06:08                                  NvStreamSvc                     
                         2014-01-05 17:06:36                                  VSS                             8194:    :      IVssWriterCallback.  hr = 0x80070005,   .  .     -        .    :         :       : {e8132975-6f93-4464-a53e-1050253ae220}      : System Writer       : {f24f37d3-4fe8-4919-8145-2b08515236aa}  
                 101        2014-01-05 17:09:05                                  Application Hang                1002:  GFExperience.exe  10.11.15.0    Windows   .  ,      ,         .     : 1388     : 01cf0a171040c377     : 0     : C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\GFExperience.exe     : 8bf7a08f-760a-11e3-a230-90e6bac09cc4    
                       2014-01-05 17:14:43                           Microsoft-Windows-User Profiles Service  1530:  Windows ,        .    .   ,    ,    .        -    6 user registry handles leaked from \Registry\User\S-1-5-21-839303928-1106944401-891866635-1000: Process 2120 (\Device\HarddiskVolume2\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000 Process 5352 (\Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000 Process 2120 (\Device\HarddiskVolume2\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\Direct3D Process 3388 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\Windows\CurrentVersion\Explorer Process 5352 (\Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\Windows\CurrentVersion\Explorer Process 2120 (\Device\HarddiskVolume2\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\Windows NT\CurrentVersion   
                       2014-01-05 17:14:44                           Microsoft-Windows-User Profiles Service  1530:  Windows ,        .    .   ,    ,    .        -    1 user registry handles leaked from \Registry\User\S-1-5-21-839303928-1106944401-891866635-1000_Classes: Process 5352 (\Device\HarddiskVolume2\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000_CLASSES   
               3          2014-01-05 17:18:54                                  Windows Search Service          3036:     <C:\ProgramData\Microsoft\Windows\Start Menu\> .  :  "",  "SystemIndex"  :  URL-       .       , ,         .  (HRESULT : 0x80040d0d) (0x80040d0d)   
               3          2014-01-05 17:19:06                                  Windows Search Service          3036:     <csc://{S-1-5-21-839303928-1106944401-891866635-1000}/> .  :  "",  "SystemIndex"  :  URL-       .       , ,         .  (HRESULT : 0x80040d0d) (0x80040d0d)   
               3          2014-01-05 17:19:06                                  Windows Search Service          3023:   ,               .  :  "",  "SystemIndex"  :  URL-       .       , ,         .  (HRESULT : 0x80040d0d) (0x80040d0d)   
               3          2014-01-05 17:20:43                                  Windows Search Service          3036:     <iehistory://{S-1-5-21-839303928-1106944401-891866635-1000}/> .  :  "",  "SystemIndex"  :  URL-       .       , ,         .  (HRESULT : 0x80040d0d) (0x80040d0d)   
               3          2014-01-05 17:20:43                                  Windows Search Service          3023:   ,               .  :  "",  "SystemIndex"  :  URL-       .       , ,         .  (HRESULT : 0x80040d0d) (0x80040d0d)   
                       2014-01-05 18:01:38                           Microsoft-Windows-User Profiles Service  1530:  Windows ,        .    .   ,    ,    .        -    1 user registry handles leaked from \Registry\User\S-1-5-21-839303928-1106944401-891866635-1000: Process 3676 (\Device\HarddiskVolume2\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\Windows\CurrentVersion\Explorer   
                       2014-01-05 18:01:49                                  Microsoft-Windows-CAPI2         4102:    crypt32 ( : 50);      60 .  
               3          2014-01-05 18:03:04                                  Windows Search Service          3036:     <csc://{S-1-5-21-839303928-1106944401-891866635-1000}/> .  :  "",  "SystemIndex"  :  URL-       .       , ,         .  (HRESULT : 0x80040d0d) (0x80040d0d)   
               3          2014-01-05 18:17:12                                  Windows Search Service          3036:     <csc://{S-1-5-21-839303928-1106944401-891866635-1000}/> .  :  "",  "SystemIndex"  :  URL-       .       , ,         .  (HRESULT : 0x80040d0d) (0x80040d0d)   
                       2014-01-05 18:27:19                           WinMgmt                         
                       2014-01-05 18:27:19                           WinMgmt                         
               3          2014-01-05 18:29:12                                  Windows Search Service          3036:     <csc://{S-1-5-21-839303928-1106944401-891866635-1000}/> .  :  "",  "SystemIndex"  :  URL-       .       , ,         .  (HRESULT : 0x80040d0d) (0x80040d0d)   
               1          2014-01-05 19:00:55                                  Windows Search Service          1008:  Windows Search        (:   ).    
                         2014-01-05 21:21:52                                  VSS                             8194:    :      IVssWriterCallback.  hr = 0x80070005,   .  .     -        .    :         :       : {e8132975-6f93-4464-a53e-1050253ae220}      : System Writer       : {e2f66ee6-2737-4a21-af3a-fbed37c6dbde}  
                 100        2014-01-05 22:36:07                                  Application Error               1000:   : csgo.exe, : 0.0.0.0,  : 0x521bba5d    : tier0.dll, : 0.0.0.0,   0x52b81fc9   : 0x40000015   : 0x0001f776    : 0x15f8     : 0x01cf0a4483a0ceab    : D:\Program Files\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe    : D:\Program Files\Steam\steamapps\common\Counter-Strike Global Offensive\bin\tier0.dll   : 3d0db2ac-7638-11e3-b73b-90e6bac09cc4
                 100        2014-01-05 22:40:08                                  Application Error               1000:   : csgo.exe, : 0.0.0.0,  : 0x521bba5d    : tier0.dll, : 0.0.0.0,   0x52b81fc9   : 0x40000015   : 0x0001f776    : 0x11e0     : 0x01cf0a450810a624    : D:\Program Files\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe    : D:\Program Files\Steam\steamapps\common\Counter-Strike Global Offensive\bin\tier0.dll   : cc6c4847-7638-11e3-b73b-90e6bac09cc4
                 100        2014-01-05 22:45:32                                  Application Error               1000:   : csgo.exe, : 0.0.0.0,  : 0x521bba5d    : tier0.dll, : 0.0.0.0,   0x52b81fc9   : 0x40000015   : 0x0001f776    : 0x1dc     : 0x01cf0a459ba23a66    : D:\Program Files\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe    : D:\Program Files\Steam\steamapps\common\Counter-Strike Global Offensive\bin\tier0.dll   : 8e0d8b10-7639-11e3-b73b-90e6bac09cc4
                       2014-01-05 23:17:10  1332                            Microsoft-Windows-RestartManager  10010:     "D:\\Adguard\Adguard.exe" (  5100) - 1.  
                         2014-01-05 23:22:50  1332                            MsiInstaller                    11935: : Microsoft Visual C++ 2005 Redistributable -- Error 1935.    "Microsoft.VC80.ATL,type="win32",version="8.0.50727.762",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86"".          . HRESULT: 0x80070BC9.  : IAssemblyCacheItem, : Commit, : {97F81AF1-0E47-DC99-A01F-C8B3B9A1E18E}  
                 101        2014-01-05 23:25:19                                  Application Hang                1002:  msiexec.exe  5.0.7600.16385    Windows   .  ,      ,         .     : c94     : 01cf0a4b78d6ad8c     : 3     : C:\Windows\system32\msiexec.exe     :     
                 100        2014-01-05 23:25:48                                  Application Error               1000:   : bioshock.exe, : 1.0.0.0,  : 0x474f5a3a    : OLEAUT32.dll, : 6.1.7600.16385,   0x4a5bdaca   : 0xc0000005   : 0x00004971    : 0x14c0     : 0x01cf0a4bea6ca050    : D:\Program Files\Steam\steamapps\common\Bioshock\Builds\Release\bioshock.exe    : C:\Windows\system32\OLEAUT32.dll   : 2da017e8-763f-11e3-b73b-90e6bac09cc4
                 100        2014-01-05 23:26:01                                  Application Error               1000:   : bioshock.exe, : 1.0.0.0,  : 0x474f5a3a    : OLEAUT32.dll, : 6.1.7600.16385,   0x4a5bdaca   : 0xc0000005   : 0x00004971    : 0xecc     : 0x01cf0a4bf537d25e    : D:\Program Files\Steam\steamapps\common\Bioshock\Builds\Release\bioshock.exe    : C:\Windows\system32\OLEAUT32.dll   : 357929ba-763f-11e3-b73b-90e6bac09cc4
                       2014-01-05 23:40:15  1332                            Microsoft-Windows-RestartManager  10010:     "D:\\Adguard\Adguard.exe" (  5100) - 1.  
               1          2014-01-05 23:54:22                                  ASP.NET 4.0.30319.0             1020:    IIS  ,      IIS   ,  .   ASP.NET    IIS,    IIS    ASP.NET  aspnet_regiis.exe /i.  
               1          2014-01-05 23:55:17                                  ASP.NET 4.0.30319.0             1020:    IIS  ,      IIS   ,  .   ASP.NET    IIS,    IIS    ASP.NET  aspnet_regiis.exe /i.  
                 100        2014-01-05 23:56:04                                  Application Error               1000:   : GOM.EXE, : 2.2.56.5183,  : 0x52b247e0    : nvd3dum.dll, : 9.18.13.3182,   0x4f6f86ef   : 0xc0000005   : 0x0081862f    : 0x16f8     : 0x01cf0a46a4622b1a    : D:\\GomPlayer\GOM.EXE    : C:\Windows\system32\nvd3dum.dll   : 682866d1-7643-11e3-b73b-90e6bac09cc4
                         2014-01-05 23:58:44                                  NvStreamSvc                     
                         2014-01-05 23:58:44                                  NvStreamSvc                     
                 100        2014-01-05 23:59:00                                  Application Error               1000:   : csgo.exe, : 0.0.0.0,  : 0x521bba5d    : tier0.dll, : 0.0.0.0,   0x52b81fc9   : 0x40000015   : 0x0001f776    : 0x1358     : 0x01cf0a505e1290c0    : D:\Program Files\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe    : D:\Program Files\Steam\steamapps\common\Counter-Strike Global Offensive\bin\tier0.dll   : d14435b8-7643-11e3-a067-90e6bac09cc4
                       2014-01-06 00:00:53                           Microsoft-Windows-User Profiles Service  1530:  Windows ,        .    .   ,    ,    .        -    15 user registry handles leaked from \Registry\User\S-1-5-21-839303928-1106944401-891866635-1000: Process 1612 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000 Process 1612 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000 Process 1612 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000 Process 1612 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000 Process 1612 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\SystemCertificates\TrustedPeople Process 1612 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\SystemCertificates\Disallowed Process 1612 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\SystemCertificates\My Process 1612 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\SystemCertificates\CA Process 1612 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\SystemCertificates\Root Process 1612 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\SystemCertificates\SmartCardRoot Process 1612 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Policies\Microsoft\SystemCertificates Process 1612 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Policies\Microsoft\SystemCertificates Process 1612 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Policies\Microsoft\SystemCertificates Process 1612 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Policies\Microsoft\SystemCertificates Process 1612 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\SystemCertificates\trust   
                         2014-01-06 00:04:54                                  NvStreamSvc                     
                         2014-01-06 00:04:54                                  NvStreamSvc                     
                       2014-01-06 00:06:55                                  Wlclntfy                        6004:        winlogon <TrustedInstaller>.  
                         2014-01-06 00:09:00                                  NvStreamSvc                     
                         2014-01-06 00:09:00                                  NvStreamSvc                     
                         2014-01-06 02:57:41                                  NvStreamSvc                     
                         2014-01-06 02:57:41                                  NvStreamSvc                     
                       2014-01-06 02:58:23                           Microsoft-Windows-User Profiles Service  1530:  Windows ,        .    .   ,    ,    .        -    15 user registry handles leaked from \Registry\User\S-1-5-21-839303928-1106944401-891866635-1000: Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000 Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000 Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000 Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000 Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\SystemCertificates\TrustedPeople Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\SystemCertificates\Disallowed Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\SystemCertificates\My Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\SystemCertificates\CA Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\SystemCertificates\Root Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\SystemCertificates\SmartCardRoot Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Policies\Microsoft\SystemCertificates Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Policies\Microsoft\SystemCertificates Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Policies\Microsoft\SystemCertificates Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Policies\Microsoft\SystemCertificates Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-1000\Software\Microsoft\SystemCertificates\trust   
                         2014-01-06 03:00:14                                  NvStreamSvc                     
                         2014-01-06 03:00:14                                  NvStreamSvc                     
                 101        2014-01-06 03:25:42                                  Application Hang                1002:  firefox.exe  26.0.0.5087    Windows   .  ,      ,         .     : 8dc     : 01cf0a6a16aa75ec     : 41     : C:\Program Files\Mozilla Firefox\firefox.exe     : afa88e5a-7660-11e3-9f1f-90e6bac09cc4    
                         2014-01-06 03:44:46                                  NvStreamSvc                     
                         2014-01-06 03:44:46                                  NvStreamSvc                     
                         2014-01-06 10:53:03                                  NvStreamSvc                     
                         2014-01-06 10:53:03                                  NvStreamSvc                     
                         2014-01-06 11:35:01                                  NvStreamSvc                     
                         2014-01-06 11:35:01                                  NvStreamSvc                     
                         2014-01-06 13:33:20                                  NvStreamSvc                     
                         2014-01-06 13:33:20                                  NvStreamSvc                     
                         2014-01-06 13:38:56                                  NvStreamSvc                     
                         2014-01-06 13:38:56                                  NvStreamSvc                     
                         2014-01-06 13:38:56                                  NvStreamSvc                     
                         2014-01-06 14:37:00                                  NvStreamSvc                     
                         2014-01-06 14:37:00                                  NvStreamSvc                     
                         2014-01-06 14:51:36                                  NvStreamSvc                     
                         2014-01-06 14:51:36                                  NvStreamSvc                     
                         2014-01-06 15:06:17                                  NvStreamSvc                     
                         2014-01-06 15:06:17                                  NvStreamSvc                     
                         2014-01-06 15:15:42                                  NvStreamSvc                     
                         2014-01-06 15:15:42                                  NvStreamSvc                     
                       2014-01-06 15:27:07                           Microsoft-Windows-User Profiles Service  1530:  Windows ,        .    .   ,    ,    .        -    1 user registry handles leaked from \Registry\User\S-1-5-21-839303928-1106944401-891866635-500: Process 624 (\Device\HarddiskVolume2\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500   
                         2014-01-06 15:28:57                                  NvStreamSvc                     
                         2014-01-06 15:28:57                                  NvStreamSvc                     
                       2014-01-06 15:37:40                     Microsoft-Windows-RestartManager  10010:     "C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Extended\Setup.exe" (  4552) - 1.  
                         2014-01-06 15:39:50                                  NvStreamSvc                     
                         2014-01-06 15:39:50                                  NvStreamSvc                     
                       2014-01-06 15:40:47                     Microsoft-Windows-RestartManager  10010:     "C:\Windows\Microsoft.NET\Framework\v4.0.30319\SetupCache\Client\Setup.exe" (  4028) - 1.  
                         2014-01-06 15:41:53                                  .NET Runtime Optimization Service  1101: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: Microsoft.CSharp, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070002    
                         2014-01-06 15:41:53                                  .NET Runtime Optimization Service  1101: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: PresentationCore, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35 . Error code = 0x80070002    
                         2014-01-06 15:41:53                                  .NET Runtime Optimization Service  1101: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: PresentationFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35 . Error code = 0x80070002    
                         2014-01-06 15:41:54                                  .NET Runtime Optimization Service  1101: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: PresentationFramework.Aero, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35 . Error code = 0x80070002    
                         2014-01-06 15:41:54                                  .NET Runtime Optimization Service  1101: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: PresentationFramework.Classic, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35 . Error code = 0x80070002    
                         2014-01-06 15:41:54                                  .NET Runtime Optimization Service  1101: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: PresentationFramework.Luna, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35 . Error code = 0x80070002    
                         2014-01-06 15:41:54                                  .NET Runtime Optimization Service  1101: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: PresentationFramework.Royale, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35 . Error code = 0x80070002    
                         2014-01-06 15:41:54                                  .NET Runtime Optimization Service  1101: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80131040    
                         2014-01-06 15:41:55                                  .NET Runtime Optimization Service  1101: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: System.ComponentModel.Composition, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070002    
                         2014-01-06 15:41:55                                  .NET Runtime Optimization Service  1101: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070002    
                         2014-01-06 15:41:55                                  .NET Runtime Optimization Service  1101: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: System.Data, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80131040    
                         2014-01-06 15:41:55                                  .NET Runtime Optimization Service  1101: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: System.Data.Linq, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070002    
                         2014-01-06 15:41:56                                  .NET Runtime Optimization Service  1101: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: System.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80131040    
                         2014-01-06 15:41:56                                  .NET Runtime Optimization Service  1101: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80131040    
                         2014-01-06 15:41:56                                  .NET Runtime Optimization Service  1101: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: System.Drawing.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80131040    
                         2014-01-06 15:41:56                                  .NET Runtime Optimization Service  1101: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: System.Dynamic, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070002    
                         2014-01-06 15:41:56                                  .NET Runtime Optimization Service  1101: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80131040    
                         2014-01-06 15:41:57                                  .NET Runtime Optimization Service  1101: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80131040    
                         2014-01-06 15:41:57                                  .NET Runtime Optimization Service  1101: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Failed to compile: WindowsBase, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35 . Error code = 0x80070002    
                         2014-01-06 15:43:45                                  NvStreamSvc                     
                         2014-01-06 15:43:45                                  NvStreamSvc                     
               1          2014-01-06 15:49:28                                  ASP.NET 4.0.30319.0             1020:    IIS  ,      IIS   ,  .   ASP.NET    IIS,    IIS    ASP.NET  aspnet_regiis.exe /i.  
                         2014-01-06 15:52:58                                  NvStreamSvc                     
                         2014-01-06 15:52:58                                  NvStreamSvc                     
                         2014-01-06 15:57:02                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-06 15:57:02                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-06 15:57:02                           Microsoft-Windows-LoadPerf      3011:        WmiApRpl (WmiApRpl)  .    (DWORD)      .  
                         2014-01-06 16:31:28                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-06 16:31:28                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-06 16:31:28                           Microsoft-Windows-LoadPerf      3011:        WmiApRpl (WmiApRpl)  .    (DWORD)      .  
                       2014-01-06 16:32:05                           Microsoft-Windows-User Profiles Service  1530:  Windows ,        .    .   ,    ,    .        -    15 user registry handles leaked from \Registry\User\S-1-5-21-839303928-1106944401-891866635-500: Process 1664 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500 Process 1664 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500 Process 1664 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500 Process 1664 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500 Process 1664 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\SmartCardRoot Process 1664 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Policies\Microsoft\SystemCertificates Process 1664 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Policies\Microsoft\SystemCertificates Process 1664 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Policies\Microsoft\SystemCertificates Process 1664 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Policies\Microsoft\SystemCertificates Process 1664 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\My Process 1664 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\TrustedPeople Process 1664 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\CA Process 1664 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\Disallowed Process 1664 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\trust Process 1664 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\Root   
                       2014-01-06 16:36:41                                  Wlclntfy                        6000:     -    winlogon <GPClient>.  
                         2014-01-06 16:40:47                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-06 16:40:47                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-06 16:40:47                           Microsoft-Windows-LoadPerf      3011:        WmiApRpl (WmiApRpl)  .    (DWORD)      .  
                       2014-01-06 16:47:00                                  Wlclntfy                        6000:     -    winlogon <GPClient>.  
                       2014-01-06 16:47:00                                  Wlclntfy                        6000:     -    winlogon <GPClient>.  
                         2014-01-06 16:48:21                                  NvStreamSvc                     
                         2014-01-06 16:48:21                                  NvStreamSvc                     
                         2014-01-06 16:52:13                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-06 16:52:13                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-06 16:52:13                           Microsoft-Windows-LoadPerf      3011:        WmiApRpl (WmiApRpl)  .    (DWORD)      .  
                         2014-01-06 18:50:33                                  SideBySide                      33:       "C:\Program Files\Yandex\Elements\helper64.exe".      "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"".   sxstrace.exe   .  
                         2014-01-06 18:50:34                                  SideBySide                      33:       "C:\Program Files\Yandex\FastDial\helper64.exe".      "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"".   sxstrace.exe   .  
                         2014-01-06 21:49:20                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-06 21:49:20                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-06 21:49:20                           Microsoft-Windows-LoadPerf      3011:        WmiApRpl (WmiApRpl)  .    (DWORD)      .  
                         2014-01-07 00:34:33                                  NvStreamSvc                     
                         2014-01-07 00:34:33                                  NvStreamSvc                     
                         2014-01-07 00:35:05                                  VSS                             8194:    :      IVssWriterCallback.  hr = 0x80070005,   .  .     -        .    :         :       : {e8132975-6f93-4464-a53e-1050253ae220}      : System Writer       : {3add3244-90ee-4cfc-bd2d-939d65f2f2c9}  
                         2014-01-07 01:25:52                                  NvStreamSvc                     
                         2014-01-07 01:25:52                                  NvStreamSvc                     
                         2014-01-07 01:31:22                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 01:31:22                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 01:31:22                           Microsoft-Windows-LoadPerf      3011:        WmiApRpl (WmiApRpl)  .    (DWORD)      .  
                         2014-01-07 01:57:23                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 01:57:23                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 01:57:23                           Microsoft-Windows-LoadPerf      3011:        WmiApRpl (WmiApRpl)  .    (DWORD)      .  
                         2014-01-07 03:11:52                                  NvStreamSvc                     
                         2014-01-07 03:11:52                                  NvStreamSvc                     
                         2014-01-07 03:17:22                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 03:17:22                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 03:17:22                           Microsoft-Windows-LoadPerf      3011:        WmiApRpl (WmiApRpl)  .    (DWORD)      .  
                       2014-01-07 03:49:03                                  IIS Express                     2264:        C:\Windows\TEMP\iisexpress\IIS Temporary Compressed Files\Clr4IntegratedAppPool.    .  
                         2014-01-07 04:40:27                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 04:40:27                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 04:40:27                           Microsoft-Windows-LoadPerf      3011:        WmiApRpl (WmiApRpl)  .    (DWORD)      .  
                         2014-01-07 05:42:28                                  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe  
                       2014-01-07 05:42:28                           Microsoft-Windows-User Profiles Service  1530:  Windows ,        .    .   ,    ,    .        -    15 user registry handles leaked from \Registry\User\S-1-5-21-839303928-1106944401-891866635-500: Process 360 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500 Process 360 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500 Process 360 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500 Process 360 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500 Process 360 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\SmartCardRoot Process 360 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Policies\Microsoft\SystemCertificates Process 360 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Policies\Microsoft\SystemCertificates Process 360 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Policies\Microsoft\SystemCertificates Process 360 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Policies\Microsoft\SystemCertificates Process 360 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\My Process 360 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\TrustedPeople Process 360 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\CA Process 360 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\Disallowed Process 360 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\trust Process 360 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\Root   
                         2014-01-07 14:30:33                                  NvStreamSvc                     
                         2014-01-07 14:30:33                                  NvStreamSvc                     
                         2014-01-07 14:46:01                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 14:46:01                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 14:46:01                           Microsoft-Windows-LoadPerf      3011:        WmiApRpl (WmiApRpl)  .    (DWORD)      .  
                         2014-01-07 15:56:13                                  NvStreamSvc                     
                         2014-01-07 15:56:13                                  NvStreamSvc                     
                         2014-01-07 16:01:35                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 16:01:35                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 16:01:35                           Microsoft-Windows-LoadPerf      3011:        WmiApRpl (WmiApRpl)  .    (DWORD)      .  
                       2014-01-07 16:14:14                                  IIS Express                     2264:        C:\Windows\TEMP\iisexpress\IIS Temporary Compressed Files\Clr4IntegratedAppPool.    .  
                         2014-01-07 16:38:48                                  SideBySide                      33:       "C:\Program Files\Yandex\Elements\helper64.exe".      "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"".   sxstrace.exe   .  
                         2014-01-07 16:38:48                                  SideBySide                      33:       "C:\Program Files\Yandex\FastDial\helper64.exe".      "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"".   sxstrace.exe   .  
                       2014-01-07 16:50:26                     MsiInstaller                    1032:    ""      .  ,     ,               .  
                         2014-01-07 16:55:42                                  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe  
                       2014-01-07 16:55:42                           Microsoft-Windows-User Profiles Service  1530:  Windows ,        .    .   ,    ,    .        -    15 user registry handles leaked from \Registry\User\S-1-5-21-839303928-1106944401-891866635-500: Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500 Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500 Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500 Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500 Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\SmartCardRoot Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Policies\Microsoft\SystemCertificates Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Policies\Microsoft\SystemCertificates Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Policies\Microsoft\SystemCertificates Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Policies\Microsoft\SystemCertificates Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\My Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\TrustedPeople Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\CA Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\Disallowed Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\trust Process 1996 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\Root   
                         2014-01-07 16:57:18                                  NvStreamSvc                     
                         2014-01-07 16:57:18                                  NvStreamSvc                     
                         2014-01-07 17:13:07                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 17:13:07                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 17:13:07                           Microsoft-Windows-LoadPerf      3011:        WmiApRpl (WmiApRpl)  .    (DWORD)      .  
                         2014-01-07 17:20:19                                  NvStreamSvc                     
                         2014-01-07 17:20:19                                  NvStreamSvc                     
                         2014-01-07 17:44:31                                  NvStreamSvc                     
                         2014-01-07 17:44:31                                  NvStreamSvc                     
                         2014-01-07 17:51:27                                  VSS                             8194:    :      IVssWriterCallback.  hr = 0x80070005,   .  .     -        .    :         :       : {e8132975-6f93-4464-a53e-1050253ae220}      : System Writer       : {3f0f0058-ca16-4d9a-b78a-6be6511eb60c}  
                 100        2014-01-07 17:52:19                                  Application Error               1000:   : bioshock.exe, : 1.0.0.0,  : 0x474f5a3a    : OLEAUT32.dll, : 6.1.7600.16872,   0x4e5873c1   : 0xc0000005   : 0x00004971    : 0x178c     : 0x01cf0bafa9955dfb    : D:\Program Files\Steam\steamapps\common\Bioshock\Builds\Release\bioshock.exe    : C:\Windows\system32\OLEAUT32.dll   : ec7a13e4-77a2-11e3-af59-90e6bac09cc4
                 100        2014-01-07 17:52:30                                  Application Error               1000:   : bioshock.exe, : 1.0.0.0,  : 0x474f5a3a    : OLEAUT32.dll, : 6.1.7600.16872,   0x4e5873c1   : 0xc0000005   : 0x00004971    : 0x1528     : 0x01cf0bafb3007cf5    : D:\Program Files\Steam\steamapps\common\Bioshock\Builds\Release\bioshock.exe    : C:\Windows\system32\OLEAUT32.dll   : f3282f29-77a2-11e3-af59-90e6bac09cc4
                 100        2014-01-07 17:52:39                                  Application Error               1000:   : bioshock.exe, : 1.0.0.0,  : 0x474f5a3a    : OLEAUT32.dll, : 6.1.7600.16872,   0x4e5873c1   : 0xc0000005   : 0x00004971    : 0x13b8     : 0x01cf0bafb7ecbed1    : D:\Program Files\Steam\steamapps\common\Bioshock\Builds\Release\bioshock.exe    : C:\Windows\system32\OLEAUT32.dll   : f8102b17-77a2-11e3-af59-90e6bac09cc4
                 100        2014-01-07 18:15:18                                  Application Error               1000:   : bioshock.exe, : 1.0.0.0,  : 0x474f5a3a    : OLEAUT32.dll, : 6.1.7600.16872,   0x4e5873c1   : 0xc0000005   : 0x00004971    : 0xd70     : 0x01cf0bb2e161ffb0    : D:\Program Files\Steam\steamapps\common\Bioshock\Builds\Release\bioshock.exe    : C:\Windows\system32\OLEAUT32.dll   : 225a9b63-77a6-11e3-af59-90e6bac09cc4
                 100        2014-01-07 18:15:58                                  Application Error               1000:   : bioshock.exe, : 1.0.0.0,  : 0x474f5a3a    : OLEAUT32.dll, : 6.1.7600.16872,   0x4e5873c1   : 0xc0000005   : 0x00004971    : 0x1264     : 0x01cf0bb2f9f381bc    : D:\Program Files\Steam\steamapps\common\Bioshock\Builds\Release\bioshock.exe    : C:\Windows\system32\OLEAUT32.dll   : 3a1edd63-77a6-11e3-af59-90e6bac09cc4
                       2014-01-07 21:37:40                           Microsoft-Windows-User Profiles Service  1530:  Windows ,        .    .   ,    ,    .        -    15 user registry handles leaked from \Registry\User\S-1-5-21-839303928-1106944401-891866635-500: Process 1388 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500 Process 1388 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500 Process 1388 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500 Process 1388 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500 Process 1388 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\SmartCardRoot Process 1388 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Policies\Microsoft\SystemCertificates Process 1388 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Policies\Microsoft\SystemCertificates Process 1388 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Policies\Microsoft\SystemCertificates Process 1388 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Policies\Microsoft\SystemCertificates Process 1388 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\My Process 1388 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\TrustedPeople Process 1388 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\CA Process 1388 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\Disallowed Process 1388 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\trust Process 1388 (\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-839303928-1106944401-891866635-500\Software\Microsoft\SystemCertificates\Root   
                         2014-01-07 21:39:52                                  NvStreamSvc                     
                         2014-01-07 21:39:52                                  NvStreamSvc                     
                       2014-01-07 21:41:44                     Microsoft-Windows-RestartManager  10010:     "C:\Windows\System32\wbem\WmiPrvSE.exe" (  3120) - 1.  
                       2014-01-07 21:41:44                     Microsoft-Windows-RestartManager  10010:     "C:\Program Files\IIS Express\iisexpress.exe" (  2060) - 1.  
                       2014-01-07 21:46:23                     Microsoft-Windows-RestartManager  10010:     "C:\Program Files\Windows Sidebar\sidebar.exe" (  3384) - 1.  
                       2014-01-07 21:46:40                     Microsoft-Windows-RestartManager  10010:     "C:\Windows\System32\wbem\WmiPrvSE.exe" (  3120) - 1.  
                       2014-01-07 21:46:41                     Microsoft-Windows-RestartManager  10010:     "C:\Windows\System32\wbem\WmiPrvSE.exe" (  3120) - 1.  
                       2014-01-07 21:46:48                     Microsoft-Windows-RestartManager  10010:     "C:\Program Files\IIS Express\iisexpress.exe" (  2060) - 1.  
                       2014-01-07 21:46:50                     Microsoft-Windows-RestartManager  10010:     "C:\Windows\System32\wbem\WmiPrvSE.exe" (  3120) - 1.  
                       2014-01-07 21:46:53                     Microsoft-Windows-RestartManager  10010:     "C:\Program Files\IIS Express\iisexpress.exe" (  2060) - 1.  
                       2014-01-07 21:46:53                     Microsoft-Windows-RestartManager  10010:     "C:\Windows\System32\wbem\WmiPrvSE.exe" (  3120) - 1.  
                       2014-01-07 21:46:53                     Microsoft-Windows-RestartManager  10010:     "C:\Windows\System32\SearchFilterHost.exe" (  4992) - 1.  
                       2014-01-07 21:46:54                     Microsoft-Windows-RestartManager  10010:     "C:\Program Files\IIS Express\iisexpress.exe" (  2060) - 1.  
                       2014-01-07 21:46:54                     Microsoft-Windows-RestartManager  10010:     "C:\Windows\System32\wbem\WmiPrvSE.exe" (  3120) - 1.  
                       2014-01-07 21:46:58                     Microsoft-Windows-RestartManager  10010:     "C:\Program Files\IIS Express\iisexpress.exe" (  2060) - 1.  
                       2014-01-07 21:46:59                     Microsoft-Windows-RestartManager  10010:     "C:\Windows\System32\wbem\WmiPrvSE.exe" (  3120) - 1.  
                       2014-01-07 21:47:13                     Microsoft-Windows-RestartManager  10010:     "C:\Program Files\IIS Express\iisexpress.exe" (  2060) - 1.  
                         2014-01-07 21:47:31                     Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 21:47:31                     Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 21:47:31                     Microsoft-Windows-LoadPerf      3011:        ASP.NET_4.0.30319 (ASP.NET_4.0.30319)  .    (DWORD)      .  
                         2014-01-07 21:47:35                     Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 21:47:35                     Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 21:47:35                     Microsoft-Windows-LoadPerf      3011:        aspnet_state (ASP.NET State Service)  .    (DWORD)      .  
                         2014-01-07 21:47:36                     Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 21:47:36                     Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 21:47:36                     Microsoft-Windows-LoadPerf      3011:        ASP.NET (ASP.NET)  .    (DWORD)      .  
               1          2014-01-07 21:47:36                                  ASP.NET 4.0.30319.0             1020:    IIS  ,      IIS   ,  .   ASP.NET    IIS,    IIS    ASP.NET  aspnet_regiis.exe /i.  
                         2014-01-07 21:47:48                     Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 21:47:48                     Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 21:47:48                     Microsoft-Windows-LoadPerf      3011:        SMSvcHost 4.0.0.0 (SMSvcHost 4.0.0.0)  .    (DWORD)      .  
                         2014-01-07 21:47:48                     Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 21:47:48                     Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 21:47:48                     Microsoft-Windows-LoadPerf      3011:        MSDTC Bridge 4.0.0.0 (MSDTC Bridge 4.0.0.0)  .    (DWORD)      .  
                         2014-01-07 21:48:01                     Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 21:48:01                     Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 21:48:01                     Microsoft-Windows-LoadPerf      3011:        Windows Workflow Foundation 4.0.0.0 (Windows Workflow Foundation 4.0.0.0)  .    (DWORD)      .  
                         2014-01-07 21:48:23                                  .NET Runtime Optimization Service  1101: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - 1>Failed to compile: mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 . Error code = 0x80070003    
                         2014-01-07 21:50:49                     Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 21:50:49                     Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 21:50:49                     Microsoft-Windows-LoadPerf      3011:        ASP.NET_4.0.30319 (ASP.NET_4.0.30319)  .    (DWORD)      .  
                         2014-01-07 21:50:51                     Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 21:50:51                     Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 21:50:51                     Microsoft-Windows-LoadPerf      3011:        aspnet_state (  ASP.NET)  .    (DWORD)      .  
                         2014-01-07 21:50:53                     Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 21:50:53                     Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 21:50:53                     Microsoft-Windows-LoadPerf      3011:        ASP.NET (ASP.NET)  .    (DWORD)      .  
               1          2014-01-07 21:50:53                                  ASP.NET 4.0.30319.0             1020:    IIS  ,      IIS   ,  .   ASP.NET    IIS,    IIS    ASP.NET  aspnet_regiis.exe /i.  
                         2014-01-07 21:58:20                                  NvStreamSvc                     
                         2014-01-07 21:58:20                                  NvStreamSvc                     
                         2014-01-07 22:22:24                                  NvStreamSvc                     
                         2014-01-07 22:22:24                                  NvStreamSvc                     
                         2014-01-07 22:22:56                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 22:22:56                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 22:22:56                           Microsoft-Windows-LoadPerf      3011:        WmiApRpl (WmiApRpl)  .    (DWORD)      .  
                         2014-01-07 22:22:59                                  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe  
                         2014-01-07 22:28:04                                  NvStreamSvc                     
                         2014-01-07 22:28:04                                  NvStreamSvc                     
                 100        2014-01-07 23:11:16                                  Application Error               1000:   : csgo.exe, : 0.0.0.0,  : 0x521bba5d    : tier0.dll, : 0.0.0.0,   0x52b81fc9   : 0x40000015   : 0x0001f776    : 0x1628     : 0x01cf0bd67565f5c0    : D:\Program Files\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe    : D:\Program Files\Steam\steamapps\common\Counter-Strike Global Offensive\bin\tier0.dll   : 7ac7218c-77cf-11e3-838d-90e6bac09cc4
                         2014-01-07 23:14:34                                  VSS                             8194:    :      IVssWriterCallback.  hr = 0x80070005,   .  .     -        .    :         :       : {e8132975-6f93-4464-a53e-1050253ae220}      : System Writer       : {6e75ebb8-188e-4d00-a521-dc23b1116bb1}  
                         2014-01-07 23:28:55                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 23:28:55                           Microsoft-Windows-LoadPerf      3012:        ,        Performance.   BaseIndex         (DWORD)  ,  LastCounter -     (DWORD)  ,   LastHelp -     (DWORD)  .  
                         2014-01-07 23:28:55                           Microsoft-Windows-LoadPerf      3011:        WmiApRpl (WmiApRpl)  .    (DWORD)      .  
                         2014-01-08 00:01:33                                  NvStreamSvc                     
                         2014-01-08 00:01:33                                  NvStreamSvc                     
      Audit Success   12288      2014-01-05 16:05:30                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x45c   :  C:\Windows\System32\svchost.exe     :  2014-01-05T15:05:30.849041300Z   :  2014-01-05T12:05:30.236411600Z          .    Windows,    ,    .           .  
      Audit Success   12288      2014-01-05 16:05:30                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x45c   :  C:\Windows\System32\svchost.exe     :  2014-01-05T12:05:30.252011600Z   :  2014-01-05T12:05:30.252000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2014-01-05 16:05:30                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x45c   :  C:\Windows\System32\svchost.exe     :  2014-01-05T12:05:30.252000000Z   :  2014-01-05T12:05:30.252000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2014-01-05 16:05:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:05:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-05 16:05:40                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\cabview.dll    : 0x41c      :    : 0x524    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 16:05:42                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP      :  0x3e7    :    : 0xe3c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x18f49e  
      Audit Success   13568      2014-01-05 16:05:42                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP      :  0x3e7    :    : 0xe3c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x18f49e  
      Audit Success   12545      2014-01-05 16:06:14                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x3bbf5      ,   .  ,  ,  .        .  
      Audit Success   13568      2014-01-05 16:06:17                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\drivers\rdpwd.sys    : 0x18      :    : 0x1e4    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 16:06:17                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\rdpcore.dll    : 0x18      :    : 0x1e4    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 16:06:17                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\drivers\tdtcp.sys    : 0x18      :    : 0x1e4    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   103        2014-01-05 16:06:20                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-05 16:06:59                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-05 16:06:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-05 16:06:59                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x964b  
      Audit Success   12544      2014-01-05 16:07:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 16:07:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 16:07:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:07:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 16:07:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 16:07:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 16:07:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 16:07:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:07:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 16:07:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 16:07:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:07:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-05 16:07:03                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-05 16:07:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:07:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-05 16:07:04                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-05 16:07:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x19407   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 16:07:08                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x218    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-05 16:07:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1db94   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x218    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 16:07:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1dbbc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x218    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:07:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1db94    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 16:07:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:07:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 16:09:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:09:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2014-01-05 16:10:20                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x40c   :  C:\Windows\System32\svchost.exe     :  2014-01-05T12:10:20.011509500Z   :  2014-01-05T12:10:20.011000000Z          .    Windows,    ,    .           .  
      Audit Success   12545      2014-01-05 16:13:13                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1dbbc      ,   .  ,  ,  .        .  
      Audit Success   103        2014-01-05 16:13:14                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-05 16:13:57                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-05 16:13:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-05 16:13:57                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x8a91  
      Audit Success   12544      2014-01-05 16:14:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 16:14:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 16:14:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 16:14:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 16:14:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:14:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 16:14:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 16:14:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 16:14:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 16:14:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-05 16:14:08                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-05 16:14:08                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x204    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-05 16:14:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x15ef1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 16:14:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x15f19   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x204    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 16:14:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:14:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x15ef1    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 16:14:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-05 16:14:09                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-05 16:14:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1c0a2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 16:14:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:14:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 16:16:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:16:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 16:17:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:17:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2014-01-05 16:18:26                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x3f8   :  C:\Windows\System32\svchost.exe     :  2014-01-05T12:18:26.062741100Z   :  2014-01-05T12:18:26.062000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2014-01-05 16:19:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:19:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 16:19:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:19:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-05 16:19:39                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\netfxperf.dll    : 0x40c      :    : 0xf10    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 16:19:41                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x394    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0xa895a  
      Audit Success   13568      2014-01-05 16:19:41                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x394    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0xa895a  
