--------[ AIDA64 Extreme ]----------------------------------------------------------------------------------------------

                                                AIDA64 v4.30.2900/ru
                                        4.1.611-x64
                                      http://www.aida64.com/
                                              
                                             ZAQ-
                                             zaq
                                   Microsoft Windows 7 Ultimate 6.1.7601.18741 (Win7 RTM)
                                                  2015-04-06
                                                 21:09


--------[   ]----------------------------------------------------------------------------------------

    :
                                           ACPI x64-based PC
                                     Microsoft Windows 7 Ultimate
                                       Service Pack 1
      Internet Explorer                                 11.0.9600.17691
      DirectX                                           DirectX 11.1
                                           ZAQ-
                                         zaq
                                              zaq-
       /                                       2015-04-06 / 21:09

     :
                                                   HexaCore AMD Phenom II X6 Black Edition 1100T, 3315 MHz (16.5 x 201)
                                          Asus M5A78L-M/USB3  (2 PCI, 1 PCI-E x1, 1 PCI-E x16, 4 DDR3 DIMM, Audio, Video, Gigabit LAN)
                                    AMD 760G, AMD K10
                                         6144   (DDR3-1333 DDR3 SDRAM)
      DIMM1: Corsair XMS3 CM3X2G1333C9                  2  DDR3-1333 DDR3 SDRAM  (9-9-9-24 @ 666 )  (8-8-8-22 @ 592 )  (7-7-7-19 @ 518 )  (6-6-6-16 @ 444 )
      DIMM2: Corsair XMS3 CM3X2G1333C9                  2  DDR3-1333 DDR3 SDRAM  (9-9-9-24 @ 666 )  (8-8-8-22 @ 592 )  (7-7-7-19 @ 518 )  (6-6-6-16 @ 444 )
      DIMM3: Kingston 9905402-586.A00LF                 2  DDR3-1333 DDR3 SDRAM  (9-9-9-24 @ 666 )  (8-8-8-22 @ 609 )  (7-7-7-20 @ 533 )  (6-6-6-17 @ 457 )
       BIOS                                          AMI (11/12/13)
                                    Nuvoton Communications Port (COM1)
                                      (LPT1)

    :
                                            NVIDIA GeForce 9800 GTX+  (512 )
                                            NVIDIA GeForce 9800 GTX+  (512 )
      3D-                                    nVIDIA GeForce 9800 GTX+
                                                   PnP [NoDB]  (UHB1434012345)

    :
                                         VIA VT1708S @ ATI SB750 - High Definition Audio Controller

     :
       IDE                                    AMD PCI IDE Controller
       IDE                                    AMD SATA Controller (IDE Mode)
                                      ST250DM001 HD253GJ ATA Device  (250 , 7200 RPM, SATA-II)
                                      WD Elements 10A2 USB Device  (465 , USB)
      SMART-                         OK

    :
      C: (NTFS)                                         232.8  (114.6  )
      E: (NTFS)                                         465.7  (347.6  )
                                              698.5  (462.2  )

    :
                                               HID
                                               HID
                                                PS/2
                                                    HID- 
                                                    HID- 

    :
        IP                                192.168.1.5
        MAC                               E0-3F-49-7F-7F-88
                                          Realtek PCIe GBE Family Controller  (192.168.1.5)

     :
                                                 Fax
                                                 Microsoft XPS Document Writer
       USB1                                   ATI SB750 - OHCI USB Controller
       USB1                                   ATI SB750 - OHCI USB Controller
       USB1                                   ATI SB750 - OHCI USB Controller
       USB1                                   ATI SB750 - OHCI USB Controller
       USB1                                   ATI SB750 - OHCI USB Controller
       USB2                                   ATI SB750 - EHCI USB 2.0 Controller
       USB2                                   ATI SB750 - EHCI USB 2.0 Controller
       USB3                                   ASMedia ASM1142 USB 3.0 xHCI Controller
      USB-                                    SteelSeries HID Device
      USB-                                    SteelSeries HID Device
      USB-                                    SteelSeries HID Device
      USB-                                    SteelSeries HID Device
      USB-                                    USB Root Hub
      USB-                                    USB- 
      USB-                                    USB- 
      USB-                                    USB- 
      USB-                                    WebCam Vista/Live! Cam Chat VF0330
      USB-                                       USB
      USB-                                     USB 
      USB-                                     USB 