      Audit Success   12544      2014-01-05 16:25:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:25:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 16:40:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:40:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 16:42:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:42:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 16:43:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1bc    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:43:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-01-05 16:44:05                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x15f19      ,   .  ,  ,  .        .  
      Audit Success   13568      2014-01-05 16:44:07                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\netfxperf.dll    : 0x18      :    : 0xd20    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 16:44:07                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\mscoree.dll    : 0x18      :    : 0xd20    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 16:44:07                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\dfshim.dll    : 0x18      :    : 0xd20    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 16:44:07                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\PresentationHost.exe    : 0x18      :    : 0xd20    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 16:44:07                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\PresentationHostProxy.dll    : 0x18      :    : 0xd20    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 16:44:07                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\MUI\0409\mscorees.dll    : 0x18      :    : 0xd20    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   103        2014-01-05 16:44:12                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-05 16:44:55                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-05 16:44:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-05 16:44:55                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x8f5d  
      Audit Success   12544      2014-01-05 16:45:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 16:45:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 16:45:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 16:45:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 16:45:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:45:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 16:45:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 16:45:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 16:45:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 16:45:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 16:45:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:45:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-05 16:45:05                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-01-05 16:45:05                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-05 16:45:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:45:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 16:45:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1d72e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 16:45:10                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x260    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-05 16:45:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x25cc8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 16:45:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x25cf2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:45:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x25cc8    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 16:45:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:45:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 16:47:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 16:47:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2014-01-05 16:49:21                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x47c   :  C:\Windows\System32\svchost.exe     :  2014-01-05T12:49:21.835172700Z   :  2014-01-05T12:49:21.835000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2014-01-05 17:01:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:01:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 17:01:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:01:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 17:06:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 17:06:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:06:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 17:06:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-05 17:07:03                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x1700    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x34bfbe  
      Audit Success   13568      2014-01-05 17:07:03                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x1700    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x34bfbe  
      Audit Success   12544      2014-01-05 17:07:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:07:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 17:12:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:12:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 17:12:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:12:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 17:12:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:12:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 17:13:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x220    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:13:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-05 17:14:34                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0xe70    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x41da4c  
      Audit Success   13568      2014-01-05 17:14:34                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0xe70    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x41da4c  
      Audit Success   12545      2014-01-05 17:14:42                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x25cf2      ,   .  ,  ,  .        .  
      Audit Success   103        2014-01-05 17:14:45                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-05 17:18:26                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-05 17:18:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 17:18:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:18:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-05 17:18:26                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x9d13  
      Audit Success   12544      2014-01-05 17:18:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:18:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 17:18:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 17:18:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 17:18:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:18:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 17:18:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 17:18:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-05 17:18:29                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-05 17:18:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:18:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-05 17:18:30                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-05 17:18:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x195d0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 17:18:36                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1f4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-05 17:18:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1f2c2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1f4    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 17:18:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1f2e8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1f4    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:18:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1f2c2    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 17:18:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:18:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 17:18:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 17:18:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:18:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 17:18:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 17:18:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:18:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 17:20:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:20:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 17:21:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:21:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2014-01-05 17:21:46                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x3f4   :  C:\Windows\System32\svchost.exe     :  2014-01-05T13:21:46.728068100Z   :  2014-01-05T13:21:46.728000000Z          .    Windows,    ,    .           .  
      Audit Success   13568      2014-01-05 17:22:08                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x9ec    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x102865  
      Audit Success   13568      2014-01-05 17:22:08                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x9ec    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x102865  
      Audit Success   13568      2014-01-05 17:22:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wuaueng.dll    : 0x548      :    : 0xa88    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 17:22:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wups2.dll    : 0x4e0      :    : 0xa88    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 17:22:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wuauclt.exe    : 0x484      :    : 0xa88    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 17:22:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wucltux.dll    : 0x538      :    : 0xa88    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 17:22:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ru-RU\wuaueng.dll.mui    : 0x548      :    : 0xa88    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 17:22:23                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ru-RU\wucltux.dll.mui    : 0x4e0      :    : 0xa88    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 17:22:26                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wuapp.exe    : 0x448      :    : 0xa88    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 17:22:26                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wuwebv.dll    : 0x504      :    : 0xa88    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 17:22:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wups.dll    : 0x66c      :    : 0xa88    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 17:22:28                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wudriver.dll    : 0x52c      :    : 0xa88    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   12544      2014-01-05 17:35:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 17:35:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:35:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 17:35:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 17:36:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:36:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-05 17:36:44                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0xd60    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x1ca282  
      Audit Success   13568      2014-01-05 17:36:44                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0xd60    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x1ca282  
      Audit Success   12544      2014-01-05 17:53:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:53:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 17:54:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:54:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 17:54:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 17:54:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:54:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 17:54:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-05 17:54:19                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\netfxperf.dll    : 0x4e0      :    : 0x4b4    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 17:54:35                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0xf14    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x239e5b  
      Audit Success   13568      2014-01-05 17:54:35                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0xf14    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x239e5b  
      Audit Success   12544      2014-01-05 17:55:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:55:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Failure   12290      2014-01-05 17:58:01                                  Microsoft-Windows-Security-Auditing  5038:     ,     .         ,          .     : \Device\CdRom0\CDRIVER.SYS   
      Audit Success   12544      2014-01-05 17:58:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 17:58:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13569      2014-01-05 18:00:22                                  Microsoft-Windows-Security-Auditing  4717:       .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1f2c2      :     :  S-1-5-21-839303928-1106944401-891866635-1001     :     :  SeServiceLogonRight  
      Audit Success   13824      2014-01-05 18:00:22                                  Microsoft-Windows-Security-Auditing  4720:    .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1f2c2      :    :  S-1-5-21-839303928-1106944401-891866635-1001     :  UpdatusUser     :  -    :      SAM: UpdatusUser    :  %%1793     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : %%1794       :  %%1794     : 513    : -     UAC:  0x0     UAC:  0x15      :     %%2080    %%2082    %%2084    : %%1793    SID:  -    :  %%1797     :   Privileges  -  
      Audit Success   13824      2014-01-05 18:00:22                                  Microsoft-Windows-Security-Auditing  4722:    .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1f2c2      :    :  S-1-5-21-839303928-1106944401-891866635-1001     :  UpdatusUser     :  -  
      Audit Success   13824      2014-01-05 18:00:22                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1f2c2      :    :  S-1-5-21-839303928-1106944401-891866635-1001     :  UpdatusUser     :  -     :      SAM: UpdatusUser    :  UpdatusUser     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : 05.01.2014 17:00:22       :  %%1794     : 513    : -     UAC:  0x15     UAC:  0x210      :     %%2048    %%2050    %%2089    : -    SID:  -    :  %%1797     :   :  -  
      Audit Success   13824      2014-01-05 18:00:22                                  Microsoft-Windows-Security-Auditing  4724:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1f2c2      :    :  S-1-5-21-839303928-1106944401-891866635-1001     :  UpdatusUser     :  -  
      Audit Success   13826      2014-01-05 18:00:22                                  Microsoft-Windows-Security-Auditing  4728:       .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1f2c2    :    :  S-1-5-21-839303928-1106944401-891866635-1001     :  -    :    :  S-1-5-21-839303928-1106944401-891866635-513    :  None    :  -     :   :  -  
      Audit Success   13569      2014-01-05 18:00:23                                  Microsoft-Windows-Security-Auditing  4717:       .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1f2c2      :     :  S-1-5-21-839303928-1106944401-891866635-1001     :     :  SeDenyInteractiveLogonRight  
      Audit Success   12544      2014-01-05 18:00:24                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1f2c2   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x818    :  E:\Driver\296.39\Win7_Vista32\setup.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-05 18:00:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1f2c2     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1001     :  UpdatusUser     :  -    :  0x2dc959   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x818    :  E:\Driver\296.39\Win7_Vista32\setup.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:00:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1001     :  UpdatusUser     :  -    :  0x2dc959    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-01-05 18:00:27                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1001     :  UpdatusUser     :  -    :  0x2dc959     :   5          .           " ".      ,       .  
      Audit Success   12544      2014-01-05 18:00:29                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1d4    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-05 18:00:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1001     :  UpdatusUser     :  -    :  0x2e364a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:00:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1001     :  UpdatusUser     :  -    :  0x2e364a    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 18:00:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1d4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:00:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-05 18:01:16                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x9e8    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x312175  
      Audit Success   13568      2014-01-05 18:01:16                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x9e8    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x312175  
      Audit Success   12545      2014-01-05 18:01:38                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1f2e8      ,   .  ,  ,  .        .  
      Audit Success   13568      2014-01-05 18:01:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\netfxperf.dll    : 0x18      :    : 0x9bc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 18:01:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\mscoree.dll    : 0x18      :    : 0x9bc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 18:01:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\dfshim.dll    : 0x18      :    : 0x9bc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 18:01:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\PresentationHost.exe    : 0x18      :    : 0x9bc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 18:01:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\PresentationHostProxy.dll    : 0x18      :    : 0x9bc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 18:01:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\MUI\0409\mscorees.dll    : 0x18      :    : 0x9bc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 18:01:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wups.dll    : 0x18      :    : 0x9bc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 18:01:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wudriver.dll    : 0x18      :    : 0x9bc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 18:01:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wuapi.dll    : 0x18      :    : 0x9bc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 18:01:41                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ru-RU\wuapi.dll.mui    : 0x18      :    : 0x9bc    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   103        2014-01-05 18:01:45                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-05 18:02:31                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-05 18:02:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-05 18:02:31                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa69f  
      Audit Success   12544      2014-01-05 18:02:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:02:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 18:02:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 18:02:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:02:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 18:02:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 18:02:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 18:02:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 18:02:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:02:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 18:02:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 18:02:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-05 18:02:42                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-01-05 18:02:42                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-05 18:02:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:02:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 18:02:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x1d257   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 18:02:49                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x288    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-05 18:02:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24cea   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 18:02:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24d14   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:02:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24cea    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 18:03:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:03:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 18:04:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:04:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 18:04:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 18:04:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:04:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 18:04:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 18:04:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:04:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 18:04:45                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x24c    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-05 18:04:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1001     :  UpdatusUser     :  -    :  0xb1756   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:04:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1001     :  UpdatusUser     :  -    :  0xb1756    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 18:04:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:04:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-05 18:05:11                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\cabview.dll    : 0x458      :    : 0x4c0    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 18:05:25                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x708    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0xeb4eb  
      Audit Success   13568      2014-01-05 18:05:25                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x708    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0xeb4eb  
      Audit Success   12288      2014-01-05 18:05:59                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x4e8   :  C:\Windows\System32\svchost.exe     :  2014-01-05T14:05:59.261128700Z   :  2014-01-05T14:05:59.261000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2014-01-05 18:14:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 18:14:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:14:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 18:14:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-05 18:16:11                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x12a8    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x30f30c  
      Audit Success   13568      2014-01-05 18:16:11                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x12a8    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x30f30c  
      Audit Success   12544      2014-01-05 18:17:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:17:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 18:21:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:21:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-05 18:22:52                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x141c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x4b762c  
      Audit Success   13568      2014-01-05 18:22:52                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x141c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x4b762c  
      Audit Success   13568      2014-01-05 18:26:17                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Config.Msi\2192c.rbf    : 0x5f4      :    : 0xc60    : C:\Windows\System32\msiexec.exe     :     :      :  S:AI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   12544      2014-01-05 18:29:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:29:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2014-01-05 18:55:53                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-05 18:55:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-05 18:55:54                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x24d69  
      Audit Success   13826      2014-01-05 18:55:55                                  Microsoft-Windows-Security-Auditing  4731:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7     :    :  S-1-5-32-556    :        :  Builtin    :      SAM:       SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 18:55:55                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-556    :        :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 18:55:55                                  Microsoft-Windows-Security-Auditing  4731:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7     :    :  S-1-5-32-547    :       :  Builtin    :      SAM:      SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 18:55:55                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-547    :       :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 18:55:55                                  Microsoft-Windows-Security-Auditing  4731:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7     :    :  S-1-5-32-569    :       :  Builtin    :      SAM:      SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 18:55:55                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-569    :       :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 18:55:55                                  Microsoft-Windows-Security-Auditing  4731:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7     :    :  S-1-5-32-551    :       :  Builtin    :      SAM:      SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 18:55:55                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 18:55:55                                  Microsoft-Windows-Security-Auditing  4731:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7     :    :  S-1-5-32-552    :      :  Builtin    :      SAM:     SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 18:55:55                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-552    :      :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 18:55:55                                  Microsoft-Windows-Security-Auditing  4731:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7     :    :  S-1-5-32-555    :         :  Builtin    :      SAM:        SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 18:55:55                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-555    :         :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   12544      2014-01-05 18:55:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:55:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 18:55:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:55:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 18:56:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 18:56:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 18:56:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 18:56:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:56:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 18:56:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 18:56:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 18:56:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-05 18:56:14                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-01-05 18:56:14                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-05 18:56:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:56:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 18:56:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x32f62   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 18:58:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:58:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 18:58:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:58:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-01-05 18:58:31                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-839303928-1106944401-891866635-500     :  Administrator     :  37L4247D28-05     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  0x211     UAC:  0x211      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   12544      2014-01-05 18:59:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 18:59:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  37L4247D28-05$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:59:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 18:59:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2014-01-05 18:59:03                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-05 18:59:49                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-05 18:59:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-05 18:59:49                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa490  
      Audit Success   12544      2014-01-05 18:59:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 18:59:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:59:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 18:59:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 18:59:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:59:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 18:59:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 18:59:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 18:59:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 18:59:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 18:59:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 18:59:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 19:00:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 19:00:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-05 19:00:17                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-05 19:00:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 19:00:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-05 19:00:18                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-05 19:00:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x24a3e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13824      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-569     :  Builtin      :        :       :   :  -  
      Audit Success   13824      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-573     :  Builtin      : Event Log Readers      :        :   :  -  
      Audit Success   13824      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-839303928-1106944401-891866635-500     :  Administrator     :  -     :      SAM: Administrator    :  %%1793     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : 14.07.2009 7:55:45       :  %%1794     : 513    : -     UAC:  0x211     UAC:  0x211      : -    : %%1793    SID:  -    :  %%1797     :   :  -  
      Audit Success   13824      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-839303928-1106944401-891866635-500     :  -      : Administrator      :      :   :  -  
      Audit Success   13824      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -     :      SAM:     :  %%1793     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : 14.07.2009 7:55:45       :  %%1794     : 513    : -     UAC:  0x211     UAC:  0x211      : -    : %%1793    SID:  -    :  %%1797     :   :  -  
      Audit Success   13824      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-839303928-1106944401-891866635-501     :  Guest     :  -     :      SAM: Guest    :  %%1793     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : %%1794       :  %%1794     : 513    : -     UAC:  0x215     UAC:  0x215      : -    : %%1793    SID:  -    :  %%1797     :   :  -  
      Audit Success   13824      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-839303928-1106944401-891866635-501     :  -      : Guest      :      :   :  -  
      Audit Success   13824      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-839303928-1106944401-891866635-501     :       :  -     :      SAM:     :  %%1793     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : %%1794       :  %%1794     : 513    : -     UAC:  0x215     UAC:  0x215      : -    : %%1793    SID:  -    :  %%1797     :   :  -  
      Audit Success   13824      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-544     :  Builtin      : Administrators      :      :   :  -  
      Audit Success   13824      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-545     :  Builtin      : Users      :      :   :  -  
      Audit Success   13824      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-546     :  Builtin      : Guests      :      :   :  -  
      Audit Success   13824      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-551     :  Builtin      :        :       :   :  -  
      Audit Success   13824      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-552     :  Builtin      :       :      :   :  -  
      Audit Success   13824      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-555     :  Builtin      :          :         :   :  -  
      Audit Success   13824      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-556     :  Builtin      :         :        :   :  -  
      Audit Success   13824      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-547     :  Builtin      :        :       :   :  -  
      Audit Success   13824      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-558     :  Builtin      : Performance Monitor Users      :        :   :  -  
      Audit Success   13824      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-559     :  Builtin      : Performance Log Users      :        :   :  -  
      Audit Success   13824      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-562     :  Builtin      : Distributed COM Users      :  DCOM     :   :  -  
      Audit Success   13824      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4781:    :    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-32-568     :  Builtin      : IIS_IUSRS      : IIS_IUSRS     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-569    :       :  Builtin     :      SAM:      SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-573    :  Event Log Readers    :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-573    :        :  Builtin     :      SAM:       SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :  Administrators    :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-544    :      :  Builtin     :      SAM:     SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-545    :  Users    :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-545    :      :  Builtin     :      SAM:     SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-546    :  Guests    :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-546    :      :  Builtin     :      SAM:     SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-551    :       :  Builtin     :      SAM:      SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-552    :      :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-552    :      :  Builtin     :      SAM:     SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-555    :         :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-555    :         :  Builtin     :      SAM:        SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-556    :        :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-556    :        :  Builtin     :      SAM:       SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-547    :       :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-547    :       :  Builtin     :      SAM:      SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-558    :  Performance Monitor Users    :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-558    :        :  Builtin     :      SAM:       SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-559    :  Performance Log Users    :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-559    :        :  Builtin     :      SAM:       SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-562    :  Distributed COM Users    :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-562    :   DCOM    :  Builtin     :      SAM:  DCOM    SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-568    :  IIS_IUSRS    :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-568    :  IIS_IUSRS    :  Builtin     :      SAM: IIS_IUSRS    SID:  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:21                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-32-569    :       :  Builtin     :      SAM: -    SID:  -     :   :  -  
      Audit Success   12288      2014-01-05 19:00:29                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    : 0x348   :  C:\Windows\System32\oobe\msoobe.exe     :  2014-01-05T15:00:30.036112900Z   :  2014-01-05T15:00:29.833000000Z          .    Windows,    ,    .           .  
      Audit Success   13824      2014-01-05 19:00:52                                  Microsoft-Windows-Security-Auditing  4720:    .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :      SAM:     :  %%1793     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : %%1794       :  %%1794     : 513    : -     UAC:  0x0     UAC:  0x15      :     %%2080    %%2082    %%2084    : %%1793    SID:  -    :  %%1797     :   Privileges  -  
      Audit Success   13826      2014-01-05 19:00:52                                  Microsoft-Windows-Security-Auditing  4728:       .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :  -    :    :  S-1-5-21-839303928-1106944401-891866635-513    :  None    :  -     :   :  -  
      Audit Success   13826      2014-01-05 19:00:52                                  Microsoft-Windows-Security-Auditing  4732:       .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :  -    :    :  S-1-5-32-545    :      :  Builtin     :   :  -  
      Audit Success   13824      2014-01-05 19:00:53                                  Microsoft-Windows-Security-Auditing  4722:    .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -  
      Audit Success   13824      2014-01-05 19:00:53                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -     :      SAM:     :  %%1793     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : %%1794       :  %%1794     : 513    : -     UAC:  0x15     UAC:  0x14      :     %%2048    : %%1793    SID:  -    :  %%1797     :   :  -  
      Audit Success   13824      2014-01-05 19:00:53                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -     :      SAM:     :  %%1793     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : %%1794       :  %%1794     : 513    : -     UAC:  0x14     UAC:  0x214      :     %%2089    : %%1793    SID:  -    :  %%1797     :   :  -  
      Audit Success   13824      2014-01-05 19:00:53                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -     :      SAM:     :  %%1793     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : 05.01.2014 18:00:53       :  %%1794     : 513    : -     UAC:  0x214     UAC:  0x214      : -    : -    SID:  -    :  %%1797     :   :  -  
      Audit Success   13824      2014-01-05 19:00:53                                  Microsoft-Windows-Security-Auditing  4724:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7      :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -  
      Audit Success   13826      2014-01-05 19:00:53                                  Microsoft-Windows-Security-Auditing  4732:       .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :  -    :    :  S-1-5-32-544    :      :  Builtin     :   :  -  
      Audit Success   13826      2014-01-05 19:00:53                                  Microsoft-Windows-Security-Auditing  4733:       .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :  -    :    :  S-1-5-32-545    :      :  Builtin     :   :  -  
      Audit Success   12544      2014-01-05 19:00:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 19:00:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 19:01:01                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x198    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-05 19:01:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x3a6e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x198    :  C:\Windows\System32\winlogon.exe      :     : WIN-3790CB6TIKQ     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 19:01:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x3bbf5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x198    :  C:\Windows\System32\winlogon.exe      :     : WIN-3790CB6TIKQ     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 19:01:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x3a6e7    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 19:01:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 19:01:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 19:01:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 19:01:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-05 19:01:28                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP      :  0x3e7    :    : 0xac8    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x639a5  
      Audit Success   13568      2014-01-05 19:01:28                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP      :  0x3e7    :    : 0xac8    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x639a5  
      Audit Success   12544      2014-01-05 19:01:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 19:01:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-05 19:01:55                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wuaueng.dll    : 0x538      :    : 0x524    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 19:01:55                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wups2.dll    : 0x4cc      :    : 0x524    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 19:01:55                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wuauclt.exe    : 0x4f8      :    : 0x524    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 19:01:55                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wucltux.dll    : 0x4e0      :    : 0x524    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 19:01:55                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ru-RU\wuaueng.dll.mui    : 0x538      :    : 0x524    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 19:01:56                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ru-RU\wucltux.dll.mui    : 0x4cc      :    : 0x524    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 19:01:58                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wuapp.exe    : 0x3b4      :    : 0x524    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 19:01:58                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wuwebv.dll    : 0x554      :    : 0x524    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 19:02:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wups.dll    : 0x680      :    : 0x524    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 19:02:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wudriver.dll    : 0x480      :    : 0x524    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 19:02:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\wuapi.dll    : 0x4f8      :    : 0x524    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 19:02:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ru-RU\wuapi.dll.mui    : 0x4b4      :    : 0x524    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   12544      2014-01-05 19:02:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  WIN-3790CB6TIKQ$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 19:02:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 19:03:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 19:03:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 19:07:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 19:07:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 19:14:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 19:14:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 19:14:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 19:14:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-05 19:16:29                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x117c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x19b1b69  
      Audit Success   13568      2014-01-05 19:16:29                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x117c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x19b1b69  
      Audit Success   12544      2014-01-05 19:16:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 19:16:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-05 19:17:31                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x117c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x1a3a999  
      Audit Success   13568      2014-01-05 19:17:31                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x117c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x1a3a999  
      Audit Success   12288      2014-01-05 21:16:32                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x4b4   :  C:\Windows\System32\svchost.exe     :  2014-01-05T20:15:24.220553600Z   :  2014-01-05T17:16:32.703540800Z          .    Windows,    ,    .           .  
      Audit Success   12288      2014-01-05 21:16:32                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x4b4   :  C:\Windows\System32\svchost.exe     :  2014-01-05T17:16:32.726540800Z   :  2014-01-05T17:16:32.726000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2014-01-05 21:16:32                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x4b4   :  C:\Windows\System32\svchost.exe     :  2014-01-05T17:16:32.728000100Z   :  2014-01-05T17:16:32.728000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2014-01-05 21:21:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 21:21:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 21:21:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 21:21:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2014-01-05 22:20:48                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24cea      :    : 0xbd0   :  C:\Windows\System32\dllhost.exe     :  2014-01-05T15:21:57.662814700Z   :  2014-01-05T18:20:48.000000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2014-01-05 22:20:48                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24cea      :    : 0xbd0   :  C:\Windows\System32\dllhost.exe     :  2014-01-05T18:20:48.000000000Z   :  2014-01-05T18:20:48.000000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2014-01-05 22:21:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 22:21:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-01-05 22:24:55                                  Microsoft-Windows-Security-Auditing  5056:   .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :  ncrypt.dll     : 0x0  
      Audit Failure   12290      2014-01-05 22:31:33                                  Microsoft-Windows-Security-Auditing  5038:     ,     .         ,          .     : \Device\HarddiskVolume3\\MSI Afterburner\RTCore32.sys   
      Audit Success   12544      2014-01-05 22:31:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 22:31:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 22:36:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 22:36:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 22:40:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 22:40:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 22:45:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 22:45:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 22:47:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 22:47:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 23:05:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 23:05:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 23:05:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-05 23:05:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 23:05:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-05 23:05:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-05 23:06:26                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x107c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x1f5ec05  
      Audit Success   13568      2014-01-05 23:06:26                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x107c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x1f5ec05  
      Audit Success   12544      2014-01-05 23:07:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 23:07:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-05 23:08:56                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\winsxs\Temp\PendingRenames\f309bb94490acf0102030000fc08ac10.WatAdminSvc.exe    : 0xdb0      :    : 0x8fc    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 23:08:56                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\winsxs\Temp\PendingRenames\56f4bb94490acf0103030000fc08ac10.npWatWeb.dll    : 0xd38      :    : 0x8fc    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 23:08:56                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\winsxs\Temp\PendingRenames\7742bc94490acf0104030000fc08ac10.WatWeb.dll    : 0xdac      :    : 0x8fc    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 23:08:56                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\winsxs\Temp\PendingRenames\9890bc94490acf0105030000fc08ac10.WatUX.exe    : 0xd98      :    : 0x8fc    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-05 23:13:52                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\winsxs\Temp\PendingRenames\c3417e454a0acf014a0b0000fc08ac10.inetcorp.iem    : 0x182c      :    : 0x8fc    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI  
      Audit Success   13568      2014-01-05 23:13:52                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\winsxs\Temp\PendingRenames\36537f454a0acf014b0b0000fc08ac10.inetset.iem    : 0x1830      :    : 0x8fc    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI  
      Audit Success   13568      2014-01-05 23:13:52                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\winsxs\Temp\PendingRenames\3d7f86454a0acf014c0b0000fc08ac10.install.ins    : 0x18dc      :    : 0x8fc    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI  
      Audit Success   13568      2014-01-05 23:14:15                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\winsxs\Temp\PendingRenames\ff3f5a534a0acf01b80c0000fc08ac10.inetcorp.iem    : 0x2650      :    : 0x8fc    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI  
      Audit Success   13568      2014-01-05 23:14:15                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\winsxs\Temp\PendingRenames\208e5a534a0acf01b90c0000fc08ac10.inetset.iem    : 0x2654      :    : 0x8fc    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI  
      Audit Success   12544      2014-01-05 23:17:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 23:17:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 23:19:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 23:19:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2014-01-05 23:22:13                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x3afd3      :    : 0x1020   :  C:\Windows\System32\dllhost.exe     :  2014-01-05T17:22:14.988000600Z   :  2014-01-05T19:22:13.000000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2014-01-05 23:22:13                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x3afd3      :    : 0x1020   :  C:\Windows\System32\dllhost.exe     :  2014-01-05T19:22:13.015600000Z   :  2014-01-05T19:22:13.000000000Z          .    Windows,    ,    .           .  
      Audit Success   13568      2014-01-05 23:22:44                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x1698    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x29c794  
      Audit Success   13568      2014-01-05 23:22:44                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x1698    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x29c794  
      Audit Success   12544      2014-01-05 23:25:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 23:25:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-01-05 23:47:30                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24cea      :    :  S-1-5-21-839303928-1106944401-891866635-1001     :  UpdatusUser     :  -     :      SAM: UpdatusUser    :  UpdatusUser     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : 05.01.2014 22:47:30       :  %%1794     : 513    : -     UAC:  0x210     UAC:  0x210      : -    : -    SID:  -    :  %%1797     :   :  -  
      Audit Success   13824      2014-01-05 23:47:30                                  Microsoft-Windows-Security-Auditing  4724:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24cea      :    :  S-1-5-21-839303928-1106944401-891866635-1001     :  UpdatusUser     :  -  
      Audit Success   12544      2014-01-05 23:47:31                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24cea   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1ddc    :  C:\NVIDIA\DisplayDriver\331.82\Win8_WinVista_Win7\International\setup.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-05 23:47:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24cea     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1001     :  UpdatusUser     :  -    :  0x2c949b5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ddc    :  C:\NVIDIA\DisplayDriver\331.82\Win8_WinVista_Win7\International\setup.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-01-05 23:47:31                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1001     :  UpdatusUser     :  -    :  0x2c949b5     :   5          .           " ".      ,       .  
      Audit Success   12548      2014-01-05 23:47:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1001     :  UpdatusUser     :  -    :  0x2c949b5    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-01-05 23:47:31                                  Microsoft-Windows-Security-Auditing  4726:    .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24cea      :    :  S-1-5-21-839303928-1106944401-891866635-1001     :  UpdatusUser     :  -     :   Privileges -  
      Audit Success   13826      2014-01-05 23:47:31                                  Microsoft-Windows-Security-Auditing  4729:       .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24cea    :    :  S-1-5-21-839303928-1106944401-891866635-1001     :  -    :    :  S-1-5-21-839303928-1106944401-891866635-513    :  None    :  -     :   :  -  
      Audit Success   12545      2014-01-05 23:50:52                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1001     :  UpdatusUser     :  -    :  0xb1756     :   5          .           " ".      ,       .  
      Audit Success   12544      2014-01-05 23:55:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 23:55:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-01-05 23:57:09                                  Microsoft-Windows-Security-Auditing  4720:    .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24cea      :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :      SAM: UpdatusUser    :  %%1793     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : %%1794       :  %%1794     : 513    : -     UAC:  0x0     UAC:  0x15      :     %%2080    %%2082    %%2084    : %%1793    SID:  -    :  %%1797     :   Privileges  -  
      Audit Success   13824      2014-01-05 23:57:09                                  Microsoft-Windows-Security-Auditing  4722:    .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24cea      :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -  
      Audit Success   13824      2014-01-05 23:57:09                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24cea      :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -     :      SAM: UpdatusUser    :  UpdatusUser     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : 05.01.2014 22:57:09       :  %%1794     : 513    : -     UAC:  0x15     UAC:  0x210      :     %%2048    %%2050    %%2089    : -    SID:  -    :  %%1797     :   :  -  
      Audit Success   13824      2014-01-05 23:57:09                                  Microsoft-Windows-Security-Auditing  4724:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24cea      :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -  
      Audit Success   13826      2014-01-05 23:57:09                                  Microsoft-Windows-Security-Auditing  4728:       .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24cea    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  -    :    :  S-1-5-21-839303928-1106944401-891866635-513    :  None    :  -     :   :  -  
      Audit Success   13569      2014-01-05 23:57:10                                  Microsoft-Windows-Security-Auditing  4717:       .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24cea      :     :  S-1-5-21-839303928-1106944401-891866635-1002     :     :  SeServiceLogonRight  
      Audit Success   13569      2014-01-05 23:57:10                                  Microsoft-Windows-Security-Auditing  4717:       .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24cea      :     :  S-1-5-21-839303928-1106944401-891866635-1002     :     :  SeDenyInteractiveLogonRight  
      Audit Success   12544      2014-01-05 23:57:11                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24cea   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1ddc    :  C:\NVIDIA\DisplayDriver\331.82\Win8_WinVista_Win7\International\setup.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-05 23:57:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24cea     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x30879c7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ddc    :  C:\NVIDIA\DisplayDriver\331.82\Win8_WinVista_Win7\International\setup.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 23:57:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x30879c7    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-01-05 23:57:16                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x30879c7     :   5          .           " ".      ,       .  
      Audit Success   12544      2014-01-05 23:57:17                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x24c    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-05 23:57:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x3093a2a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 23:57:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x3093a2a    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 23:58:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 23:58:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 23:58:27                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24cea   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1ddc    :  C:\NVIDIA\DisplayDriver\331.82\Win8_WinVista_Win7\International\setup.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-05 23:58:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24cea     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x30ea305   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1ddc    :  C:\NVIDIA\DisplayDriver\331.82\Win8_WinVista_Win7\International\setup.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-01-05 23:58:27                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x30ea305     :   5          .           " ".      ,       .  
      Audit Success   12548      2014-01-05 23:58:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x30ea305    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-05 23:58:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-05 23:58:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-01-06 00:00:53                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x24d14      ,   .  ,  ,  .        .  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\winsrv.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\kernel32.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\conhost.exe    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\KernelBase.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:00                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\System.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\SOS.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscordacwks.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v3.0\WPF\wpfgfx_v0300.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\System.AddIn.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\WindowsBase.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\PresentationCore.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.0\PresentationFramework.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\tzres.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\ru-RU\tzres.dll.mui    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\en-US\tzres.dll.mui    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\servicing\GC32\tzupd.exe    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 00:01:01                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\shell32.dll    : 0x14      :    : 0x1b00    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   103        2014-01-06 00:01:08                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-06 00:03:57                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-06 00:03:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-06 00:03:58                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x9cfa  
      Audit Success   12544      2014-01-06 00:04:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 00:04:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 00:04:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 00:04:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 00:04:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 00:04:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 00:04:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 00:04:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 00:04:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 00:04:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 00:04:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 00:04:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 00:04:10                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-06 00:04:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 00:04:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 00:04:11                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-06 00:04:22                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x24c    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 00:04:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x1f489   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 00:04:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x1f489    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 00:04:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x24ac9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 00:04:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 00:04:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 00:06:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 00:06:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2014-01-06 00:06:58                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-06 00:08:00                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-06 00:08:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 00:08:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 00:08:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-06 00:08:01                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa042  
      Audit Success   12544      2014-01-06 00:08:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 00:08:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 00:08:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 00:08:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 00:08:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 00:08:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 00:08:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 00:08:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 00:08:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 00:08:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 00:08:07                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-06 00:08:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 00:08:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 00:08:17                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x250    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 00:08:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x1b74b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 00:08:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x1b74b    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 00:08:31                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-06 00:08:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x294f8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 00:09:05                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x270    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 00:09:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x3afd3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 00:09:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x3afdf   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 00:09:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x3afd3    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 00:09:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 00:09:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 00:10:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 00:10:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 00:12:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 00:12:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2014-01-06 01:00:10                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x4bc   :  C:\Windows\System32\svchost.exe     :  2014-01-05T23:00:09.608388200Z   :  2014-01-05T21:00:10.409975200Z          .    Windows,    ,    .           .  
      Audit Success   12288      2014-01-06 01:00:10                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x4bc   :  C:\Windows\System32\svchost.exe     :  2014-01-05T21:00:10.409975200Z   :  2014-01-05T21:00:10.409000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2014-01-06 01:00:10                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5      :    : 0x4bc   :  C:\Windows\System32\svchost.exe     :  2014-01-05T21:00:10.412000100Z   :  2014-01-05T21:00:10.412000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2014-01-06 02:26:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 02:26:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 02:48:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 02:48:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2014-01-06 02:56:45                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-06 02:56:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-06 02:56:45                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa39f  
      Audit Success   12544      2014-01-06 02:56:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 02:56:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 02:56:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 02:56:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 02:56:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 02:56:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 02:56:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 02:56:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 02:56:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 02:56:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2014-01-06 02:56:49                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12292      2014-01-06 02:56:50                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-06 02:56:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 02:56:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 02:56:54                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-06 02:57:06                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 02:57:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1e2c1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 02:57:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1e2f3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 02:57:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1e2c1    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 02:57:14                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x250    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 02:57:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x23c78   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 02:57:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x23c78    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 02:57:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2945c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 02:58:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 02:58:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-01-06 02:58:23                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1e2f3      ,   .  ,  ,  .        .  
      Audit Success   103        2014-01-06 02:58:26                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-06 02:59:22                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-06 02:59:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-06 02:59:22                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x99c9  
      Audit Success   12544      2014-01-06 02:59:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 02:59:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 02:59:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 02:59:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 02:59:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 02:59:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 02:59:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 02:59:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 02:59:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 02:59:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 02:59:28                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-06 02:59:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 02:59:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 02:59:31                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2c0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 02:59:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1a826   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2c0    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 02:59:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1a850   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2c0    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 02:59:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1a826    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 02:59:33                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-06 02:59:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 02:59:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 02:59:50                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x24c    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 02:59:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x22dd6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 02:59:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x22dd6    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 02:59:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2b49a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 03:00:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 03:00:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2014-01-06 03:00:26                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1a826      :    : 0xffc   :  C:\Windows\System32\dllhost.exe     :  2014-01-05T23:01:27.958329100Z   :  2014-01-05T23:00:26.000000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2014-01-06 03:00:26                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1a826      :    : 0xffc   :  C:\Windows\System32\dllhost.exe     :  2014-01-05T23:00:26.000000000Z   :  2014-01-05T23:00:26.000000000Z          .    Windows,    ,    .           .  
      Audit Success   12544      2014-01-06 03:00:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 03:00:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 03:01:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 03:01:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 03:13:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 03:13:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 03:23:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x24c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 03:23:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-01-06 03:42:56                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1a850      ,   .  ,  ,  .        .  
      Audit Success   103        2014-01-06 03:42:58                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-06 03:43:49                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-06 03:43:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-06 03:43:49                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xaa0f  
      Audit Success   12544      2014-01-06 03:43:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 03:43:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 03:43:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 03:43:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 03:43:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 03:43:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 03:43:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 03:43:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 03:43:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 03:43:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 03:43:56                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-06 03:43:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 03:43:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 03:43:57                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-06 03:43:57                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 03:43:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1c108   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 03:43:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1c132   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 03:43:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1c108    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 03:44:25                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x254    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 03:44:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x2fe4c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 03:44:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x2fe4c    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 03:44:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x38ab3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 03:44:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 03:44:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 03:46:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 03:46:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-01-06 04:25:22                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1c132      ,   .  ,  ,  .        .  
      Audit Success   103        2014-01-06 04:25:23                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-06 10:52:08                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-06 10:52:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-06 10:52:08                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa942  
      Audit Success   12544      2014-01-06 10:52:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 10:52:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 10:52:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 10:52:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 10:52:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 10:52:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 10:52:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 10:52:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 10:52:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 10:52:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 10:52:16                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-06 10:52:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 10:52:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 10:52:17                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 10:52:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1be13   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 10:52:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1be3d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 10:52:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1be13    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 10:52:21                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-06 10:52:42                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x254    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 10:52:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x30bb5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 10:52:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x30bb5    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 10:52:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x34613   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 10:52:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 10:52:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 10:54:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 10:54:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 11:19:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 11:19:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 11:20:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 11:20:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 11:23:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 11:23:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 11:23:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 11:23:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-06 11:24:04                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x1170    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x27d4b0  
      Audit Success   13568      2014-01-06 11:24:04                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x1170    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x27d4b0  
      Audit Success   12288      2014-01-06 11:34:19                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-06 11:34:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-06 11:34:19                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xab4f  
      Audit Success   12544      2014-01-06 11:34:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 11:34:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 11:34:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 11:34:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 11:34:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 11:34:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 11:34:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 11:34:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 11:34:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 11:34:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2014-01-06 11:34:22                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2014-01-06 11:34:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 11:34:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 11:34:24                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-06 11:34:24                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x280    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 11:34:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1a7b2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 11:34:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1a7dc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 11:34:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1a7b2    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 11:34:26                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-06 11:34:38                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x268    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 11:34:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x2426d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 11:34:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x2426d    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 11:34:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x305e3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 11:35:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 11:35:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 11:36:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 11:36:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 11:36:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 11:36:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 11:46:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 11:46:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 12:49:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 12:49:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 13:07:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 13:07:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2014-01-06 13:32:40                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-06 13:32:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-06 13:32:40                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x9e16  
      Audit Success   12544      2014-01-06 13:32:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 13:32:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 13:32:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 13:32:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 13:32:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 13:32:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 13:32:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 13:32:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 13:32:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 13:32:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2014-01-06 13:32:43                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12292      2014-01-06 13:32:44                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-06 13:32:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 13:32:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 13:32:46                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-06 13:32:46                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x25c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 13:32:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1acb0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 13:32:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1ace9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x25c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 13:32:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1acb0    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 13:32:52                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x278    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 13:32:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x22357   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\services.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 13:32:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x22357    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 13:32:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2bbbe   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 13:33:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 13:33:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-01-06 13:34:54                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1ace9      ,   .  ,  ,  .        .  
      Audit Success   103        2014-01-06 13:34:55                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-06 13:38:40                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-06 13:38:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 13:38:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 13:38:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 13:38:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 13:38:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-06 13:38:40                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa7c4  
      Audit Success   12544      2014-01-06 13:38:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 13:38:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 13:38:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 13:38:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 13:38:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 13:38:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 13:38:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 13:38:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 13:38:43                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-01-06 13:38:45                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-06 13:38:45                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x27c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 13:38:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1b6e9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 13:38:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1b72a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 13:38:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1b6e9    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 13:38:54                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x264    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 13:38:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x27e36   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 13:38:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x27e36    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 13:39:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x3ecfb   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 13:39:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 13:39:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 13:41:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 13:41:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 13:42:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 13:42:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2014-01-06 14:36:21                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-06 14:36:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-06 14:36:21                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa911  
      Audit Success   12544      2014-01-06 14:36:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 14:36:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 14:36:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 14:36:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 14:36:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 14:36:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2014-01-06 14:36:24                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2014-01-06 14:36:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 14:36:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 14:36:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 14:36:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 14:36:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 14:36:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 14:36:26                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-06 14:36:28                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x278    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 14:36:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1b302   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 14:36:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1b32c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 14:36:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1b302    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 14:36:29                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-06 14:36:37                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x260    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 14:36:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x242d3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 14:36:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x242d3    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 14:36:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2e64c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 14:37:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 14:37:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 14:39:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 14:39:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-01-06 14:42:48                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1b32c      ,   .  ,  ,  .        .  
      Audit Success   103        2014-01-06 14:42:49                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-06 14:50:51                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-06 14:50:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-06 14:50:52                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa28f  
      Audit Success   12544      2014-01-06 14:50:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 14:50:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 14:50:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 14:50:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 14:50:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 14:50:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 14:50:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 14:50:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 14:50:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 14:50:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 14:50:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 14:50:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 14:50:57                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-01-06 14:50:58                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-06 14:50:59                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x26c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 14:50:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1b453   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 14:50:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1b47d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 14:50:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1b453    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 14:51:04                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x278    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 14:51:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x21a5a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\services.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 14:51:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x21a5a    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 14:51:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x24d36   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 14:51:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 14:51:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 14:51:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 14:51:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 14:53:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 14:53:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-01-06 14:56:07                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1b47d      ,   .  ,  ,  .        .  
      Audit Success   103        2014-01-06 14:56:08                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-06 15:05:43                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-06 15:05:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:05:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:05:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-06 15:05:43                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa530  
      Audit Success   12544      2014-01-06 15:05:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:05:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:05:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:05:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:05:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:05:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:05:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:05:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:05:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:05:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 15:05:47                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-01-06 15:05:48                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-06 15:05:49                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x270    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 15:05:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1b446   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:05:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1b470   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:05:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1b446    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:05:54                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x250    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 15:05:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x226a1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:05:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x226a1    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:06:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x30455   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:06:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:06:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:06:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:06:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:08:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:08:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-01-06 15:13:35                                  Microsoft-Windows-Security-Auditing  4722:    .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1b446      :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -  
      Audit Success   13824      2014-01-06 15:13:35                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1b446      :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -     :      SAM:     :  %%1793     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : 14.07.2009 8:55:45       :  %%1794     : 513    : -     UAC:  0x211     UAC:  0x210      :     %%2048    : %%1793    SID:  -    :  %%1797     :   :  -  
      Audit Success   13824      2014-01-06 15:14:01                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1b446      :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -     :      SAM: -    :  -     : -    :  -    :  -     :  -     :  -     : -     : -       :  -     : -    : -     UAC:  -     UAC:  -      : -    : -    SID:  -    :  -     :   :  -  
      Audit Success   12545      2014-01-06 15:14:11                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0x1b470      ,   .  ,  ,  .        .  
      Audit Success   103        2014-01-06 15:14:12                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-06 15:15:06                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-06 15:15:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:15:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:15:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:15:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:15:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:15:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:15:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-06 15:15:07                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa74d  
      Audit Success   12544      2014-01-06 15:15:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:15:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:15:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:15:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 15:15:10                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-06 15:15:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:15:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 15:15:12                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-06 15:15:15                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x270    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 15:15:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1eb31   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x270    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:15:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1eb31    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:15:19                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x250    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 15:15:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x25daf   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:15:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x25daf    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:15:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2e3c8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:15:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:15:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:17:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:17:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:19:37                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0xc74    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 15:19:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0xf248a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0xc74    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:19:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0xf24aa   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0xc74    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:19:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0xf248a    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:19:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:19:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:22:04                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0xef8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 15:22:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x15b471   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0xef8    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:22:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x15b471    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-01-06 15:22:06                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x15b471     :   2          .           " ".      ,       .  
      Audit Success   13826      2014-01-06 15:22:34                                  Microsoft-Windows-Security-Auditing  4733:       .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1eb31    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :  -    :    :  S-1-5-32-544    :      :  Builtin     :   :  -  
      Audit Success   13824      2014-01-06 15:22:36                                  Microsoft-Windows-Security-Auditing  4726:    .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1eb31      :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -     :   Privileges -  
      Audit Success   13826      2014-01-06 15:22:36                                  Microsoft-Windows-Security-Auditing  4729:       .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1eb31    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :  -    :    :  S-1-5-21-839303928-1106944401-891866635-513    :  None    :  -     :   :  -  
      Audit Success   12544      2014-01-06 15:25:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:25:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:26:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:26:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:26:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:26:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-06 15:26:37                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x1614    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x22d1ed  
      Audit Success   13568      2014-01-06 15:26:37                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x1614    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x22d1ed  
      Audit Success   12544      2014-01-06 15:27:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:27:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-01-06 15:27:07                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1eb31      ,   .  ,  ,  .        .  
      Audit Success   12545      2014-01-06 15:27:10                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-1000     :       :  -    :  0xf24aa      ,   .  ,  ,  .        .  
      Audit Success   13568      2014-01-06 15:27:11                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\PresentationHost.exe    : 0x18      :    : 0x1358    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2014-01-06 15:27:11                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\PresentationHostProxy.dll    : 0x18      :    : 0x1358    : C:\Windows\System32\poqexec.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   103        2014-01-06 15:27:15                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-06 15:28:10                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-06 15:28:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:28:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:28:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:28:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:28:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:28:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:28:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:28:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:28:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:28:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:28:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-06 15:28:11                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xaab4  
      Audit Success   12544      2014-01-06 15:28:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:28:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 15:28:15                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-06 15:28:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:28:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:28:20                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x264    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 15:28:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x1c706   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:28:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x1c706    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 15:28:25                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-06 15:28:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2757e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:28:32                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x26c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 15:28:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x2ee87   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:28:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x2ee87    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:29:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:29:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:29:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:29:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:30:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:30:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:34:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:34:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:37:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x264    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:37:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-01-06 15:38:15                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x2ee87      ,   .  ,  ,  .        .  
      Audit Success   103        2014-01-06 15:38:16                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-06 15:39:13                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-06 15:39:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-06 15:39:13                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x9f4b  
      Audit Success   12544      2014-01-06 15:39:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:39:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:39:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:39:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 15:39:20                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-06 15:39:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:39:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:39:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:39:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:39:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:39:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:39:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:39:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 15:39:21                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-06 15:39:21                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x268    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 15:39:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1b836   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:39:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1b836    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:39:24                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x260    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 15:39:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x1ed3c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:39:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x1ed3c    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:39:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2553b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:39:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:39:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:40:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:40:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:40:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:40:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:41:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:41:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-01-06 15:42:14                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1b836      ,   .  ,  ,  .        .  
      Audit Success   103        2014-01-06 15:42:16                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-06 15:43:09                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-06 15:43:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-06 15:43:10                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa302  
      Audit Success   12544      2014-01-06 15:43:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:43:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:43:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:43:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:43:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:43:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:43:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:43:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:43:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:43:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 15:43:21                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-06 15:43:21                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x268    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 15:43:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x194b3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:43:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:43:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x194b3    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:43:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 15:43:22                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-06 15:43:23                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x260    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 15:43:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x2042c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:43:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x2042c    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:43:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x277ed   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:43:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:43:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:45:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:45:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:46:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:46:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:46:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:46:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:46:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:46:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-06 15:47:38                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0xba8    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0xa6416  
      Audit Success   13568      2014-01-06 15:47:38                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0xba8    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0xa6416  
      Audit Success   12544      2014-01-06 15:47:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:47:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:48:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:48:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2014-01-06 15:52:14                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-06 15:52:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-06 15:52:14                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa8fe  