    DMI:
      DMI  BIOS                                American Megatrends Inc.
      DMI  BIOS                                   1801
      DMI                           System manufacturer
      DMI                                        System Product Name
      DMI                                System Version
      DMI                         System Serial Number
      DMI  UUID                                C0E8D530-10FFD511-900BE03F-497F7F88
      DMI                    ASUSTeK Computer INC.
      DMI                                 M5A78L-M/USB3
      DMI                           Rev X.0x
      DMI                    131219849904412
      DMI                             Chassis Manufacture
      DMI                                    Chassis Version
      DMI                             Chassis Serial Number
      DMI Asset-                                Asset-1234567890
      DMI                                       Desktop Case


--------[   ]----------------------------------------------------------------------------------------------

          
     NetBIOS                 ZAQ-
      DNS               zaq-
      DNS              
      DNS              zaq-
     NetBIOS                 ZAQ-
      DNS               zaq-
      DNS              
      DNS              zaq-


--------[   ]----------------------------------------------------------------------------------------

      :
                                              Microsoft Windows 7 Ultimate
                                                   ()
                                        ()
                                               Multiprocessor Free (64-bit)
                                                6.1.7601.18741 (Win7 RTM)
                                       Service Pack 1
                                         19.05.2014
                                         C:\Windows

     :
                          zaq
                           
      ID                                        00426-OEM-8992662-00006
                                            FJGCP-4DFJD-GJY49-VJBQ7-HYRR2
        (WPA)                           

     :
                                           ZAQ-
                                         zaq
                                              zaq-
                                             662  (0 ., 0 , 11 , 2 )

     :
      Common Controls                                   6.16
      Windows Mail                                      6.1.7600.16385 (win7_rtm.090713-1255)
      Windows Media Player                              12.0.7600.16385 (win7_rtm.090713-1255)
      Windows Messenger                                 -
      MSN Messenger                                     -
      Internet Information Services (IIS)               -
      .NET Framework                                    4.0.30319.34209 built by: FX452RTMGDR
      Novell Client                                     -
      DirectX                                           DirectX 11.1
      OpenGL                                            6.1.7600.16385 (win7_rtm.090713-1255)
      ASPI                                              -

      :
                                        
       DBCS                                       
                                        
                                     
                                             
                                         
                                         
                                      
                                      


--------[  ]----------------------------------------------------------------------------------------------------