      Audit Success   12544      2014-01-06 15:52:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:52:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:52:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:52:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:52:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:52:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:52:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:52:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:52:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 15:52:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2014-01-06 15:52:19                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2014-01-06 15:52:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:52:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 15:52:20                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-01-06 15:52:20                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-06 15:52:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:52:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:52:34                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x250    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 15:52:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x2074c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:52:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x2074c    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:52:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2ca7f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 15:52:53                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 15:52:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x2ebda   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:52:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x2ebda    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:53:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:53:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 15:54:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 15:54:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 16:03:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 16:03:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 16:05:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 16:05:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 16:29:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 16:29:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 16:30:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x250    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 16:30:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-01-06 16:32:05                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x2ebda      ,   .  ,  ,  .        .  
      Audit Success   103        2014-01-06 16:32:07                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-06 16:36:31                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-06 16:36:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-06 16:36:32                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x8f0d  
      Audit Success   12544      2014-01-06 16:36:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 16:36:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 16:36:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 16:36:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 16:36:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 16:36:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 16:36:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 16:36:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 16:36:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 16:36:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 16:36:40                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1c0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 16:36:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x11b94   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1c0    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 16:36:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x11b94    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 16:38:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 16:38:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-01-06 16:47:00                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x11b94      ,   .  ,  ,  .        .  
      Audit Success   103        2014-01-06 16:47:01                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-06 16:47:43                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-06 16:47:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-06 16:47:43                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa6c8  
      Audit Success   12544      2014-01-06 16:47:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 16:47:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 16:47:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 16:47:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 16:47:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 16:47:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 16:47:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 16:47:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 16:47:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 16:47:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 16:47:47                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-06 16:47:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 16:47:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-06 16:47:49                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-06 16:47:50                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x268    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 16:47:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1b1f7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x268    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 16:47:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1b1f7    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 16:47:57                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x260    :  C:\Windows\System32\services.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-06 16:47:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x1f973   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 16:47:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x1f973    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 16:47:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x24cb2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 16:48:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 16:48:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 16:50:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 16:50:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 17:41:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 17:41:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-06 17:54:13                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    : Security    : Device    : \Device\519D458926485D6E    : 0x3034      :    : 0x4    :      :     : S:AI     :  S:(ML;;NW;;;S-1-16-0)  
      Audit Success   12544      2014-01-06 18:50:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 18:50:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 18:52:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 18:52:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Failure   12290      2014-01-06 18:54:24                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys   
      Audit Failure   12290      2014-01-06 18:54:24                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys   
      Audit Failure   12290      2014-01-06 18:54:24                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys   
      Audit Failure   12290      2014-01-06 18:54:24                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys   
      Audit Failure   12290      2014-01-06 18:54:24                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys   
      Audit Failure   12290      2014-01-06 18:54:24                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys   
      Audit Failure   12290      2014-01-06 18:54:24                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys   
      Audit Failure   12290      2014-01-06 18:54:24                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys   
      Audit Failure   12290      2014-01-06 18:54:24                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys   
      Audit Failure   12290      2014-01-06 18:54:24                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys   
      Audit Failure   12290      2014-01-06 18:54:24                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys   
      Audit Failure   12290      2014-01-06 18:54:24                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys   
      Audit Success   12544      2014-01-06 18:57:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-06 18:57:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 18:57:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-06 18:57:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-06 18:59:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-06 18:59:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Failure   12290      2014-01-06 19:02:55                                  Microsoft-Windows-Security-Auditing  5038:     ,     .         ,          .     : \Device\HarddiskVolume3\\MSI Afterburner\RTCore32.sys   
      Audit Success   12288      2014-01-06 21:45:11                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1b1f7      :    : 0x16cc   :  C:\Windows\System32\rundll32.exe     :  2014-01-06T15:45:13.235982200Z   :  2014-01-06T17:45:11.000000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2014-01-06 21:45:11                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1b1f7      :    : 0x16cc   :  C:\Windows\System32\rundll32.exe     :  2014-01-06T17:45:11.010000000Z   :  2014-01-06T17:45:11.000000000Z          .    Windows,    ,    .           .  
      Audit Success   13824      2014-01-07 00:33:41                                  Microsoft-Windows-Security-Auditing  4738:    .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1b1f7      :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -     :      SAM: UpdatusUser    :  UpdatusUser     : -    :  %%1793    :  %%1793     :  %%1793     :  %%1793     : %%1793     : 07.01.2014 0:33:41       :  %%1794     : 513    : -     UAC:  0x210     UAC:  0x210      : -    : -    SID:  -    :  %%1797     :   :  -  
      Audit Success   13824      2014-01-07 00:33:41                                  Microsoft-Windows-Security-Auditing  4724:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1b1f7      :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -  
      Audit Success   12544      2014-01-07 00:33:42                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1b1f7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  UpdatusUser     :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x1204    :  C:\Users\836D~1\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\10.11.15.0\setup.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-07 00:33:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1b1f7     :   5     :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x1526845   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x1204    :  C:\Users\836D~1\AppData\Local\Temp\NVIDIA\GeForceExperienceSelfUpdate\10.11.15.0\setup.exe      :     : -     : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 00:33:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x1526845    :  SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
      Audit Success   13824      2014-01-07 00:33:42                                  Microsoft-Windows-Security-Auditing  4726:    .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1b1f7      :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -     :   Privileges -  
      Audit Success   13826      2014-01-07 00:33:42                                  Microsoft-Windows-Security-Auditing  4729:       .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1b1f7    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  -    :    :  S-1-5-21-839303928-1106944401-891866635-513    :  None    :  -     :   :  -  
      Audit Success   12545      2014-01-07 00:33:43                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x1526845     :   5          .           " ".      ,       .  
      Audit Success   12544      2014-01-07 00:35:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 00:35:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 00:35:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 00:35:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-07 00:35:51                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x1338    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x160cb00  
      Audit Success   13568      2014-01-07 00:35:51                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x1338    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x160cb00  
      Audit Success   12545      2014-01-07 00:37:05                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-21-839303928-1106944401-891866635-1002     :  UpdatusUser     :  -    :  0x1f973     :   5          .           " ".      ,       .  
      Audit Success   12544      2014-01-07 00:45:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x260    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 00:45:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2014-01-07 01:25:11                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-07 01:25:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-07 01:25:11                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa7f3  
      Audit Success   12544      2014-01-07 01:25:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 01:25:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 01:25:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 01:25:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 01:25:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 01:25:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 01:25:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 01:25:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 01:25:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 01:25:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2014-01-07 01:25:19                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2014-01-07 01:25:19                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-07 01:25:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x192ba   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 01:25:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x192ba    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-07 01:25:20                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-01-07 01:25:20                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-07 01:25:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 01:25:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 01:25:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2b14e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 01:26:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 01:26:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Failure   12290      2014-01-07 01:28:00                                  Microsoft-Windows-Security-Auditing  5038:     ,     .         ,          .     : \Device\HarddiskVolume3\\MSI Afterburner\RTCore32.sys   
      Audit Success   12544      2014-01-07 01:28:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 01:28:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 01:28:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 01:28:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 02:21:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 02:21:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2014-01-07 03:11:12                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-07 03:11:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 03:11:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x258    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 03:11:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x258    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 03:11:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x258    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 03:11:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x258    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 03:11:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x258    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 03:11:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 03:11:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 03:11:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 03:11:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 03:11:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-07 03:11:12                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xac73  
      Audit Success   101        2014-01-07 03:11:14                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12292      2014-01-07 03:11:15                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-07 03:11:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x258    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 03:11:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-07 03:11:19                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-07 03:11:19                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x278    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-07 03:11:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1cbf2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x278    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 03:11:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1cbf2    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 03:11:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x29eaa   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 03:11:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x258    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 03:11:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 03:13:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x258    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 03:13:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 03:13:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x258    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 03:13:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 03:16:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x258    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 03:16:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x258    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 03:16:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 03:16:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 03:45:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x258    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 03:45:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 03:46:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x258    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 03:46:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x258    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 03:46:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 03:46:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:34                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12290      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5061:  .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : RSA    : IIS Express Development Certificate Container    : %%2499     :   : %%2480    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   12292      2014-01-07 03:46:35                                  Microsoft-Windows-Security-Auditing  5058:    .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7     :    : Microsoft Software Key Storage Provider    : %%2432    : IIS Express Development Certificate Container    : %%2499         :     : C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fad662b360941f26a1193357aab3c12d_627b59f6-0bac-4a03-9306-e99a4217deb4   : %%2458    : 0x0  
      Audit Success   13568      2014-01-07 03:46:59                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0xad4    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x234e26  
      Audit Success   13568      2014-01-07 03:46:59                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0xad4    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x234e26  
      Audit Success   12544      2014-01-07 03:50:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x258    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 03:50:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 03:50:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x258    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 03:50:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 03:50:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x258    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 03:50:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 03:50:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x258    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 03:50:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 03:50:56                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-0-0     :  -     :  -    :  0xa62b   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  .   GUID :  {00000000-0000-0000-0000-000000000000}     :     : -    : -      :    :  0x384    :  C:\Windows\System32\svchost.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-07 03:51:51                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-0-0     :  -     :  -    :  0xa62b   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  .   GUID :  {00000000-0000-0000-0000-000000000000}     :     : -    : -      :    :  0x384    :  C:\Windows\System32\svchost.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Failure   12290      2014-01-07 03:56:11                                  Microsoft-Windows-Security-Auditing  5038:     ,     .         ,          .     : \Device\HarddiskVolume2\Users\\Desktop\EVEREST Ultimate Edition\kerneld.wnt   
      Audit Success   12544      2014-01-07 04:12:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x258    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 04:12:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x258    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 04:12:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 04:12:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-01-07 05:42:28                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1cbf2      ,   .  ,  ,  .        .  
      Audit Success   103        2014-01-07 05:42:30                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-07 14:29:41                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-07 14:29:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-07 14:29:42                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x922f  
      Audit Success   12544      2014-01-07 14:29:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 14:29:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 14:29:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 14:29:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 14:29:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 14:29:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 14:29:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 14:29:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 14:29:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 14:29:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-07 14:29:49                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-01-07 14:29:49                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-07 14:29:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 14:29:49                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-07 14:29:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x18bd3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 14:29:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 14:29:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x18bd3    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 14:30:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x38ffc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 14:30:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 14:30:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 14:30:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 14:30:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 14:30:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 14:30:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 14:31:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 14:31:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 14:32:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 14:32:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 14:46:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 14:46:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 15:27:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 15:27:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 15:40:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x26c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 15:40:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-01-07 15:54:43                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x18bd3      ,   .  ,  ,  .        .  
      Audit Success   103        2014-01-07 15:54:45                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-07 15:55:40                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-07 15:55:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-07 15:55:40                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0x9fa6  
      Audit Success   12544      2014-01-07 15:55:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 15:55:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 15:55:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 15:55:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 15:55:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 15:55:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 15:55:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 15:55:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 15:55:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 15:55:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 15:55:44                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-07 15:55:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x18aae   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 15:55:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x18aae    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-07 15:55:45                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-01-07 15:55:45                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-07 15:55:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 15:55:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 15:55:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2af58   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 15:56:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 15:56:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 15:56:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 15:56:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 15:56:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 15:56:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 15:58:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 15:58:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 16:11:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 16:11:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 16:11:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 16:11:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 16:31:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 16:31:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 16:33:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28703d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : -     : 192.168.0.102    :  49195       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 16:33:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2878f9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : -     : 192.168.0.102    :  49205       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-01-07 16:34:04                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28703d     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-01-07 16:34:04                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2878f9     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-01-07 16:35:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 16:35:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Failure   12290      2014-01-07 16:40:03                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys   
      Audit Failure   12290      2014-01-07 16:40:03                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys   
      Audit Failure   12290      2014-01-07 16:40:03                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys   
      Audit Failure   12290      2014-01-07 16:40:03                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys   
      Audit Failure   12290      2014-01-07 16:40:03                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys   
      Audit Failure   12290      2014-01-07 16:40:03                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\KLELAMX86\klelam.sys   
      Audit Failure   12290      2014-01-07 16:40:03                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys   
      Audit Failure   12290      2014-01-07 16:40:03                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys   
      Audit Failure   12290      2014-01-07 16:40:03                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys   
      Audit Failure   12290      2014-01-07 16:40:03                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys   
      Audit Failure   12290      2014-01-07 16:40:03                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys   
      Audit Failure   12290      2014-01-07 16:40:03                                  Microsoft-Windows-Security-Auditing  6281:     ,  -    . ,      -      .         .     : \Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys   
      Audit Success   12544      2014-01-07 16:41:39                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-0-0     :  -     :  -    :  0x9c2e   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  .   GUID :  {00000000-0000-0000-0000-000000000000}     :     : -    : -      :    :  0x394    :  C:\Windows\System32\svchost.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-07 16:45:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 16:45:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 16:45:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 16:45:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 16:45:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x4c14b2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : -     : 192.168.0.102    :  54047       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 16:45:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x4c1b40   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : -     : 192.168.0.102    :  54071       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-01-07 16:46:10                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x4c14b2     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-01-07 16:46:10                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x4c1b40     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-01-07 16:46:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 16:46:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 16:48:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x254    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 16:48:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-07 16:48:48                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x1204    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x549771  
      Audit Success   13568      2014-01-07 16:48:48                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x1204    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x549771  
      Audit Success   13826      2014-01-07 16:49:03                                  Microsoft-Windows-Security-Auditing  4731:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :    :  S-1-5-21-839303928-1106944401-891866635-1003    :  AMD FUEL    :  -    :      SAM: AMD FUEL    SID:  -     :   :  -  
      Audit Success   13826      2014-01-07 16:49:03                                  Microsoft-Windows-Security-Auditing  4735:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7    :    :  S-1-5-21-839303928-1106944401-891866635-1003    :  AMD FUEL    :  -     :      SAM: -    SID:  -     :   :  -  
      Audit Success   12545      2014-01-07 16:55:42                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x18aae      ,   .  ,  ,  .        .  
      Audit Success   103        2014-01-07 16:55:44                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-07 16:56:39                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-07 16:56:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-07 16:56:39                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb3b5  
      Audit Success   12544      2014-01-07 16:56:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 16:56:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 16:56:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 16:56:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 16:56:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 16:56:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 16:56:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 16:56:44                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-07 16:56:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1d253   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a0    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 16:56:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 16:56:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 16:56:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 16:56:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1d253    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-07 16:56:45                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-01-07 16:56:45                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-07 16:56:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 16:56:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 16:57:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x42a41   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 16:57:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 16:57:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 16:57:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 16:57:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 16:57:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 16:57:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 16:58:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 16:58:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 16:59:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 16:59:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 17:13:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:13:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 17:13:13                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-0-0     :  -     :  -    :  0xb10e   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  .   GUID :  {00000000-0000-0000-0000-000000000000}     :     : -    : -      :    :  0x3bc    :  C:\Windows\System32\svchost.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12288      2014-01-07 17:19:15                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-07 17:19:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 17:19:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:19:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-07 17:19:15                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb902  
      Audit Success   12544      2014-01-07 17:19:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:19:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2014-01-07 17:19:18                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2014-01-07 17:19:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 17:19:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 17:19:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:19:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 17:19:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 17:19:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 17:19:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:19:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-07 17:19:20                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-07 17:19:21                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-07 17:19:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1e2d4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:19:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1e2d4    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-07 17:19:22                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-07 17:20:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x51374   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 17:20:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:20:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 17:20:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:20:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 17:20:32                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-0-0     :  -     :  -    :  0xb5f7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  .   GUID :  {00000000-0000-0000-0000-000000000000}     :     : -    : -      :    :  0x3c4    :  C:\Windows\System32\svchost.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-07 17:20:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:20:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 17:20:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:20:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 17:22:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:22:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2014-01-07 17:43:51                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-07 17:43:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 17:43:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:43:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-07 17:43:51                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xba6d  
      Audit Success   12544      2014-01-07 17:43:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:43:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 17:43:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:43:53                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 17:43:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 17:43:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:43:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 17:43:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2014-01-07 17:43:56                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2014-01-07 17:43:56                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-07 17:43:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1c866   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:43:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1c866    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-07 17:43:57                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-07 17:43:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:43:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-07 17:43:58                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-07 17:44:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x41e37   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 17:44:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:44:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 17:44:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:44:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 17:44:43                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-0-0     :  -     :  -    :  0xb76d   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  .   GUID :  {00000000-0000-0000-0000-000000000000}     :     : -    : -      :    :  0x3bc    :  C:\Windows\System32\svchost.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-07 17:44:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:44:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 17:46:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:46:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Failure   12290      2014-01-07 17:47:39                                  Microsoft-Windows-Security-Auditing  5038:     ,     .         ,          .     : \Device\HarddiskVolume3\\MSI Afterburner\RTCore32.sys   
      Audit Success   12544      2014-01-07 17:48:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:48:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 17:48:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 17:48:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:48:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 17:48:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 17:48:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:48:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-07 17:49:24                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x1274    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x120a06  
      Audit Success   13568      2014-01-07 17:49:24                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x1274    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x120a06  
      Audit Success   13568      2014-01-07 17:52:09                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x1274    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x173825  
      Audit Success   13568      2014-01-07 17:52:09                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x1274    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x173825  
      Audit Success   12544      2014-01-07 17:52:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 17:52:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 18:15:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 18:15:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 18:55:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 18:55:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 19:37:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 19:37:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 20:27:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xd0279a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : -     : 192.168.0.102    :  49159       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 20:27:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xd02d28   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : -     : 192.168.0.102    :  49162       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-01-07 20:27:43                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xd0279a     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-01-07 20:27:43                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xd02d28     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-01-07 20:39:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xd85bc2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : -     : 192.168.0.102    :  49245       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 20:39:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xd86157   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : -     : 192.168.0.102    :  49246       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-01-07 20:39:49                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xd85bc2     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-01-07 20:39:49                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xd86157     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-01-07 20:51:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xdf5ee3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : -     : 192.168.0.102    :  51341       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 20:51:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xdf6313   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : -     : 192.168.0.102    :  51362       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-01-07 20:51:55                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xdf5ee3     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-01-07 20:51:55                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xdf6313     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-01-07 20:57:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 20:57:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 21:03:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xf1a98e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : -     : 192.168.0.102    :  52507       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 21:03:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xf1af01   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : -     : 192.168.0.102    :  52510       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-01-07 21:04:01                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xf1a98e     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-01-07 21:04:01                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xf1af01     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-01-07 21:15:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfab90a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : -     : 192.168.0.102    :  53078       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 21:15:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfabed1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : -     : 192.168.0.102    :  53079       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-01-07 21:16:01                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfab90a     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-01-07 21:16:01                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0xfabed1     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-01-07 21:19:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 21:19:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 21:27:53                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x104f3f6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : -     : 192.168.0.102    :  53936       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 21:27:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x104f979   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : -     : 192.168.0.102    :  53959       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2014-01-07 21:28:07                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x104f3f6     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-01-07 21:28:07                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x104f979     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-01-07 21:37:39                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1c866      ,   .  ,  ,  .        .  
      Audit Success   103        2014-01-07 21:37:44                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-07 21:39:19                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-07 21:39:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-07 21:39:19                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb6d1  
      Audit Success   12544      2014-01-07 21:39:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 21:39:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 21:39:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 21:39:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 21:39:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 21:39:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 21:39:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 21:39:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 21:39:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 21:39:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 21:39:23                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-07 21:39:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1d522   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a0    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 21:39:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1d522    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-07 21:39:24                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-01-07 21:39:24                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-07 21:39:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 21:39:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 21:39:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x38930   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 21:39:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 21:39:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 21:39:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x5fe9e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : -     : 192.168.0.102    :  54219       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 21:39:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 21:39:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 21:40:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x6337b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     : -     : 192.168.0.102    :  54220       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  128          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 21:40:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 21:40:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-01-07 21:40:13                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x5fe9e     :   3          .           " ".      ,       .  
      Audit Success   12545      2014-01-07 21:40:13                                  Microsoft-Windows-Security-Auditing  4634:      .    :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x6337b     :   3          .           " ".      ,       .  
      Audit Success   12544      2014-01-07 21:40:24                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-0-0     :  -     :  -    :  0xb20d   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  .   GUID :  {00000000-0000-0000-0000-000000000000}     :     : -    : -      :    :  0x3b8    :  C:\Windows\System32\svchost.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-07 21:40:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 21:40:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Failure   12290      2014-01-07 21:40:59                                  Microsoft-Windows-Security-Auditing  5038:     ,     .         ,          .     : \Device\HarddiskVolume3\\MSI Afterburner\RTCore32.sys   
      Audit Success   12544      2014-01-07 21:41:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 21:41:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 21:46:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 21:46:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2014-01-07 21:57:01                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-07 21:57:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-07 21:57:01                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xbaad  
      Audit Success   101        2014-01-07 21:57:02                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2014-01-07 21:57:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 21:57:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 21:57:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 21:57:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 21:57:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 21:57:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 21:57:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 21:57:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 21:57:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 21:57:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-07 21:57:04                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-07 21:57:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 21:57:04                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-07 21:57:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1da9d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 21:57:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 21:57:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1da9d    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-07 21:57:05                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-07 21:58:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x5b8c6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 21:58:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 21:58:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 21:58:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 21:58:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 21:58:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 21:58:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 21:59:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 21:59:06                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-0-0     :  -     :  -    :  0xb5e0   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  .   GUID :  {00000000-0000-0000-0000-000000000000}     :     : -    : -      :    :  0x3c0    :  C:\Windows\System32\svchost.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12548      2014-01-07 21:59:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 22:00:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 22:00:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-01-07 22:18:28                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1da9d      ,   .  ,  ,  .        .  
      Audit Success   103        2014-01-07 22:18:29                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-07 22:21:18                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-07 22:21:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-07 22:21:18                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xaf6b  
      Audit Success   12544      2014-01-07 22:21:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 22:21:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 22:21:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 22:21:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 22:21:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 22:21:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 22:21:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 22:21:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 22:21:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 22:21:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-07 22:21:23                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-07 22:21:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 22:21:23                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-07 22:21:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1ca9b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 22:21:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 22:21:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1ca9b    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-07 22:21:24                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-07 22:22:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x5683b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 22:22:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 22:22:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 22:22:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 22:22:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 22:22:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a0    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 22:22:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2014-01-07 22:22:59                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1ca9b      ,   .  ,  ,  .        .  
      Audit Success   103        2014-01-07 22:23:01                                  Microsoft-Windows-Eventlog      1100:      .  
      Audit Success   12288      2014-01-07 22:27:04                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-07 22:27:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-07 22:27:04                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb038  
      Audit Success   12544      2014-01-07 22:27:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x294    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 22:27:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 22:27:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x294    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 22:27:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x294    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 22:27:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 22:27:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 22:27:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x294    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 22:27:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x294    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 22:27:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 22:27:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 22:27:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x294    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 22:27:08                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x29c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-07 22:27:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1cbe0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x29c    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 22:27:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-07 22:27:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1cbe0    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-07 22:27:09                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2014-01-07 22:27:10                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-07 22:27:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x508e2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-07 22:28:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x294    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 22:28:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 22:28:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x294    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 22:28:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 22:28:34                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-0-0     :  -     :  -    :  0xacd5   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  .   GUID :  {00000000-0000-0000-0000-000000000000}     :     : -    : -      :    :  0x3a8    :  C:\Windows\System32\svchost.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-07 22:30:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x294    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 22:30:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 23:11:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x294    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 23:11:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Failure   12290      2014-01-07 23:13:42                                  Microsoft-Windows-Security-Auditing  5038:     ,     .         ,          .     : \Device\HarddiskVolume3\\MSI Afterburner\RTCore32.sys   
      Audit Success   12544      2014-01-07 23:14:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x294    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 23:14:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 23:14:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x294    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 23:14:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2014-01-07 23:15:23                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x128c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x26c1c9  
      Audit Success   13568      2014-01-07 23:15:23                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  -$     :  WORKGROUP      :  0x3e7    :    : 0x128c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x26c1c9  
      Audit Success   12544      2014-01-07 23:15:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x294    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 23:15:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 23:15:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x294    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 23:15:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-07 23:47:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x294    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-07 23:47:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Failure   12290      2014-01-07 23:47:44                                  Microsoft-Windows-Security-Auditing  5038:     ,     .         ,          .     : \Device\HarddiskVolume2\Windows\System32\drivers\PnkBstrK.sys   
      Audit Success   12288      2014-01-08 00:00:11                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2014-01-08 00:00:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2014-01-08 00:00:11                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xbe0f  
      Audit Success   12544      2014-01-08 00:00:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-08 00:00:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-08 00:00:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-08 00:00:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-08 00:00:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-08 00:00:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-08 00:00:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-08 00:00:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-08 00:00:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2014-01-08 00:00:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2014-01-08 00:00:14                                  Microsoft-Windows-Eventlog      1101:     .  0  
      Audit Success   12544      2014-01-08 00:00:14                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  -   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-08 00:00:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1d815   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : -     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-08 00:00:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-839303928-1106944401-891866635-500     :       :  -    :  0x1d815    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-08 00:00:16                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2014-01-08 00:00:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-08 00:00:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2014-01-08 00:00:17                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2014-01-08 00:01:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x5eb66   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2014-01-08 00:01:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-08 00:01:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-08 00:02:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-08 00:02:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-08 00:02:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-08 00:02:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-08 00:02:19                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-0-0     :  -     :  -    :  0xb974   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  .   GUID :  {00000000-0000-0000-0000-000000000000}     :     : -    : -      :    :  0x3c4    :  C:\Windows\System32\svchost.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-08 00:02:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-08 00:02:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2014-01-08 00:03:16                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-0-0     :  -     :  -    :  0xb974   GUID :  {00000000-0000-0000-0000-000000000000}          :     :       :  .   GUID :  {00000000-0000-0000-0000-000000000000}     :     : -    : -      :    :  0x3c4    :  C:\Windows\System32\svchost.exe      :    : -   :   -      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2014-01-08 00:04:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  -$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2014-01-08 00:04:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
                          2014-01-05 16:06:15                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:08:09                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:09:29                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:10:09                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:10:51                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:11:46                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:12:15                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:12:55                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:13:18                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147944153.  
                          2014-01-05 16:16:46                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:17:22                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:18:11                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:18:42                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:19:11                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:19:55                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:20:26                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:20:54                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:21:22                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:21:51                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:22:20                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:22:50                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:23:21                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:23:50                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:24:18                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:24:47                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:25:16                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:25:45                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:26:14                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:26:43                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:27:12                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:27:41                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:28:09                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:28:39                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:29:07                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:29:36                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:30:05                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:30:34                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:31:01                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:31:30                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:31:58                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:32:30                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:32:58                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:33:27                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:33:57                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:34:26                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:34:55                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:35:23                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:35:52                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:36:20                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:36:48                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:37:16                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:37:44                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:38:11                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:38:41                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:39:08                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:39:36                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:40:04                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:40:32                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:40:59                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:41:27                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:41:55                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:42:23                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:42:51                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:43:19                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:43:46                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:47:34                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:48:01                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:48:42                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:49:17                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:49:46                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:50:14                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:50:41                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:51:09                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:51:37                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:52:11                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:52:51                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:53:19                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:53:52                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:54:33                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:55:03                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:55:44                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:56:12                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:56:51                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:57:20                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:57:52                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:58:19                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:58:51                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:59:21                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 16:59:50                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 17:00:22                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 17:00:50                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 17:01:20                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 17:01:48                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 17:02:20                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 17:02:48                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 17:03:18                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 17:04:08                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 17:04:35                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 17:05:11                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 17:05:41                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                            2014-01-05 17:12:16                                  Service Control Manager         7006:    ScRegSetValueExW  FailureActions -    %%5  
                          2014-01-05 17:33:18                           Microsoft-Windows-Kernel-Tm     4: The TransactionManager (TmId={D413FC07-760B-11E3-A93E-90E6BAC09CC4}, LogPath=\Device\HarddiskVolume2\Windows\System32\config\components{d413fc05-760b-11e3-a93e-90e6bac09cc4}.TM) has failed to advance its log tail, due to the transaction (UOW={D413FC88-760B-11E3-A93E-90E6BAC09CC4}, Description='') being unresolved for some time.  The transaction must be forced to resolve in order for the TransactionManager to continue to provide transactional services.  Forcing the incorrect outcome may cause data corruption in any subordinate ResourceManagers or Transactionmanagers.  
                          2014-01-05 17:33:18                           Microsoft-Windows-Kernel-Tm     4: The TransactionManager (TmId={B648F810-760B-11E3-84CC-806E6F6E6963}, LogPath=\SystemRoot\System32\Config\TxR\{2874943b-7607-11e3-a230-90e6bac09cc4}.TM) has failed to advance its log tail, due to the transaction (UOW={D413FC88-760B-11E3-A93E-90E6BAC09CC4}, Description='') being unresolved for some time.  The transaction must be forced to resolve in order for the TransactionManager to continue to provide transactional services.  Forcing the incorrect outcome may cause data corruption in any subordinate ResourceManagers or Transactionmanagers.  
                          2014-01-05 18:06:25                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:07:02                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:07:32                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:08:25                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:09:23                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:09:53                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:10:22                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:10:50                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:11:20                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:11:51                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:12:19                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:12:47                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                            2014-01-05 18:13:02                                  Service Control Manager         7006:    ScRegSetValueExW  FailureActions -    %%5  
                          2014-01-05 18:13:16                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:13:44                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:14:13                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:14:43                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:16:57                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:17:25                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:17:58                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:18:28                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:18:58                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                            2014-01-05 18:20:06                                  Service Control Manager         7009:    (30000 )     "Steam Client Service".  
                            2014-01-05 18:20:06                                  Service Control Manager         7000:     "Steam Client Service" -    %%1053  
                          2014-01-05 18:20:33                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:21:02                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                            2014-01-05 18:21:16                                  Disk                            11:     \Device\Harddisk1\DR1.  
                            2014-01-05 18:21:16                                  Disk                            11:     \Device\Harddisk1\DR1.  
                            2014-01-05 18:21:17                                  Disk                            11:     \Device\Harddisk1\DR1.  
                            2014-01-05 18:21:17                                  Disk                            11:     \Device\Harddisk1\DR1.  
                            2014-01-05 18:21:18                                  Disk                            11:     \Device\Harddisk1\DR1.  
                          2014-01-05 18:21:30                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:22:05                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:22:37                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:23:07                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:23:59                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:24:26                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:24:56                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:25:26                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:25:56                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:26:24                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:26:53                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:27:21                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:27:48                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:28:16                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:28:44                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:29:12                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:29:45                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:30:13                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:30:40                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:31:08                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:31:36                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:32:05                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:32:34                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:33:03                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:33:30                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:33:58                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:34:26                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:34:54                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:35:23                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:35:50                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:36:18                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:36:46                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:38:20                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:38:52                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:39:25                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:39:54                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:40:31                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:40:59                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:41:31                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:42:02                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:42:32                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:43:01                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:43:29                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:44:00                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:44:33                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:45:04                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:45:43                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:46:16                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:46:50                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:47:41                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:48:12                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:48:45                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:49:17                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:49:46                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:50:16                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:50:55                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:51:24                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:51:56                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:52:27                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:52:56                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:53:25                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:53:56                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:54:24                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:54:52                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:55:29                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:56:00                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:56:29                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:56:59                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:57:27                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:58:00                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:58:28                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 18:58:57                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 19:00:08                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 19:01:30                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 19:02:02                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 19:02:33                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 19:03:05                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 19:03:34                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 19:04:03                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 19:09:33                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 19:10:01                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 19:10:30                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 19:11:46                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 19:12:15                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 19:16:36                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 19:17:09                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 19:19:09                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 19:19:40                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 21:16:58                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 21:19:24                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 22:21:15                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 22:21:43                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 22:23:44                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 22:24:13                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 22:25:23                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 22:26:54                           Microsoft-Windows-Bits-Client   16393:  BITS       . ,     .  BITS           .  : 2147747073.  
                          2014-01-05 22:50:40  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     www.rusdocs.com        DNS.  
                    1          2014-01-05 23:06:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x8024200d:     Microsoft .NET Framework 3.5.1  32-  Windows 7 (KB2756920).  
                            2014-01-05 23:08:01                                  Disk                            11:     \Device\Harddisk1\DR1.  
                            2014-01-05 23:08:02                                  Disk                            11:     \Device\Harddisk1\DR1.  
                            2014-01-05 23:08:03                                  Disk                            11:     \Device\Harddisk1\DR1.  
                    1          2014-01-05 23:08:43                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x8024200d:   Windows 7 (KB2533552).  
                    1          2014-01-05 23:09:13                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x8024200d:     Windows 7 (KB2511455).  
                    1          2014-01-05 23:22:10                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x8024200d:     Windows 7 (KB2705219).  
                            2014-01-05 23:54:23                                  Disk                            11:     \Device\Harddisk1\DR1.  
                            2014-01-05 23:54:23                                  Disk                            11:     \Device\Harddisk1\DR1.  
                            2014-01-05 23:54:24                                  Disk                            11:     \Device\Harddisk1\DR1.  
                            2014-01-05 23:54:25                                  Disk                            11:     \Device\Harddisk1\DR1.  
                          2014-01-06 00:02:49                                  Disk                            51:     \Device\Harddisk1\DR1      .  
                          2014-01-06 00:02:49                                  Disk                            51:     \Device\Harddisk1\DR1      .  
                          2014-01-06 00:02:49                                  Disk                            51:     \Device\Harddisk1\DR1      .  
                          2014-01-06 00:02:49                                  Disk                            51:     \Device\Harddisk1\DR1      .  
                          2014-01-06 00:02:49                                  Disk                            51:     \Device\Harddisk1\DR1      .  
                          2014-01-06 00:02:49                                  Disk                            51:     \Device\Harddisk1\DR1      .  
                          2014-01-06 00:02:49                                  Disk                            51:     \Device\Harddisk1\DR1      .  
                          2014-01-06 00:02:49                                  Disk                            51:     \Device\Harddisk1\DR1      .  
                          2014-01-06 00:02:49                                  Disk                            51:     \Device\Harddisk1\DR1      .  
                          2014-01-06 00:02:57                                  Disk                            51:     \Device\Harddisk1\DR1      .  
                          2014-01-06 00:02:57                                  Disk                            51:     \Device\Harddisk1\DR1      .  
                          2014-01-06 00:02:57                                  Disk                            51:     \Device\Harddisk1\DR1      .  
                          2014-01-06 00:02:57                                  Disk                            51:     \Device\Harddisk1\DR1      .  
                          2014-01-06 00:02:57                                  Disk                            51:     \Device\Harddisk1\DR1      .  
                          2014-01-06 00:02:57                                  Disk                            51:     \Device\Harddisk1\DR1      .  
                          2014-01-06 00:02:57                                  Disk                            51:     \Device\Harddisk1\DR1      .  
                          2014-01-06 00:02:57                                  Disk                            51:     \Device\Harddisk1\DR1      .  
                          2014-01-06 00:02:57                                  Disk                            51:     \Device\Harddisk1\DR1      .  
                          2014-01-06 00:02:57                                  Disk                            51:     \Device\Harddisk1\DR1      .  
                            2014-01-06 00:07:01                                  Service Control Manager         7023:  " Windows"  -    %%-2147024882  
                    1          2014-01-06 00:11:54                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB979687).  
                    1          2014-01-06 00:11:54                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2753842).  
                    1          2014-01-06 00:11:54                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2840149).  
                    1          2014-01-06 00:11:54                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2536275).  
                    1          2014-01-06 00:11:54                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2503665).  
                    1          2014-01-06 00:11:54                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB975467).  
                    1          2014-01-06 00:11:54                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2807986).  
                    1          2014-01-06 00:11:54                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2347290).  
                    1          2014-01-06 00:11:54                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2644615).  
                    1          2014-01-06 00:11:54                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2808735).  
                    1          2014-01-06 00:11:55                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:   Windows 7 (KB2749655).  
                    1          2014-01-06 00:11:55                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2758857).  
                    1          2014-01-06 00:11:55                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2770660).  
                    1          2014-01-06 00:11:55                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Microsoft .NET Framework 3.5.1  32-  Windows 7 (KB2729451).  
                    1          2014-01-06 00:11:55                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2510531).  
                    1          2014-01-06 00:11:55                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2769369).  
                    1          2014-01-06 00:11:55                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2509553).  
                    1          2014-01-06 00:11:55                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:   Windows 7 (KB2718704).  
                    1          2014-01-06 00:11:55                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2620704).  
                    1          2014-01-06 00:11:55                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2813170).  
                    1          2014-01-06 00:11:55                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:    Microsoft .NET Framework 3.5   Windows 7    x86 (KB982526).  
                    1          2014-01-06 00:11:55                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB982665).  
                    1          2014-01-06 00:11:55                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:   Windows 7 (KB2552343).  
                    1          2014-01-06 00:11:55                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:   Windows 7 (KB977074).  
                    1          2014-01-06 00:11:55                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB982132).  
                    1          2014-01-06 00:11:55                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:      Windows 7 (KB2423089).  
                    1          2014-01-06 00:11:55                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:   Windows 7 (KB2661254).  
                    1          2014-01-06 00:11:55                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2579686).  
                    1          2014-01-06 00:11:55                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:         ActiveX   Windows 7 (KB2618451).  
                    1          2014-01-06 00:11:55                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2685939).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2532531).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2305420).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB974571).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:   Windows 7 (KB980408).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB982799).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB978542).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2655992).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2719985).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2536276).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2564958).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2419640).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2660649).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2813347).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2535512).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Microsoft .NET Framework 3.5.1  32-  Windows 7 (KB2736418).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2757638).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2544893).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:   Windows 7 (KB974431).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2659262).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Microsoft .NET Framework 3.5.1  32-  Windows 7 (KB2656410).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB979482).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2296011).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2387149).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2790655).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:      Windows 7 (KB2378111).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2584146).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Microsoft .NET Framework 3.5.1  32-  Windows 7 (KB2656355).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2698365).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2676562).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2491683).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB972270).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2619339).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB977165).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2621440).  
                    1          2014-01-06 00:11:56                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB975560).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:      Internet Explorer 8  Windows 7 (KB2817183).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2479943).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Microsoft .NET Framework 3.5.1  32-  Windows 7 (KB2742598).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2631813).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2743555).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2570947).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Microsoft .NET Framework 3.5.1  32-  Windows 7 (KB2789644).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2483614).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2653956).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2785220).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2585542).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2560656).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2667402).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2654428).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2690533).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2727528).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:   Windows 7 (KB2345886).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2393802).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2712808).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2281679).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:      Windows 7 (KB2442962).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2658846).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:   Windows 7 (KB2748349).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2506212).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:      Windows 7 (KB979688).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:   Windows 7 (KB971033).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2691442).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:   Windows 7 (KB2779562).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Microsoft .NET Framework 3.5.1  32-  Windows 7 (KB2604114).  
                    1          2014-01-06 00:11:57                           Microsoft-Windows-WindowsUpdateClient  20:  :      -  0x80070643:     Windows 7 (KB2790113).  
                            2014-01-06 02:56:48                                  EventLog                        6008:      2:54:46  ?06.?01.?2014  .  
                            2014-01-06 02:56:49                                  BugCheck                        
                          2014-01-06 02:57:16  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     teredo.ipv6.microsoft.com        DNS.  
                            2014-01-06 02:57:34  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   20:   .    : AMD Northbridge   : 3   : 7   : 0          .  
                            2014-01-06 03:00:54                                  DCOM                            
                          2014-01-06 11:22:13  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     kerio-rus.ru        DNS.  
                            2014-01-06 11:34:21                                  EventLog                        6008:      11:33:01  ?06.?01.?2014  .  
                            2014-01-06 11:34:22                                  BugCheck                        
                            2014-01-06 11:34:49  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   20:   .    : AMD Northbridge   : 3   : 7   : 0          .  
                            2014-01-06 13:32:42                                  EventLog                        6008:      13:08:09  ?06.?01.?2014  .  
                            2014-01-06 13:41:06                           Microsoft-Windows-Application-Experience  205:           .  
                            2014-01-06 14:36:24                                  EventLog                        6008:      14:34:30  ?06.?01.?2014  .  
                            2014-01-06 14:36:25                                  BugCheck                        
                            2014-01-06 14:37:17  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   20:   .    : AMD Northbridge   : 3   : 7   : 0          .  
                            2014-01-06 14:42:44                                  DCOM                            
                            2014-01-06 14:56:08                                  DCOM                            
                            2014-01-06 15:19:26                           Microsoft-Windows-Application-Experience  205:           .  
                            2014-01-06 15:28:17                                  Service Control Manager         7009:    (120000 )     "Adguard Service".  
                            2014-01-06 15:28:17                                  Service Control Manager         7000:     "Adguard Service" -    %%1053  
                            2014-01-06 15:39:21                                  Service Control Manager         7009:    (120000 )     "Adguard Service".  
                            2014-01-06 15:39:21                                  Service Control Manager         7000:     "Adguard Service" -    %%1053  
                            2014-01-06 15:43:22                                  Service Control Manager         7009:    (120000 )     "Adguard Service".  
                            2014-01-06 15:43:22                                  Service Control Manager         7000:     "Adguard Service" -    %%1053  
                            2014-01-06 15:52:18                                  EventLog                        6008:      15:50:03  ?06.?01.?2014  .  
                            2014-01-06 15:52:19                                  BugCheck                        
                            2014-01-06 15:52:58  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   20:   .    : AMD Northbridge   : 3   : 7   : 0          .  
                            2014-01-06 15:53:44                                  DCOM                            
                            2014-01-06 16:36:39                                  Service Control Manager         7001:  "DHCP-"     "Ancillary Function Driver for Winsock",     -    %%31  
                            2014-01-06 16:36:39                                  Service Control Manager         7001:  "DNS-"     "  NetIO Legacy TDI",     -    %%31  
                            2014-01-06 16:36:39                                  Service Control Manager         7001:  "  NetBIOS  TCP/IP"     "Ancillary Function Driver for Winsock",     -    %%31  
                            2014-01-06 16:36:39                                  Service Control Manager         7001:  "   "     "NSI proxy service driver.",     -    %%31  
                            2014-01-06 16:36:39                                  Service Control Manager         7001:  " "     "   ",     -    %%1068  
                            2014-01-06 16:36:39                                  Service Control Manager         7001:  "  IP"     "   ",     -    %%1068  
                            2014-01-06 16:36:39                                  Service Control Manager         7001:  "   - SMB"     "  ",     -    %%31  
                            2014-01-06 16:36:39                                  Service Control Manager         7001:  "- SMB 1.x"     "   - SMB",     -    %%1068  
                            2014-01-06 16:36:39                                  Service Control Manager         7001:  "- SMB 2.0"     "   - SMB",     -    %%1068  
                            2014-01-06 16:36:39                                  Service Control Manager         7001:  "    "     "   ",     -    %%1068  
                            2014-01-06 16:36:39                                  Service Control Manager         7026:    ()    :   adgnetworktdi  AFD  CSC  DfsC  discache  KLIF  KLIM6  klpd  kltdi  kneps  NetBIOS  NetBT  nsiproxy  Psched  rdbss  spldr  tdx  Wanarpv6  WfpLwf  
                            2014-01-06 16:36:47                                  DCOM                            
                            2014-01-06 16:36:53                                  DCOM                            
                            2014-01-06 16:36:54                                  DCOM                            
                            2014-01-06 16:36:54                                  DCOM                            
                            2014-01-06 16:36:54                                  DCOM                            
                            2014-01-06 16:36:54                                  DCOM                            
                            2014-01-06 16:36:54                                  Service Control Manager         7001:  "  "     "    ",     -    %%1068  
                            2014-01-06 16:36:54                                  Service Control Manager         7001:  "  "     "    ",     -    %%1068  
                            2014-01-06 16:37:03                                  Service Control Manager         7001:  "  "     "    ",     -    %%1068  
                            2014-01-06 16:37:03                                  Service Control Manager         7001:  "  "     "    ",     -    %%1068  
                            2014-01-06 16:37:03                                  Service Control Manager         7001:  "  "     "    ",     -    %%1068  
                            2014-01-06 16:37:03                                  Service Control Manager         7001:  "  "     "    ",     -    %%1068  
                            2014-01-06 16:37:03                                  Service Control Manager         7001:  "  "     "    ",     -    %%1068  
                            2014-01-06 16:37:03                                  Service Control Manager         7001:  "  "     "    ",     -    %%1068  
                            2014-01-06 17:16:03                                  cdrom                           11:     \Device\CdRom0.  
                            2014-01-06 17:16:25                                  cdrom                           11:     \Device\CdRom0.  
                            2014-01-06 17:16:26                                  cdrom                           11:     \Device\CdRom0.  
                            2014-01-06 17:16:28                                  cdrom                           15:    \Device\CdRom0  .  
                            2014-01-06 17:16:59                                  cdrom                           15:    \Device\CdRom0  .  
                            2014-01-06 17:16:59                                  cdrom                           15:    \Device\CdRom0  .  
                            2014-01-06 17:17:00                                  cdrom                           15:    \Device\CdRom0  .  
                            2014-01-06 17:17:01                                  cdrom                           15:    \Device\CdRom0  .  
                            2014-01-06 17:17:02                                  atapi                           11:     \Device\Ide\IdePort0.  
                            2014-01-06 17:17:02                                  cdrom                           15:    \Device\CdRom0  .  
                          2014-01-06 17:28:24  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     www.megaupload.com        DNS.  
                            2014-01-07 00:46:29                                  nvlddmkm                        
                            2014-01-07 01:25:18                                  EventLog                        6008:      1:06:34  ?07.?01.?2014  .  
                            2014-01-07 01:26:39                                  Service Control Manager         7034:  "Guard.Mail.ru"  .   (): 1.  
                            2014-01-07 01:54:33                                  Disk                            11:     \Device\Harddisk1\DR1.  
                            2014-01-07 01:54:34                                  Disk                            11:     \Device\Harddisk1\DR1.  
                            2014-01-07 03:11:12                                  EventLog                        6008:      3:10:05  ?07.?01.?2014  .  
                            2014-01-07 03:11:14                                  BugCheck                        
                            2014-01-07 03:11:41  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   20:   .    : AMD Northbridge   : 3   : 7   : 0          .  
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:34                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                          2014-01-07 03:46:35                                  HTTP                            
                            2014-01-07 03:50:56                                  DCOM                            
                            2014-01-07 03:51:31                                  DCOM                            
                            2014-01-07 03:51:51                                  DCOM                            
                            2014-01-07 14:46:45                                  DCOM                            
                          2014-01-07 15:36:25  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     download-driver.info        DNS.  
                            2014-01-07 15:56:59                                  DCOM                            
                            2014-01-07 16:12:09                                  DCOM                            
                            2014-01-07 16:41:39                                  DCOM                            
                            2014-01-07 17:13:13                                  DCOM                            
                            2014-01-07 17:13:50                                  DCOM                            
                            2014-01-07 17:15:23                                  Disk                            11:     \Device\Harddisk1\DR6.  
                            2014-01-07 17:15:24                                  Disk                            11:     \Device\Harddisk1\DR6.  
                            2014-01-07 17:15:24                                  Disk                            11:     \Device\Harddisk1\DR6.  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                          2014-01-07 17:15:26                                  Disk                            51:     \Device\Harddisk1\DR6      .  
                  2          2014-01-07 17:15:26                                  Ntfs                            57:       .   .  
                            2014-01-07 17:19:18                                  EventLog                        6008:      17:17:33  ?07.?01.?2014  .  
                            2014-01-07 17:19:19                                  BugCheck                        
                            2014-01-07 17:20:19  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   20:   .    : AMD Northbridge   : 3   : 7   : 0          .  
                            2014-01-07 17:20:32                                  DCOM                            
                            2014-01-07 17:21:10                                  DCOM                            
                            2014-01-07 17:43:54                                  EventLog                        6008:      17:42:08  ?07.?01.?2014  .  
                            2014-01-07 17:43:55                                  BugCheck                        
                            2014-01-07 17:44:27  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   20:   .    : AMD Northbridge   : 3   : 7   : 0          .  
                            2014-01-07 17:44:43                                  DCOM                            
                            2014-01-07 17:45:21                                  DCOM                            
                            2014-01-07 18:03:16                                  Service Control Manager         7034:  "Guard.Mail.ru"  .   (): 1.  
                          2014-01-07 18:18:39  NETWORK SERVICE                 Microsoft-Windows-DNS-Client    1014:     www.megaupload.com        DNS.  
                            2014-01-07 21:40:24                                  DCOM                            
                            2014-01-07 21:41:02                                  DCOM                            
                  2          2014-01-07 21:48:21                                  Ntfs                            57:       .   .  
                            2014-01-07 21:57:02                                  EventLog                        6008:      21:53:14  ?07.?01.?2014  .  
                            2014-01-07 21:59:06                                  DCOM                            
                            2014-01-07 21:59:45                                  DCOM                            
                            2014-01-07 22:28:34                                  DCOM                            
                            2014-01-07 22:29:12                                  DCOM                            
                            2014-01-08 00:00:12                                  EventLog                        6008:      23:58:58  ?07.?01.?2014  .  
                            2014-01-08 00:00:13                                  BugCheck                        
                            2014-01-08 00:02:06  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   20:   .    : AMD Northbridge   : 3   : 7   : 0          .  
                            2014-01-08 00:02:19                                  DCOM                            
                            2014-01-08 00:02:58                                  DCOM                            
                            2014-01-08 00:03:16                                  DCOM                            