    ABService.exe            C:\Program Files (x86)\AOMEI Backupper\ABService.exe                          32          6648              3 
    aida64.exe               C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe                    32         88108             78 
    AppleMobileDeviceService.exe  C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe  64         10752              3 
    armsvc.exe               C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe                  32          4060              1 
    atieclxx.exe             C:\Windows\system32\atieclxx.exe                                              64          7164              2 
    atiesrxx.exe             C:\Windows\system32\atiesrxx.exe                                              64          4956              1 
    audiodg.exe                                                                                            64         19652             18 
    avp.exe                  C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avp.exe      32           130            224 
    avpui.exe                C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 14.0.0\avpui.exe    32          4844             73 
    chrome.exe               C:\Program Files (x86)\Google\Chrome\Application\chrome.exe                   32         71468             62 
    chrome.exe               C:\Program Files (x86)\Google\Chrome\Application\chrome.exe                   32         63840             46 
    chrome.exe               C:\Program Files (x86)\Google\Chrome\Application\chrome.exe                   32           107             70 
    chrome.exe               C:\Program Files (x86)\Google\Chrome\Application\chrome.exe                   32         28024             28 
    chrome.exe               C:\Program Files (x86)\Google\Chrome\Application\chrome.exe                   32         66604             56 
    chrome.exe               C:\Program Files (x86)\Google\Chrome\Application\chrome.exe                   32         77064             65 
    conhost.exe              C:\Windows\system32\conhost.exe                                               32          3308              1 
    conhost.exe              C:\Windows\system32\conhost.exe                                               64          4968              1 
    csrss.exe                C:\Windows\system32\csrss.exe                                                 64          5208              2 
    csrss.exe                C:\Windows\system32\csrss.exe                                                 64          7712              3 
    DrvUpdater.exe           C:\Users\zaq\AppData\Roaming\DRPSu\DrvUpdater.exe                             32          6868              2 
    dwm.exe                  C:\Windows\system32\Dwm.exe                                                   64         34296             30 
    explorer.exe             C:\Windows\Explorer.EXE                                                       64         64168             39 
    GoogleUpdate.exe         C:\Program Files (x86)\Google\Update\GoogleUpdate.exe                         32          1940              2 
    iPodService.exe          C:\Program Files\iPod\bin\iPodService.exe                                     64          7172              2 
    iTunesHelper.exe         C:\Program Files\iTunes\iTunesHelper.exe                                      64         14440              5 
    lsass.exe                C:\Windows\system32\lsass.exe                                                 64         12136              4 
    lsm.exe                  C:\Windows\system32\lsm.exe                                                   64          4968              2 
    mDNSResponder.exe        C:\Program Files\Bonjour\mDNSResponder.exe                                    64          6140              2 
    NetworkLicenseServer.exe  C:\Program Files (x86)\ABBYY FineReader 12\NetworkLicenseServer.exe           32         17824             13 
    NvBackend.exe            C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe           32         13584              8 
    NvNetworkService.exe     C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe     32          5964              1 
    nvSCPAPISvr.exe          C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe           32          5956              2 
    nvstreamsvc.exe          C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe               64         10464              8 
    nvstreamsvc.exe          C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe               32         15408              7 
    nvstreamsvc.exe          C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe               64         15196              7 
    nvtray.exe               C:\Program Files\NVIDIA Corporation\Display\nvtray.exe                        64         13656              6 
    nvvsvc.exe               C:\Windows\system32\nvvsvc.exe                                                64         14276              6 
    nvvsvc.exe               C:\Windows\system32\nvvsvc.exe                                                64          8476              3 
    nvxdsync.exe             C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe                      64         21388              9 
    SearchFilterHost.exe     C:\Windows\system32\SearchFilterHost.exe                                      64          7620              3 
    SearchIndexer.exe        C:\Windows\system32\SearchIndexer.exe                                         64         28252             27 
    SearchProtocolHost.exe   C:\Windows\system32\SearchProtocolHost.exe                                    64          8932              3 
    services.exe             C:\Windows\system32\services.exe                                              64         12272              6 
    Skype.exe                C:\Program Files (x86)\Skype\Phone\Skype.exe                                  32           223            206 
    smss.exe                                                                                               64          1312              0 
    splwow64.exe             C:\Windows\splwow64.exe                                                       64          5544              2 
    spoolsv.exe              C:\Windows\System32\spoolsv.exe                                               64         12308              6 
    sppsvc.exe               C:\Windows\system32\sppsvc.exe                                                64         12016              5 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64          8928              4 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         18084             10 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         31300             18 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64          6032              2 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         15780             14 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         14956             11 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64          6244              2 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         13292              6 
    svchost.exe              C:\Windows\System32\svchost.exe                                               64          9720              4 
    svchost.exe              C:\Windows\System32\svchost.exe                                               64         25452             43 
    svchost.exe              C:\Windows\System32\svchost.exe                                               64         24932             24 
    svchost.exe              C:\Windows\System32\svchost.exe                                               64           151            144 
    svchost.exe              C:\Windows\system32\svchost.exe                                               64         11124              5 
    System Idle Process                                                                                                     24              0 
    System                                                                                                 64          2820              0 
    taskeng.exe              C:\Windows\system32\taskeng.exe                                               64          5864              2 
    taskhost.exe             C:\Windows\system32\taskhost.exe                                              64         17976             19 
    V0330Mon.exe             C:\Windows\V0330Mon.exe                                                       32          5896              1 
    ViakaraokeSrv.exe        C:\Windows\system32\viakaraokesrv.exe                                         64          4992              1 
    wininit.exe              C:\Windows\system32\wininit.exe                                               64          5056              1 
    winlogon.exe             C:\Windows\system32\winlogon.exe                                              64          8384              3 
    WmiPrvSE.exe             C:\Windows\system32\wbem\wmiprvse.exe                                         64          6952              3 
    WmiPrvSE.exe             C:\Windows\sysWOW64\wbem\wmiprvse.exe                                         64          7584              3 
    WmiPrvSE.exe             C:\Windows\system32\wbem\wmiprvse.exe                                         64          6908              3 
    wmpnetwk.exe             C:\Program Files\Windows Media Player\wmpnetwk.exe                            64          5100             11 


--------[   ]------------------------------------------------------------------------------------------