--------[   ]-------------------------------------------------------------------------------------------------------

      :
      Borland Database Engine                           -
      Borland InterBase Client                          -
      Easysoft ODBC-InterBase 6                         -
      Easysoft ODBC-InterBase 7                         -
      Firebird Client                                   -
      Jet Engine                                        4.00.9756.0
      MDAC                                              6.1.7600.16385 (win7_rtm.090713-1255)
      ODBC                                              6.1.7600.16688 (win7_gdr.101015-1505)
      MySQL Connector/ODBC                              -
      Oracle Client                                     -
      PsqlODBC                                          -
      Sybase ASE ODBC                                   -

     :
      Borland InterBase Server                          -
      Firebird Server                                   -
      Microsoft SQL Server                              -
      Microsoft SQL Server Compact Edition              -
      Microsoft SQL Server Express Edition              -
      MySQL Server                                      -
      Oracle Server                                     -
      PostgreSQL Server                                 -
      Sybase SQL Server                                 -


--------[  ODBC ]-----------------------------------------------------------------------------------------------

    Driver da Microsoft para arquivos texto (*.txt; *.csv)      odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.,*.asc,*.csv,*.tab,*.txt,*.csv
    Driver do Microsoft Access (*.mdb)                          odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.mdb
    Driver do Microsoft dBase (*.dbf)                           odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.dbf,*.ndx,*.mdx
    Driver do Microsoft Excel(*.xls)                            odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.xls
    Driver do Microsoft Paradox (*.db )                         odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.db
    Driver para o Microsoft Visual FoxPro                       vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft Access dBASE Driver (*.dbf, *.ndx, *.mdx)         aceodbc.dll         12.0.4518.1014        *.dbf, *.ndx, *.mdx
    Microsoft Access Driver (*.mdb)                             odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.mdb
    Microsoft Access Driver (*.mdb, *.accdb)                    aceodbc.dll         12.0.4518.1014        *.mdb,*.accdb
    Microsoft Access Paradox Driver (*.db)                      aceodbc.dll         12.0.4518.1014        *.mdb,*.accdb
    Microsoft Access Text Driver (*.txt, *.csv)                 aceodbc.dll         12.0.4518.1014        *.txt, *.csv
    Microsoft Access-Treiber (*.mdb)                            odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.mdb
    Microsoft dBase Driver (*.dbf)                              odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.dbf,*.ndx,*.mdx
    Microsoft dBase VFP Driver (*.dbf)                          vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft dBase-Treiber (*.dbf)                             odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.dbf,*.ndx,*.mdx
    Microsoft Excel Driver (*.xls)                              odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.xls
    Microsoft Excel Driver (*.xls, *.xlsx, *.xlsm, *.xlsb)      aceodbc.dll         12.0.4518.1014        *.xls,*.xlsx, *.xlsb
    Microsoft Excel-Treiber (*.xls)                             odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.xls
    Microsoft FoxPro VFP Driver (*.dbf)                         vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft ODBC for Oracle                                   msorcl32.dll        6.1.7600.16385 (win7_rtm.090713-1255)  
    Microsoft Paradox Driver (*.db )                            odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.db
    Microsoft Paradox-Treiber (*.db )                           odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.db
    Microsoft Text Driver (*.txt; *.csv)                        odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.,*.asc,*.csv,*.tab,*.txt,*.csv
    Microsoft Text-Treiber (*.txt; *.csv)                       odbcjt32.dll        6.1.7600.16833 (win7_gdr.110614-1931)  *.,*.asc,*.csv,*.tab,*.txt,*.csv
    Microsoft Visual FoxPro Driver                              vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft Visual FoxPro-Treiber                             vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    SQL Server                                                  sqlsrv32.dll        6.1.7600.16385 (win7_rtm.090713-1255)  


--------[   ODBC ]---------------------------------------------------------------------------------------

    dBASE Files                   Microsoft Access dBASE Driver (*.dbf, *.ndx, *.mdx)           aceodbc.dll
    Excel Files                   Microsoft Excel Driver (*.xls, *.xlsx, *.xlsm, *.xlsb)        aceodbc.dll
    MS Access Database            Microsoft Access Driver (*.mdb, *.accdb)                      aceodbc.dll


--------[    ]--------------------------------------------------------------------------------------------

    Core i7-2600            3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1            16259 /
    Core i7-990X Extreme    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1            14024 /
    Core i7-965 Extreme     3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1            13979 /
    Xeon X5550              2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1            12883 /
    Xeon X3430              2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1            11601 /
    Core i5-650             3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1             9469 /
    Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1             8842 /
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1             8057 /
    Pentium EE 955          3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                 8030 /
    Phenom II X6 1055T      2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1             7956 /
    P4EE                    3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                 7931 /
    Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2             7615 /
    Athlon II X3 425        2700   Asus M4A78                                                              AMD770                Unganged Dual DDR2-800  5-5-5-18 CR2             7296 /
    Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2             7186 /
    Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2             7066 /
    Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                 6739 /
    Athlon64 X2 4000+       2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2             6310 /
    Pentium D 820           2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2             6206 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2             6002 /
    Core 2 Duo P8400        2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                 5802 /
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                 5383 /
    Opteron 2210 HE         1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1             5332 /
    Opteron 2431            2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1             5124 /
    Opteron 2378            2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1             5107 /
    Phenom X4 9500          2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2             5027 /
    Core 2 Duo T5600        1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15                 4601 /
    Xeon                    3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                4587 /
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2              4354 /
    Core Duo T2500          2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15                 4099 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                 4006 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1              3936 /
    Opteron 240             1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1              3922 /
    E-350                   1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1             3781 /
    Xeon                    3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2.5-3-3-7                3776 /
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12                 3723 /
    Atom 230                1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                 3625 /
    Xeon E5462              2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                 3542 /
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2             3504 /
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                        3431 /
    Opteron 2344 HE         1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1             3342 /
    Xeon 5140               2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                 3264 /
    Xeon L5320              1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                 3155 /
    AthlonXP 3200+          2200   Asus A7N8X-E                                                            nForce2-U400          Dual DDR400           2.5-4-4-8 CR1             2990 /
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8                2982 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2             2907 /
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1              2761 /
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                        2748 /
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12                 2695 /
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7                2436 /
    Duron                   1600   MSI KT6V-LSR                                                            KT600                 DDR400 SDRAM          3-3-3-8 CR2              2001 /
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                                   1542 /
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-2-2-6                  1307 /
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5                  1135 /
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2             1090 /
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6                  1049 /
    PIII-E                   733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6                  1046 /
    PIII-S                  1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2              1043 /
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6                   954 /
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                                    904 /
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6                   768 /
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2               689 /
    PIII                     500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?                   621 /
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6                   605 /
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                         524 /
    PII                      333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?                   372 /
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5                   361 /
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5                   262 /
    PentiumPro               200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                         258 /
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4                   228 /
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6                   221 /
    PentiumMMX               200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                         205 /
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6                   168 /
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6                   118 /


--------[    ]---------------------------------------------------------------------------------------------

    Core i7-2600            3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1            18587 /
    Core i7-990X Extreme    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1            12545 /
    Core i7-965 Extreme     3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1            12050 /
    Core i5-650             3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1             9927 /
    Xeon X3430              2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1             9468 /
    Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1             8837 /
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1             7535 /
    Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2             7086 /
    Phenom II X6 1055T      2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1             6765 /
    Xeon E5462              2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                 6756 /
    Athlon II X3 425        2700   Asus M4A78                                                              AMD770                Unganged Dual DDR2-800  5-5-5-18 CR2             6453 /
    Xeon X5550              2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1             6368 /
    Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2             5947 /
    Athlon64 X2 4000+       2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2             5654 /
    Pentium EE 955          3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                 5635 /
    P4EE                    3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                 5618 /
    Core 2 Duo P8400        2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                 5488 /
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2              5383 /
    Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2             4870 /
    Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                 4853 /
    Opteron 2210 HE         1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1             4481 /
    Pentium D 820           2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2             4252 /
    Xeon                    3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                4196 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2             4108 /
    Opteron 2378            2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1             3957 /
    Phenom X4 9500          2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2             3864 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1              3819 /
    Opteron 2431            2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1             3785 /
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                 3637 /
    Core Duo T2500          2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15                 3444 /
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2             3162 /
    AthlonXP 3200+          2200   Asus A7N8X-E                                                            nForce2-U400          Dual DDR400           2.5-4-4-8 CR1             3124 /
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8                3112 /
    Core 2 Duo T5600        1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15                 3004 /
    Opteron 2344 HE         1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1             2954 /
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                        2837 /
    Xeon                    3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2.5-3-3-7                2835 /
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12                 2834 /
    Atom 230                1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                 2832 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                 2786 /
    Xeon 5140               2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                 2503 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2             2373 /
    Xeon L5320              1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                 2330 /
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1              2148 /
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                        2132 /
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7                2127 /
    Opteron 240             1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1              2019 /
    Duron                   1600   MSI KT6V-LSR                                                            KT600                 DDR400 SDRAM          3-3-3-8 CR2              1959 /
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12                 1877 /
    E-350                   1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1             1669 /
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2             1590 /
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-2-2-6                  1336 /
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5                  1204 /
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2              1057 /
    PIII-S                  1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2              1055 /
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6                  1044 /
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6                  1037 /
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6                   953 /
    PIII-E                   733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6                   848 /
    PIII                     500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?                   781 /
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                         761 /
    PentiumMMX               200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                         691 /
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4                   660 /
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6                   588 /
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                                    550 /
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6                   501 /
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                                    356 /
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6                   253 /
    PII                      333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?                   177 /
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6                   171 /
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5                   139 /
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5                   127 /
    PentiumPro               200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                          87 /


--------[    ]----------------------------------------------------------------------------------------

    Core i7-2600            3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1            18154 /
    Core i7-965 Extreme     3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1            14399 /
    Core i7-990X Extreme    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1            13240 /
    Xeon X3430              2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1            11869 /
    Phenom II X6 1055T      2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1            10607 /
    Core i5-650             3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1            10283 /
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1             9843 /
    Xeon X5550              2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1             9648 /
    Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2             8464 /
    Athlon II X3 425        2700   Asus M4A78                                                              AMD770                Unganged Dual DDR2-800  5-5-5-18 CR2             8397 /
    Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1             7263 /
    Opteron 2378            2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1             7005 /
    Opteron 2431            2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1             6839 /
    Athlon64 X2 4000+       2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2             6768 /
    Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2             6379 /
    Pentium EE 955          3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                 6157 /
    P4EE                    3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                 6103 /
    Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2             5521 /
    Xeon E5462              2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                 5469 /
    Phenom X4 9500          2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2             5360 /
    Core 2 Duo P8400        2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                 5088 /
    Pentium D 820           2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2             4810 /
    Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                 4638 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2             4637 /
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                 4239 /
    Xeon                    3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                4131 /
    Opteron 2344 HE         1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1             4033 /
    Opteron 2210 HE         1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1             3944 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1              3712 /
    Core 2 Duo T5600        1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15                 3161 /
    Core Duo T2500          2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15                 3154 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                 3147 /
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2              3097 /
    Xeon                    3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2.5-3-3-7                3060 /
    Xeon 5140               2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                 2986 /
    AthlonXP 3200+          2200   Asus A7N8X-E                                                            nForce2-U400          Dual DDR400           2.5-4-4-8 CR1             2986 /
    Xeon L5320              1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                 2908 /
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2             2847 /
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8                2625 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2             2609 /
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12                 2586 /
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                        2531 /
    E-350                   1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1             2450 /
    Atom 230                1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                 2426 /
    Opteron 240             1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1              2335 /
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                        2218 /
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1              2023 /
    Duron                   1600   MSI KT6V-LSR                                                            KT600                 DDR400 SDRAM          3-3-3-8 CR2              1969 /
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12                 1955 /
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7                1668 /
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2             1294 /
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-2-2-6                  1259 /
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5                  1183 /
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6                   952 /
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6                   877 /
    PIII-E                   733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6                   864 /
    PIII-S                  1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2               799 /
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2               784 /
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                                    629 /
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6                   557 /
    PIII                     500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?                   529 /
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                         503 /
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                                    495 /
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6                   309 /
    PII                      333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?                   243 /
    PentiumMMX               200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                         188 /
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4                   182 /
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5                   166 /
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5                   134 /
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6                   131 /
    PentiumPro               200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                         109 /
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6                    83 /
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6                    82 /


--------[   ]---------------------------------------------------------------------------------------------

    Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1       47.5 ns
    Core i7-2600            3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1       52.7 ns
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2       55.5 ns
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1       55.8 ns
    Phenom II X6 1055T      2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1       56.7 ns
    Xeon X3430              2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1       57.2 ns
    Athlon II X3 425        2700   Asus M4A78                                                              AMD770                Unganged Dual DDR2-800  5-5-5-18 CR2       58.3 ns
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2       59.8 ns
    Core i7-965 Extreme     3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1       59.9 ns
    Core i7-990X Extreme    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1       60.5 ns
    Athlon64 X2 4000+       2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2       61.7 ns
    Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2       61.8 ns
    Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2       67.9 ns
    Xeon X5550              2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1       69.0 ns
    Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15           71.5 ns
    Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2       74.5 ns
    Core i5-650             3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1       79.5 ns
    Pentium EE 955          3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11           80.2 ns
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1        80.7 ns
    Opteron 2210 HE         1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1       83.2 ns
    P4EE                    3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15           85.4 ns
    E-350                   1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1       85.9 ns
    Core 2 Duo P8400        2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15           86.1 ns
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15           87.2 ns
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12           89.8 ns
    Opteron 2378            2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1       94.5 ns
    AthlonXP 3200+          2200   Asus A7N8X-E                                                            nForce2-U400          Dual DDR400           2.5-4-4-8 CR1       95.6 ns
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7          96.2 ns
    Core Duo T2500          2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15           98.4 ns
    Pentium D 820           2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2      101.4 ns
    Atom 230                1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12          101.8 ns
    Opteron 240             1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1       104.6 ns
    Opteron 2431            2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1      106.0 ns
    PIII-S                  1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2       108.3 ns
    Xeon 5140               2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15          108.5 ns
    Xeon E5462              2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15          110.5 ns
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                            111.6 ns
    Xeon                    3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2.5-3-3-7         112.6 ns
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8         112.8 ns
    Phenom X4 9500          2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2      113.2 ns
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2      113.3 ns
    Core 2 Duo T5600        1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15          113.4 ns
    PIII-E                   733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6           117.8 ns
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2       124.8 ns
    Xeon L5320              1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12          126.1 ns
    Duron                   1600   MSI KT6V-LSR                                                            KT600                 DDR400 SDRAM          3-3-3-8 CR2       137.0 ns
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5           139.1 ns
    Xeon                    3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7         145.1 ns
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2      146.6 ns
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                 147.8 ns
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11          147.9 ns
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2       156.4 ns
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6           159.5 ns
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6           159.6 ns
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                            160.2 ns
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1       161.4 ns
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6           162.3 ns
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                 163.1 ns
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12          165.6 ns
    PIII                     500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?           166.3 ns
    PentiumMMX               200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                 167.7 ns
    Opteron 2344 HE         1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1      169.4 ns
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6           170.8 ns
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-2-2-6           175.9 ns
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5           183.3 ns
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6           206.5 ns
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                 215.6 ns
    PentiumPro               200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                 233.9 ns
    PII                      333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?           248.5 ns
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4           256.3 ns
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6           275.8 ns
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6           281.4 ns
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5           317.1 ns


--------[ CPU Queen ]---------------------------------------------------------------------------------------------------

    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1         57876
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1         57280
    4x Core i7-2600 HT      3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1         43507
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1         42686
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15             41391
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1         39033
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1         30925
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12             27842
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1         27340
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2         25303
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15             22690
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1         22038
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2         21998
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1         21356
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1         21087
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15             19830
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2         16148
    3x Athlon II X3 425     2700   Asus M4A78                                                              AMD770                Unganged Dual DDR2-800  5-5-5-18 CR2         13951
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2         12562
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1         12438
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1         11131
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15              9572
    2x Core Duo T2500       2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15              7783
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15              7754
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11              7731
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7             7515
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2          7256
    2x Xeon                 3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2.5-3-3-7             6131
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1          4999
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1          4974
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1           4846
    2x PIII-S               1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2           4845
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2          4219
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15              4140
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1           3833
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12              3761
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2           3518
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2          3483
    AthlonXP 3200+          2200   Asus A7N8X-E                                                            nForce2-U400          Dual DDR400           2.5-4-4-8 CR1          3464
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15              3420
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12              3116
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8             2813
    2x PIII-E                733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6               2802
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2          2796
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12              2601
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2          2572
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7             2538
    Duron                   1600   MSI KT6V-LSR                                                            KT600                 DDR400 SDRAM          3-3-3-8 CR2           2526
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                     2428
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-2-2-6               2223
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6               2202
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1           2050
    2x PIII                  500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?               1922
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11              1905
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6               1716
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                     1616
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2          1558
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                                1442
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6               1342
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6               1187
    2x PII                   333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?               1142
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2           1096
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5                950
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                                 892
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                      870
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5                811
    2x PentiumMMX            200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                      663
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6                574
    2x PentiumPro            200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                      533
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5                457
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4                232
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6                202
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6                184


--------[ CPU PhotoWorxx ]----------------------------------------------------------------------------------------------

    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1                 52262
    4x Core i7-2600 HT      3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1                 47150
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1                 47004
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1                 42167
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1                 39130
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1                 29591
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1                 28246
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                     25835
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1                 23596
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1                 20435
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2                 19421
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2                 18238
    3x Athlon II X3 425     2700   Asus M4A78                                                              AMD770                Unganged Dual DDR2-800  5-5-5-18 CR2                 16274
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2                 14200
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                     11516
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                      9600
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1                  9239
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                      8843
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1                  8328
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                      7972
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1                  7546
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1                  7329
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2                  7159
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2                  6483
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                      6473
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15                      5315
    2x Core Duo T2500       2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15                      5303
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1                   5148
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                      5066
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                      4467
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2                  4455
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1                  4267
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                     4201
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2                  4112
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1                   3677
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2                  3119
    2x Xeon                 3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2.5-3-3-7                     3075
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12                      3009
    AthlonXP 3200+          2200   Asus A7N8X-E                                                            nForce2-U400          Dual DDR400           2.5-4-4-8 CR1                  2853
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2                   2498
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                      2406
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                      2372
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12                      2306
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2                  2078
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8                     2028
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                             1943
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7                     1934
    Duron                   1600   MSI KT6V-LSR                                                            KT600                 DDR400 SDRAM          3-3-3-8 CR2                   1901
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1                   1653
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                             1443
    2x PIII-S               1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2                   1340
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2                  1302
    2x PIII-E                733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6                       1192
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                                        1160
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6                       1096
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6                        991
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-2-2-6                        886
    2x PIII                  500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?                        884
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5                        715
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2                    699
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6                        629
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                                         587
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                              582
    2x PII                   333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?                        559
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5                        371
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6                        365
    2x PentiumPro            200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                              346
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5                        321
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6                        282
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6                        201
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4                        161
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6                        153
    2x PentiumMMX            200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                              149


--------[ CPU ZLib ]----------------------------------------------------------------------------------------------------

    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1            341.3 /
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1            331.4 /
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1            323.2 /
    4x Core i7-2600 HT      3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1            262.3 /
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                252.7 /
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1            220.6 /
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1            215.5 /
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1            194.6 /
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                171.1 /
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1            156.5 /
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2            138.1 /
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2            137.8 /
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                123.8 /
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                107.1 /
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1            102.1 /
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1             99.1 /
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2             93.5 /
    3x Athlon II X3 425     2700   Asus M4A78                                                              AMD770                Unganged Dual DDR2-800  5-5-5-18 CR2             92.2 /
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1             75.8 /
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2             68.3 /
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1             67.4 /
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                 60.8 /
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                59.3 /
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                 51.7 /
    2x Xeon                 3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2.5-3-3-7                48.1 /
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2             43.2 /
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15                 42.0 /
    2x Core Duo T2500       2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15                 41.4 /
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2             40.2 /
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                 32.7 /
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1             31.5 /
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1             29.7 /
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1              28.7 /
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2              27.0 /
    2x PIII-S               1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2              26.5 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1              22.6 /
    AthlonXP 3200+          2200   Asus A7N8X-E                                                            nForce2-U400          Dual DDR400           2.5-4-4-8 CR1             22.6 /
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8                21.8 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2             21.1 /
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                 18.6 /
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                        18.6 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                 17.1 /
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12                 16.8 /
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                 16.3 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2             15.2 /
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2             14.3 /
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6                  14.0 /
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-2-2-6                  13.9 /
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7                13.8 /
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12                 13.8 /
    2x PIII-E                733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6                  13.5 /
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                        11.8 /
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1              11.7 /
    Duron                   1600   MSI KT6V-LSR                                                            KT600                 DDR400 SDRAM          3-3-3-8 CR2              10.6 /
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                                    9.6 /
    2x PIII                  500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?                   9.1 /
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6                   8.8 /
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                                    8.5 /
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2              7.2 /
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6                   7.0 /
    2x PII                   333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?                   5.9 /
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5                   4.8 /
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2               4.5 /
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                         4.2 /
    2x PentiumPro            200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                         3.7 /
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5                   3.6 /
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6                   2.9 /
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6                   2.7 /
    2x PentiumMMX            200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                         2.1 /
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5                   1.6 /
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6                   1.0 /
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4                   0.9 /
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6                   0.9 /


--------[ CPU AES ]-----------------------------------------------------------------------------------------------------

    4x Core i7-2600 HT      3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1        362187
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1        351060
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1        196628
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1         48989
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1         42620
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2         41730
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15             41684
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1         32865
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1         30518
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12             27754
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1         26668
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1         22801
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2         22440
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2         21646
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15             19876
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1         19453
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15             17316
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2         16425
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2         14796
    3x Athlon II X3 425     2700   Asus M4A78                                                              AMD770                Unganged Dual DDR2-800  5-5-5-18 CR2         14604
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2         10980
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1          9366
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11              8973
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7             8735
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15              8438
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1          8331
    2x Core Duo T2500       2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15              7117
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15              6773
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2           6700
    2x Xeon                 3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2.5-3-3-7             6375
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2          5447
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1          4900
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15              4813
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2          4704
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1          4608
    2x PIII-S               1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2           4007
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1           3606
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2           3583
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15              2991
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8             2908
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12              2850
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1           2847
    AthlonXP 3200+          2200   Asus A7N8X-E                                                            nForce2-U400          Dual DDR400           2.5-4-4-8 CR1          2795
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2          2602
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12              2371
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7             2295
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                     2269
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11              2113
    2x PIII-E                733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6               2110
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2          2090
    Duron                   1600   MSI KT6V-LSR                                                            KT600                 DDR400 SDRAM          3-3-3-8 CR2           2031
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1           1912
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12              1840
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6               1775
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                                1755
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6               1578
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-2-2-6               1539
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                     1477
    2x PIII                  500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?               1468
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                                1315
    2x PII                   333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?                983
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6                910
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6                858
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5                724
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                      684
    2x PentiumPro            200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                      596
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5                429
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5                400
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6                397
    2x PentiumMMX            200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                      314
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6                169
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6                137
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4                107


--------[ CPU Hash ]----------------------------------------------------------------------------------------------------

    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1             4811 /
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                 3584 /
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1             3235 /
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1             3207 /
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1             3197 /
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1             2816 /
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                 2336 /
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1             2261 /
    4x Core i7-2600 HT      3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1             2175 /
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1             2007 /
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2             2003 /
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2             1925 /
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1             1686 /
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                 1672 /
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                 1458 /
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2             1455 /
    3x Athlon II X3 425     2700   Asus M4A78                                                              AMD770                Unganged Dual DDR2-800  5-5-5-18 CR2             1346 /
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1             1091 /
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1             1001 /
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1              972 /
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2              920 /
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                  759 /
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                 743 /
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                  725 /
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2              635 /
    2x Xeon                 3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2.5-3-3-7                 619 /
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2              579 /
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15                  570 /
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2              494 /
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1              453 /
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1               424 /
    2x Core Duo T2500       2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15                  414 /
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                  407 /
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2              360 /
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2               347 /
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1               334 /
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1              322 /
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2              304 /
    AthlonXP 3200+          2200   Asus A7N8X-E                                                            nForce2-U400          Dual DDR400           2.5-4-4-8 CR1              284 /
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8                 281 /
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                  262 /
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                  251 /
    2x PIII-S               1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2               247 /
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2              244 /
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                         242 /
    Duron                   1600   MSI KT6V-LSR                                                            KT600                 DDR400 SDRAM          3-3-3-8 CR2               207 /
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1               203 /
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-2-2-6                   181 /
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6                   181 /
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                                    170 /
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12                  167 /
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                  162 /
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6                   160 /
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                         150 /
    2x PIII-E                733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6                   143 /
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12                  138 /
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7                 136 /
    2x PIII                  500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?                    98 /
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6                    97 /
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                                     89 /
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5                    77 /
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6                    68 /
    2x PII                   333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?                    63 /
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2                59 /
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                          44 /
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6                    36 /
    2x PentiumPro            200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                          34 /
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5                    25 /
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5                    24 /
    2x PentiumMMX            200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                          24 /
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6                    11 /
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4                    10 /
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6                     8 /


--------[ FPU VP8 ]-----------------------------------------------------------------------------------------------------

    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1                  3537
    4x Core i7-2600 HT      3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1                  3195
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1                  3096
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1                  2846
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15                      2807
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1                  2649
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1                  2614
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1                  2525
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2                  2128
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2                  1961
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1                  1905
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12                      1710
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1                  1707
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1                  1663
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15                      1638
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2                  1444
    3x Athlon II X3 425     2700   Asus M4A78                                                              AMD770                Unganged Dual DDR2-800  5-5-5-18 CR2                  1424
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15                      1403
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2                  1058
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1                   999
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1                   949
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15                       780
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11                       703
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7                      687
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2                   603
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15                       594
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1                   562
    2x Xeon                 3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2.5-3-3-7                      561
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2                   546
    2x Core Duo T2500       2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15                       542
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15                       463
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2                   463
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1                   413
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15                       407
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1                    388
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2                    386
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11                       381
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2                   377
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1                    353
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8                      325
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2                   295
    AthlonXP 3200+          2200   Asus A7N8X-E                                                            nForce2-U400          Dual DDR400           2.5-4-4-8 CR1                   294
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12                       293
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12                       289
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12                       283
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                              280
    2x PIII-S               1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2                    242
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1                    235
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7                      234
    Duron                   1600   MSI KT6V-LSR                                                            KT600                 DDR400 SDRAM          3-3-3-8 CR2                    205
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                              201
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2                   198
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6                        191
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-2-2-6                        182
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6                        182
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                                         151
    2x PIII-E                733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6                        138
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6                        126
    2x PIII                  500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?                        122
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5                        101
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2                     98
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6                         96
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6                         94
    2x PII                   333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?                         90
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5                         90
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                                          75
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                               73
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5                         72
    2x PentiumMMX            200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                               35
    2x PentiumPro            200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                               26
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6                         21
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6                         19
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4                         13


--------[ FPU Julia ]---------------------------------------------------------------------------------------------------

    4x Core i7-2600 HT      3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1         17434
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1         17010
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1         16819
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1         15622
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15             13546
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1         10516
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1         10414
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1          9142
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12              8887
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1          7408
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2          7280
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1          7075
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2          6508
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15              6370
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15              5555
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1          5324
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2          4770
    3x Athlon II X3 425     2700   Asus M4A78                                                              AMD770                Unganged Dual DDR2-800  5-5-5-18 CR2          4370
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2          3509
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15              2734
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11              2306
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7             2253
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15              2170
    2x Xeon                 3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2.5-3-3-7             2139
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1          2038
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1          1815
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2          1737
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1          1469
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15              1239
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2           1203
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2          1187
    2x Core Duo T2500       2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15              1010
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8              974
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15               955
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1           915
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                      839
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2           795
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11               782
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1            724
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1            703
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1            624
    AthlonXP 3200+          2200   Asus A7N8X-E                                                            nForce2-U400          Dual DDR400           2.5-4-4-8 CR1           607
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6                593
    2x PIII-S               1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2            577
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2           567
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                      560
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12               550
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2           455
    Duron                   1600   MSI KT6V-LSR                                                            KT600                 DDR400 SDRAM          3-3-3-8 CR2            442
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12               403
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6                384
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-2-2-6                382
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12               337
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7              332
    2x PIII-E                733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6                321
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                                 304
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2           231
    2x PIII                  500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?                220
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6                206
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5                165
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6                149
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2            145
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                      100
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5                 86
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6                 80
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                                  61
    2x PII                   333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?                 58
    2x PentiumPro            200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                       35
    2x PentiumMMX            200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                       28
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5                 23
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4                 13
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6                  8
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6                  4


--------[ FPU Mandel ]--------------------------------------------------------------------------------------------------

    4x Core i7-2600 HT      3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1          8853
    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1          8481
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1          8390
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1          8047
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15              7072
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1          5366
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1          5257
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1          4714
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12              4481
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1          3803
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2          3800
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2          3352
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1          3344
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15              3210
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15              2799
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1          2618
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2          2447
    3x Athlon II X3 425     2700   Asus M4A78                                                              AMD770                Unganged Dual DDR2-800  5-5-5-18 CR2          2243
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2          1768
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15              1428
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1          1180
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11              1155
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7             1130
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15              1094
    2x Xeon                 3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2.5-3-3-7             1092
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1          1050
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2           888
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1           757
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2           687
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15               620
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2            613
    2x Core Duo T2500       2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15               505
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8              496
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15               481
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                      427
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1           426
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2           400
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11               400
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1            376
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1            361
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1            358
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2           328
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6                303
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                      285
    AthlonXP 3200+          2200   Asus A7N8X-E                                                            nForce2-U400          Dual DDR400           2.5-4-4-8 CR1           278
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2           263
    Duron                   1600   MSI KT6V-LSR                                                            KT600                 DDR400 SDRAM          3-3-3-8 CR2            203
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12               190
    2x PIII-S               1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2            188
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6                177
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-2-2-6                176
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12               169
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                                 168
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12               158
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7              152
    2x PIII-E                733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6                113
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6                 94
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2            86
    2x PIII                  500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?                 78
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5                 76
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                                  71
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2             63
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6                 54
    2x PII                   333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?                 52
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                       35
    2x PentiumPro            200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                       31
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6                 26
    2x PentiumMMX            200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                       24
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5                 21
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5                 16
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4                 10
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6                  5
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6                  3


--------[ FPU SinJulia ]------------------------------------------------------------------------------------------------

    6x Core i7-990X Extreme HT    3466   Intel DX58SO2                                                           X58                   Triple DDR3-1333      9-9-9-24 CR1          7490
    8x Xeon X5550 HT        2666   Supermicro X8DTN+                                                       i5520                 Triple DDR3-1333      9-9-9-24 CR1          7045
    4x Core i7-2600 HT      3400   Intel DP67BG                                                            P67                   Dual DDR3-1333        9-9-9-24 CR1          4661
    12x Opteron 2431        2400   Supermicro H8DI3+-F                                                     SR5690                Unganged Dual DDR2-800R  6-6-6-18 CR1          4657
    4x Core i7-965 Extreme HT    3200   Asus P6T Deluxe                                                         X58                   Triple DDR3-1333      9-9-9-24 CR1          4635
    8x Xeon E5462           2800   Intel S5400SF                                                           i5400                 Quad DDR2-640FB       5-5-5-15              4135
    8x Opteron 2378         2400   Tyan Thunder n3600R                                                     nForcePro-3600        Unganged Dual DDR2-800R  6-6-6-18 CR1          3104
    6x Phenom II X6 1055T    2800   Gigabyte GA-790FXTA-UD5                                                 AMD790FX              Unganged Dual DDR3-1333  9-9-9-24 CR1          2727
    8x Xeon L5320           1866   Intel S5000VCL                                                          i5000V                Dual DDR2-533FB       4-4-4-12              2594
    2x Core i5-650 HT       3200   Supermicro C7SIM-Q                                                      Q57 Int.              Dual DDR3-1333        9-9-9-24 CR1          2313
    4x Xeon X3430           2400   Supermicro X8SIL-F                                                      i3420                 Dual DDR3-1333        9-9-9-24 CR1          2271
    4x Core 2 Extreme QX9650    3000   Gigabyte GA-EP35C-DS3R                                                  P35                   Dual DDR3-1066        8-8-8-20 CR2          2221
    8x Opteron 2344 HE      1700   Supermicro H8DME-2                                                      nForcePro-3600        Unganged Dual DDR2-667R  5-5-5-15 CR1          2208
    4x Phenom II X4 Black 940    3000   Asus M3N78-EM                                                           GeForce8300 Int.      Ganged Dual DDR2-800  5-5-5-18 CR2          1940
    4x Core 2 Extreme QX6700    2666   Intel D975XBX2                                                          i975X                 Dual DDR2-667         5-5-5-15              1858
    4x Xeon 5140            2333   Intel S5000VSA                                                          i5000V                Dual DDR2-667FB       5-5-5-15              1619
    4x Phenom X4 9500       2200   Asus M3A                                                                AMD770                Ganged Dual DDR2-800  5-5-5-18 CR2          1422
    3x Athlon II X3 425     2700   Asus M4A78                                                              AMD770                Unganged Dual DDR2-800  5-5-5-18 CR2          1303
    4x Opteron 2210 HE      1800   Tyan Thunder h2000M                                                     BCM5785               Dual DDR2-600R        5-5-5-15 CR1          1179
    2x Athlon64 X2 Black 6400+    3200   MSI K9N SLI Platinum                                                    nForce570SLI          Dual DDR2-800         4-4-4-11 CR1          1049
    2x Core 2 Extreme X6800    2933   Abit AB9                                                                P965                  Dual DDR2-800         5-5-5-18 CR2          1023
    2x Pentium EE 955 HT    3466   Intel D955XBK                                                           i955X                 Dual DDR2-667         4-4-4-11               962
    2x Xeon HT              3400   Intel SE7320SP2                                                         iE7320                Dual DDR333R          2.5-3-3-7              942
    2x Core 2 Duo P8400     2266   MSI MegaBook PR201                                                      GM45 Int.             Dual DDR2-667         5-5-5-15               835
    2x Athlon64 X2 4000+    2100   ASRock ALiveNF7G-HDready                                                nForce7050-630a Int.  Dual DDR2-700         5-5-5-18 CR2           686
    2x Core Duo T2500       2000   Asus N4L-VM DH                                                          i945GT Int.           Dual DDR2-667         5-5-5-15               662
    2x Xeon                 3066   Asus PCH-DL                                                             i875P + PAT           Dual DDR333           2.5-3-3-7              658
    2x Core 2 Duo T5600     1833   Asus F3000Jc Notebook                                                   i945PM                Dual DDR2-667         5-5-5-15               634
    P4EE HT                 3733   Intel SE7230NH1LX                                                       iE7230                Dual DDR2-667         5-5-5-15               516
    2x E-350                1600   ASRock E350M1                                                           A50M Int.             DDR3-1066 SDRAM       8-8-8-20 CR1           505
    2x Opteron 240          1400   MSI K8D Master3-133 FS                                                  AMD8100               Dual DDR400R          3-4-4-8 CR1            458
    2x Pentium D 820        2800   Abit Fatal1ty F-I90HD                                                   RS600 Int.            Dual DDR2-800         5-5-5-18 CR2           452
    Sempron 140             2700   Gigabyte GA-890GPA-UD3H v2                                              AMD890GX Int.         Unganged Dual DDR3-1066  8-8-8-20 CR1           438
    2x PIII-S               1266   MSI Pro266TD Master-LR                                                  ApolloPro266TD        DDR266 SDRAM          2-3-3-6 CR2            421
    P4EE                    3466   ASRock 775Dual-880Pro                                                   PT880Pro              Dual DDR2-400         3-3-3-8 CR2            370
    Opteron 248             2200   MSI K8T Master1-FAR                                                     K8T800                Dual DDR266R          2-3-3-6 CR1            361
    AthlonXP 3200+          2200   Asus A7N8X-E                                                            nForce2-U400          Dual DDR400           2.5-4-4-8 CR1           357
    Athlon64 3200+          2000   ASRock 939S56-M                                                         SiS756                Dual DDR400           2.5-3-3-8 CR2           328
    P4                      2800   MSI 848P Neo-S                                                          i848P                 DDR400 SDRAM          2.5-3-3-8              299
    Celeron 420             1600   Intel DQ965CO                                                           Q965 Int.             Dual DDR2-667         5-5-5-15               279
    Pentium M 730           1600   AOpen i915Ga-HFS                                                        i915G Int.            Dual DDR2-533         4-4-4-12               272
    Sempron 2600+           1600   ASRock K8NF4G-SATA2                                                     GeForce6100 Int.      DDR400 SDRAM          2.5-3-3-8 CR2           263
    Duron                   1600   MSI KT6V-LSR                                                            KT600                 DDR400 SDRAM          3-3-3-8 CR2            261
    P4                      2400   Abit SI7                                                                SiSR658               Dual PC1066 RDRAM     -                      258
    2x PIII-E                733   Tyan Thunder 2500                                                       ServerSet3HE          PC133R SDRAM          3-3-3-6                238
    AthlonXP 1600+          1400   Acorp 7KMM1                                                             KM133A Int.           PC133 SDRAM           3-3-3-6                227
    Athlon                  1400   PCChips M817LMR                                                         MAGiK1                DDR266 SDRAM          2-2-2-6                225
    Celeron M 320           1300   DFI 855GME-MGF                                                          i855GME Int.          DDR333 SDRAM          2.5-3-3-7              224
    Celeron 215             1333   Intel D201GLY                                                           SiS662 Int.           DDR2-533              5-4-4-12               221
    Celeron                 2000   Gigabyte GA-8TRS350MT                                                   RS350 Int.            Dual DDR400           2-2-4-6 CR1            216
    Atom 230 HT             1600   Intel D945GCLF                                                          i945GC Int.           DDR2-533 SDRAM        4-4-4-12               206
    Celeron D 326           2533   ASRock 775Twins-HDTV                                                    RC410 Ext.            DDR2-533 SDRAM        4-4-4-11               204
    Celeron                 1700   Asus P4B                                                                i845                  PC133 SDRAM           3-3-3-6                188
    P4                      1600   Abit TH7II                                                              i850                  Dual PC800 RDRAM      -                      169
    2x PIII                  500   Epox KP6-BS                                                             i440BX                PC100R SDRAM          3-3-3-?                163
    Nano L2200              1600   VIA VB8001                                                              CN896 Int.            DDR2-667 SDRAM        5-5-5-15 CR2           128
    Athlon                   750   Epox EP-7KXA                                                            KX133                 PC133 SDRAM           3-3-3-6                121
    Celeron                  700   PCChips M758LT                                                          SiS630ET Int.         PC100 SDRAM           3-3-3-6                114
    2x PII                   333   Intel DK440LX                                                           i440LX                PC66 SDRAM            3-2-2-?                109
    Efficeon 8600           1000   ECS 532 Notebook                                                        Efficeon              DDR266 SDRAM                                 103
    Duron                    600   Abit KG7-Lite                                                           AMD-760               DDR200R SDRAM         2-2-2-5                 96
    PIII                     450   Asus P3C-S                                                              i820                  PC600 RDRAM           -                       74
    Crusoe 5800             1000   ECS A530 DeskNote                                                       Crusoe                DDR266 SDRAM                                  73
    2x PentiumPro            200   Compaq ProLiant 800                                                     i440FX                Dual EDO              -                       65
    2x PentiumMMX            200   Gigabyte GA-586DX                                                       i430HX                Dual EDO              -                       65
    K6-III                   400   Epox EP-MVP3G-M                                                         MVP3                  PC100 SDRAM           2-2-2-5                 51
    C7                      1500   VIA EPIA EN                                                             CN700 Int.            DDR2-533 SDRAM        4-4-4-12 CR2            46
    Celeron                  266   Epox P2-100B                                                            ApolloPro             PC66 SDRAM            3-2-2-5                 43
    C3                      1333   VIA EPIA SP                                                             CN400 Int.            DDR400 SDRAM          3-3-3-8 CR2             35
    Pentium                  166   Asus TX97-X                                                             i430TX                PC66 SDRAM            2-2-3-4                 27
    C3                       800   VIA EPIA                                                                PLE133 Int.           PC133 SDRAM           3-3-3-6                 21
    MediaGXm                 233   ALD NPC6836                                                             Cx5520                PC60 SDRAM            3-3-3-6                 17
    K5 PR166                 116   Asus P5A                                                                ALADDiN5              PC66 SDRAM            2-2-2-6                  6


--------[ Debug - PCI ]-------------------------------------------------------------------------------------------------

    B00 D00 F00:  ATI RX780 Chipset - Host Bridge
                  
      Offset 000:  02 10 57 59  06 00 30 22  00 00 00 06  00 00 00 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 53 83 
      Offset 030:  00 00 00 00  C4 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  08 54 00 C0  C1 00 00 00  02 00 00 00  42 20 05 00 
      Offset 050:  43 10 53 83  08 9C 00 90  08 10 00 00  00 00 00 00 
      Offset 060:  7D 00 00 00  E3 00 00 00  00 02 20 00  61 7F 00 78 
      Offset 070:  00 00 00 00  00 00 00 00  54 A1 0F 00  00 00 00 00 
      Offset 080:  00 00 00 00  10 00 00 03  20 01 30 00  31 20 00 40 
      Offset 090:  00 00 00 D0  7D 00 00 00  00 00 00 00  08 00 3C D0 
      Offset 0A0:  82 00 00 00  00 00 00 80  00 00 00 00  79 40 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 80  08 40 80 01  20 00 11 11  D0 00 00 00 
      Offset 0D0:  60 0B F5 7F  02 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 05 00  FF FF FF FF  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 80 80 00  00 00 00 00  00 00 00 00 

    B00 D02 F00:  ATI RX780 Chipset - PCI Express Graphics 0 Port A
                  
      Offset 000:  02 10 78 59  07 01 10 00  00 00 04 06  10 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 01 01 00  D1 D1 00 20 
      Offset 020:  00 F8 E0 FB  01 D4 F1 DF  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  12 01 1B 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 58 03 C8  00 00 00 00  10 A0 42 00  20 80 00 00 
      Offset 060:  10 08 00 00  02 0D 30 00  40 00 02 71  80 25 14 00 
      Offset 070:  00 00 40 01  00 00 01 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  42 00 01 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 B0 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  0D B8 00 00  43 10 53 83  08 00 03 A8  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  50 00 00 00  40 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D06 F00:  ATI RX780 Chipset - PCI Express Port C
                  
      Offset 000:  02 10 7C 59  07 01 10 40  00 00 04 06  10 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 02 02 00  E1 E1 00 20 
      Offset 020:  F0 FB F0 FB  F1 FF 01 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  12 01 07 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 58 03 C8  00 00 00 00  10 A0 42 00  20 80 00 00 
      Offset 060:  10 08 00 00  12 0C 30 02  40 00 11 70  80 0C 34 00 
      Offset 070:  00 00 40 01  00 00 01 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  01 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 B0 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  0D B8 00 00  43 10 53 83  08 00 03 A8  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  50 00 00 00  02 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D11 F00:  ATI SB700 - SATA Controller
                  
      Offset 000:  02 10 90 43  07 01 30 02  00 8F 01 01  10 40 00 00 
      Offset 010:  01 C0 00 00  01 B0 00 00  01 A0 00 00  01 90 00 00 
      Offset 020:  01 80 00 00  00 FC FF F7  00 00 00 00  43 10 EF 82 
      Offset 030:  00 00 00 00  60 00 00 00  00 00 00 00  16 01 00 00 
      Offset 040:  10 00 00 20  01 00 10 00  00 00 20 01  00 00 00 00 
      Offset 050:  05 70 84 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  01 70 22 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  12 00 10 00  0F 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  06 00 40 2C  F6 A0 B4 01  F6 A0 B4 01 
      Offset 090:  F6 A0 B4 01  BE A0 B4 01  F6 A0 B4 01  F6 A0 B4 01 
      Offset 0A0:  DE 20 BE 20  DE 20 FE A0  BE 20 BE 20  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 20 00 00 
      Offset 0E0:  80 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D12 F00:  ATI SB700 - OHCI USB Controller
                  
      Offset 000:  02 10 97 43  06 01 A0 02  00 10 03 0C  10 40 80 00 
      Offset 010:  00 E0 FF F7  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 EF 82 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  10 01 00 00 
      Offset 040:  80 03 00 00  11 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  40 13 01 F0  00 00 00 00  FF FF FF FF  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  FF 00 00 80  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D12 F01:  ATI SB700 - OHCI USB Controller
                  
      Offset 000:  02 10 98 43  16 01 A0 02  00 10 03 0C  10 40 00 00 
      Offset 010:  00 D0 FF F7  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 EF 82 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  10 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D12 F02:  ATI SB700 - EHCI USB 2.0 Controller
                  
      Offset 000:  02 10 96 43  06 01 B0 02  00 20 03 0C  10 40 00 00 
      Offset 010:  00 F8 FF F7  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 EF 82 
      Offset 030:  00 00 00 00  C0 00 00 00  00 00 00 00  11 02 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  40 00 9E 90  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  20 20 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  01 00 00 00  00 20 00 C0  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  01 E4 02 7E  00 00 40 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  0A 00 E0 20  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D13 F00:  ATI SB700 - OHCI USB Controller
                  
      Offset 000:  02 10 97 43  06 01 A0 02  00 10 03 0C  10 40 80 00 
      Offset 010:  00 C0 FF F7  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 EF 82 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  12 01 00 00 
      Offset 040:  80 03 00 00  11 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  40 13 01 F0  00 00 00 00  FF FF FF FF  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  FF 00 00 80  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D13 F01:  ATI SB700 - OHCI USB Controller
                  
      Offset 000:  02 10 98 43  16 01 A0 02  00 10 03 0C  10 40 00 00 
      Offset 010:  00 B0 FF F7  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 EF 82 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  12 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D13 F02:  ATI SB700 - EHCI USB 2.0 Controller
                  
      Offset 000:  02 10 96 43  06 01 B0 02  00 20 03 0C  10 40 00 00 
      Offset 010:  00 F4 FF F7  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 EF 82 
      Offset 030:  00 00 00 00  C0 00 00 00  00 00 00 00  13 02 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  40 00 9E 90  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  20 20 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  01 00 00 00  00 20 00 C0  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  01 E4 02 7E  00 00 40 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  0A 00 E0 20  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F00:  ATI SB700 - SMBus Controller
                  
      Offset 000:  02 10 85 43  03 04 30 D2  3A 00 05 0C  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 EF 82 
      Offset 030:  00 00 00 00  B0 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  44 EB 00 FC  00 00 00 00  0F FF 00 00  00 00 00 C0 
      Offset 050:  E0 00 F0 0E  F0 0F F0 0F  21 0B F0 0F  00 00 00 00 
      Offset 060:  01 00 24 20  BF FC 9E 03  FF 90 00 00  20 00 00 00 
      Offset 070:  00 00 00 00  08 00 C0 FE  FF 6E 00 00  00 00 F0 0E 
      Offset 080:  F0 0A F0 0F  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  01 0B 00 00  F9 CE FF 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 FF FF  7F FF 70 01  00 FF 08 02  06 79 20 18 
      Offset 0B0:  08 00 02 A8  00 00 D0 FE  00 00 00 00  F0 0F 08 1A 
      Offset 0C0:  FF FF FF FF  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 01 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  20 99 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  D8 0C 00 00  00 00 44 00  00 00 00 00  02 00 30 00 

    B00 D14 F01:  ATI SB700 - IDE Controller
                  
      Offset 000:  02 10 9C 43  05 00 30 02  00 8A 01 01  00 00 00 00 
      Offset 010:  01 00 00 00  01 00 00 00  01 00 00 00  01 00 00 00 
      Offset 020:  01 FF 00 00  00 00 00 00  00 00 00 00  43 10 EF 82 
      Offset 030:  00 00 00 00  70 00 00 00  00 00 00 00  00 01 00 00 
      Offset 040:  99 99 20 99  FF FF FF FF  00 00 00 40  00 00 00 00 
      Offset 050:  00 00 00 00  08 00 00 20  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 40 26  10 2C 01 07  01 00 00 00  FF FF 0F 00 
      Offset 070:  05 00 02 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F02:  ATI SB700 - High Definition Audio Controller
                  
      Offset 000:  02 10 83 43  06 00 10 04  00 00 03 04  10 40 00 00 
      Offset 010:  04 40 FF F7  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 7B 83 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  10 01 00 00 
      Offset 040:  00 00 00 00  01 00 00 00  00 00 00 00  01 00 00 00 
      Offset 050:  01 00 42 C8  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  05 00 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F03:  ATI SB700 - PCI-LPC Bridge
                  
      Offset 000:  02 10 9D 43  0F 00 20 02  00 00 01 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 EF 82 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  04 00 00 00  43 C0 03 FF  17 FF 40 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  30 02 00 00  0D 00 0F 00  B0 FF FF FF 
      Offset 070:  67 45 23 00  00 00 00 00  1C 00 00 00  05 0B 00 00 
      Offset 080:  08 00 03 A8  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 08  00 00 00 00 
      Offset 0A0:  02 00 C1 FE  2F 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 E9  F2 FF 00 00 
      Offset 0C0:  00 00 00 00  00 00 08 00  F7 FF FF FF  00 00 00 78 
      Offset 0D0:  00 FF FF 00  00 00 00 FF  FF FF FF 00  00 00 00 0C 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F04:  ATI SB700 - PCI-PCI Bridge
                  
      Offset 000:  02 10 84 43  07 05 A0 02  00 01 04 06  00 40 81 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 03 03 40  F0 00 80 22 
      Offset 020:  F0 FF 00 00  F0 FF 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 07 00 
      Offset 040:  26 00 3C FF  00 00 00 00  0C 0F 3D D1  00 01 00 00 
      Offset 050:  01 00 00 00  08 00 03 A8  00 00 00 00  85 00 FF FF 
      Offset 060:  CA 0E 17 00  BA D8 10 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  01 00 02 06 
      Offset 0E0:  00 00 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F05:  ATI SB700 - OHCI USB Controller
                  
      Offset 000:  02 10 99 43  06 01 A0 02  00 10 03 0C  10 40 00 00 
      Offset 010:  00 A0 FF F7  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 EF 82 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  12 03 00 00 
      Offset 040:  80 01 00 00  11 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  40 13 1F F0  00 00 00 00  FF FF FF FF  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  FF 00 00 80  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F00:  AMD K10 - HyperTransport Technology Configuration
                  
      Offset 000:  22 10 00 12  00 00 10 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  80 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  01 02 04 00  01 02 04 00  01 02 04 00  01 02 04 00 
      Offset 050:  01 02 04 00  01 02 04 00  01 02 04 00  01 02 04 00 
      Offset 060:  00 00 02 00  E0 00 00 00  20 A8 4F 01  30 F8 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  08 00 01 21  20 20 11 11  60 0B F5 8F  13 00 00 00 
      Offset 090:  D1 01 84 82  00 00 00 00  07 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F01:  AMD K10 - Address Map
                  
      Offset 000:  22 10 01 12  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  03 00 00 00  00 00 2F 01  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  03 00 E0 00  80 FF EF 00  03 00 F0 00  00 FF FF 00 
      Offset 0B0:  03 0A 00 00  00 0B 00 00  03 00 D0 00  00 FF DF 00 
      Offset 0C0:  13 10 00 00  00 F0 FF 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  03 00 00 07  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  03 30 00 D0  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F02:  AMD K10 - DRAM Controller
                  
      Offset 000:  22 10 02 12  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  01 00 00 00  01 01 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  E0 3E 78 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  06 00 88 0E  00 00 00 00 
      Offset 080:  05 00 00 00  00 00 00 00  24 FA 7C 00  34 03 22 00 
      Offset 090:  10 00 01 00  0B 00 58 7F  07 03 00 80  00 00 00 00 
      Offset 0A0:  00 02 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  0C 40 A2 0C  CB 00 00 00  00 90 22 00  17 1A 4B 21 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  11 FC 55 24  F5 F3 50 6E  46 86 FF 82  B5 54 3D 50 
      Offset 0E0:  22 BF FB EF  5B AD 59 C0  F0 00 68 6D  CC 10 98 33 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 100:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 110:  84 05 00 00  00 00 00 00  24 A4 40 04  C0 0F E0 2C 
      Offset 120:  C9 86 18 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 130:  98 BB 06 1A  C1 C7 D9 E0  2E ED 1B F6  73 B1 78 E4 
      Offset 140:  01 00 00 00  01 01 00 00  00 00 00 00  00 00 00 00 
      Offset 150:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 160:  E0 3E 78 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 170:  00 00 00 00  00 00 00 00  06 00 48 0F  00 00 00 00 
      Offset 180:  05 00 00 00  00 00 00 00  24 FA 7D 00  34 03 22 00 
      Offset 190:  10 00 01 00  0B 00 58 7F  07 03 00 80  00 00 00 00 
      Offset 1A0:  00 02 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1B0:  01 01 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F03:  AMD K10 - Miscellaneous Control
                  
      Offset 000:  22 10 03 12  00 00 10 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  F0 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  FF FF FF 3F  5C 00 B0 4A  00 00 00 00  00 00 00 00 
      Offset 050:  20 A0 02 06  10 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  05 70 5F 34  C0 00 00 30  52 80 01 10 
      Offset 070:  54 11 14 10  01 01 18 00  14 0C 20 00  0D 09 09 00 
      Offset 080:  81 E6 00 E6  E6 41 E6 01  08 00 00 00  00 00 58 02 
      Offset 090:  00 00 00 00  84 23 00 00  10 E7 F1 31  00 00 00 00 
      Offset 0A0:  00 08 0E A0  80 18 6C 27  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  26 0F 81 C8  16 16 20 03  22 53 47 01 
      Offset 0E0:  00 00 00 00  30 17 00 1D  59 6F 07 00  00 00 00 00 
      Offset 0F0:  0F 00 10 00  00 00 00 00  00 00 00 00  52 0F 10 00 

    B00 D18 F04:  AMD K10 - Link Control
                  
      Offset 000:  22 10 04 12  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B01 D00 F00:  NVIDIA GeForce GTX 550 Ti [10DE-1244] [NoDB]
                  
      Offset 000:  DE 10 44 12  07 01 10 00  A1 00 00 03  10 00 80 00 
      Offset 010:  00 00 00 F8  0C 00 00 D8  00 00 00 00  0C 00 00 D4 
      Offset 020:  00 00 00 00  01 DC 00 00  00 00 00 00  62 14 9D 80 
      Offset 030:  00 00 00 00  60 00 00 00  00 00 00 00  12 01 00 00 
      Offset 040:  62 14 9D 80  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 00 00 00  01 00 00 00  CE D6 23 00  00 00 00 00 
      Offset 060:  01 68 03 00  08 00 00 00  05 78 80 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  10 B4 02 00  A0 8D 2C 01 
      Offset 080:  00 29 00 00  02 2D 05 00  40 01 02 11  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  10 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  01 00 01 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  09 00 14 01  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B01 D00 F01:   High Definition Audio (Microsoft) [10DE-0BEE] [NoDB]
                  
      Offset 000:  DE 10 EE 0B  06 01 10 00  A1 00 03 04  10 00 80 00 
      Offset 010:  00 C0 E7 FB  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  62 14 9D 80 
      Offset 030:  00 00 00 00  60 00 00 00  00 00 00 00  13 02 00 00 
      Offset 040:  62 14 9D 80  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  CE D6 23 00  00 00 00 00 
      Offset 060:  01 68 03 00  08 00 00 00  05 78 80 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  10 00 02 00  A0 8D 2C 01 
      Offset 080:  00 28 00 00  02 2D 05 00  48 01 02 11  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  10 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 01 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B02 D00 F00:  Realtek RTL8168B/8111B PCI-E Gigabit Ethernet Adapter
                  
      Offset 000:  EC 10 68 81  07 01 10 40  01 00 00 02  10 00 00 00 
      Offset 010:  01 E8 00 00  00 00 00 00  04 F0 FF FB  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 85 83 
      Offset 030:  00 00 00 00  40 00 00 00  00 00 00 00  12 01 00 00 
      Offset 040:  01 48 C2 F7  00 01 00 00  03 50 00 00  00 00 00 00 
      Offset 050:  05 60 82 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  10 84 01 00  60 7E 00 00  00 58 1A 00  11 F4 03 00 
      Offset 070:  40 00 11 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  09 00 4C 01  01 1C 02 00  FB FF FF 11 
      Offset 090:  08 30 00 00  E1 08 06 00  C9 70 03 00  54 0F 00 00 
      Offset 0A0:  02 28 FF 01  00 00 00 00  00 08 00 00  03 00 03 00 
      Offset 0B0:  00 40 00 00  FF 3F FF 3F  FF FF 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    PCI-1002-5957:  ATI ClkConfig
                  
      Offset 00:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 10:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 20:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 30:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 40:  01 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 50:  00 00 00 00  00 00 00 00  00 00 00 00  42 00 00 00 
      Offset 60:  00 00 00 00  DD DD DD DD  9F 10 03 00  80 00 00 00 
      Offset 70:  01 00 00 02  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 80:  00 00 00 00  00 00 00 00  00 00 00 00  3F 7F C4 03 
      Offset 90:  00 00 00 00  97 FF FF 73  40 00 00 00  00 00 00 00 
      Offset A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset B0:  00 00 00 00  00 00 00 00  00 00 00 00  FF FF 10 00 
      Offset C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset D0:  00 00 00 00  6C 7B 00 00  96 00 00 00  00 00 00 00 
      Offset E0:  01 00 4D 07  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset F0:  00 00 00 00  00 00 00 00  FF 0F 00 00  00 00 00 00 


--------[ Debug - Video BIOS ]------------------------------------------------------------------------------------------

    C000:0000  U.l.K7400.L.w.VIDEO ......F...IBM VGA Compatible......pO04/13/12
    C000:0040  ..........@.......*.b....#..P.........(9.Q..C..CPMIDl.o.......
    C000:0080  .....3NVIDIA GeForce GTX 550 Ti VGA BIOS ..MSINV809MS.E00.......
    C000:00C0  .......................Version 70.26.3A.00.01 ...Copyright (C) 1
    C000:0100  996-2011 NVIDIA Corp.........B....GF106B Board - 10500000.......
    C000:0140  .....Chip Rev   ................................................
    C000:0180  ........PCIR..D.........l.......HYB$..BIT......E2...,.B.!.8.C...
    C000:01C0  Y.D...g.A...k.I...n.L.....M.....N.....P.8...S.....T.....U.....V.
    C000:0200  ....x.....d.....p.....i.C.....G.DI.[.b...................:&p....
    C000:0240  ..............\\....0............(J.....M.@....K.K.K.KDM.M.K...M
    C000:0280  ....J.J.g...g...K...b..Pc..Xe...f..Jg.......g..{....f...f..&g..+
    C000:02C0  g...f...f....P.....(DI.XI#".#E..ZN{I..I.I...........B.[.[......H
    C000:0300  .....:&p...g.......06/02/11.........................400.10500000
    C000:0340  ..................d.]..................[ .........d.].........,.
    C000:0380  .....[1.......5.............@.@.G.....L.{.J...Q...d.......+.....
    C000:03C0  ..............a.......f...............n.....q.....t.o...{.x.].z.


--------[ Debug - Unknown ]---------------------------------------------------------------------------------------------

    HDD             TOSHIBA MQ01ABD050
    Optical         PIONEER DVD-RW  DVR-221L ATA Device
    PCI/AGP         10DE-0BEE [SubSys: 1462-809D]:  High Definition Audio (Microsoft) [10DE-0BEE] [NoDB]
    PCI/AGP         10DE-1244 [SubSys: 1462-809D]: NVIDIA GeForce GTX 550 Ti [10DE-1244] [NoDB]
    SSD             TOSHIBA MQ01ABD050


------------------------------------------------------------------------------------------------------------------------

The names of actual companies and products mentioned herein may be the trademarks of their respective owners.