    {572f484b-455f-44b0-9d6a-da3ad2071365}Gw64  {572f484b-455f-44b0-9d6a-da3ad2071365}Gw64                              {572f484b-455f-44b0-9d6a-da3ad2071365}Gw64.sys  1.4.3.1                               
    1394ohci         1394 OHCI Compliant Host Controller                                     1394ohci.sys          6.1.7601.17514                        
    ACPI              Microsoft ACPI                                                  ACPI.sys              6.1.7601.17514                        
    AcpiPmi          ACPI Power Meter Driver                                                 acpipmi.sys           6.1.7601.17514                        
    adp94xx          adp94xx                                                                 adp94xx.sys           1.6.6.4                               
    adpahci          adpahci                                                                 adpahci.sys           1.6.6.1                               
    adpu320          adpu320                                                                 adpu320.sys           7.2.0.0                               
    AFD              Ancillary Function Driver for Winsock                                   afd.sys               6.1.7601.18489                        
    agp440           Intel AGP Bus Filter                                                    agp440.sys            6.1.7600.16385                        
    AIDA64Driver     FinalWire AIDA64 Kernel Driver                                          kerneld.x64                                                 
    aliide           aliide                                                                  aliide.sys            1.2.0.0                               
    ambakdrv         ambakdrv                                                                ambakdrv.sys                                                
    amd_sata         amd_sata                                                                amd_sata.sys          1.2.1.349                             
    amd_xata         amd_xata                                                                amd_xata.sys          1.2.1.349                             
    amdide           amdide                                                                  amdide.sys            6.1.7600.16385                        
    amdide64         amdide64                                                                amdide64.sys          5.2.2.179                             
    AmdK8            AMD K8 Processor Driver                                                 amdk8.sys             6.1.7600.16385                        
    amdkmdag         amdkmdag                                                                atikmdag.sys          8.1.1.1248                            
    amdkmdap         amdkmdap                                                                atikmpag.sys          8.14.1.6264                           
    AmdPPM             AMD                                                  amdppm.sys            6.1.7600.16385                        
    amdsata          amdsata                                                                 amdsata.sys           1.1.2.5                               
    amdsbs           amdsbs                                                                  amdsbs.sys            3.6.1540.127                          
    amdxata          amdxata                                                                 amdxata.sys           1.1.2.5                               
    ammntdrv         ammntdrv                                                                ammntdrv.sys                                                
    amwrtdrv         amwrtdrv                                                                amwrtdrv.sys                                                
    AppID             AppID                                                           appid.sys             6.1.7601.18741                        
    arc              arc                                                                     arc.sys               5.2.0.10384                           
    arcsas           arcsas                                                                  arcsas.sys            5.2.0.16119                           
    asmthub3         ASMedia USB3 Hub Service                                                asmthub3.sys          1.16.12.0                             
    asmtxhci         ASMEDIA XHCI Service                                                    asmtxhci.sys          1.16.12.0                             
    AsyncMac            RAS                                       asyncmac.sys          6.1.7600.16385                        
    atapi             IDE                                                               atapi.sys             6.1.7600.16385                        
    AtiHDAudioService  AMD Function Driver for HD Audio Service                                AtihdW76.sys          7.12.0.7706                           
    AtiPcie          AMD PCI Express (3GIO) Filter                                           AtiPcie.sys           1.3.2.54                              
    b06bdrv          Broadcom NetXtreme II VBD                                               bxvbda.sys            4.8.2.0                               
    b57nd60a         Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0                          b57nd60a.sys          10.100.4.0                            
    Beep             Beep                                                                                                                                
    blbdrive         blbdrive                                                                blbdrive.sys          6.1.7600.16385                        
    bowser                                                           bowser.sys            6.1.7601.17565             
    BrFiltLo         Brother USB Mass-Storage Lower Filter Driver                            BrFiltLo.sys          1.10.0.2                              
    BrFiltUp         Brother USB Mass-Storage Upper Filter Driver                            BrFiltUp.sys          1.4.0.1                               
    Brserid          Brother MFC Serial Port Interface Driver (WDM)                          Brserid.sys           1.0.1.6                               
    BrSerWdm         Brother WDM Serial driver                                               BrSerWdm.sys          1.0.0.20                              
    BrUsbMdm         Brother MFC USB Fax Only Modem                                          BrUsbMdm.sys          1.0.0.12                              
    BrUsbSer         Brother MFC USB Serial WDM Driver                                       BrUsbSer.sys          1.0.1.3                               
    BTHMODEM         Bluetooth Serial Communications Driver                                  bthmodem.sys          6.1.7600.16385                        
    busenum          SteelBusSvc                                                             SteelBus64.sys        3.0.0.18                              
    cdfs             CD/DVD File System Reader                                               cdfs.sys              6.1.7600.16385             
    cdrom             CD-ROM                                                 cdrom.sys             6.1.7601.17514                        
    circlass         Consumer IR Devices                                                     circlass.sys          6.1.7600.16385                        
    CLFS               (CLFS)                                                     CLFS.sys              6.1.7600.16385                        
    CmBatt           Microsoft ACPI Control Method Battery Driver                            CmBatt.sys            6.1.7600.16385                        
    cmdide           cmdide                                                                  cmdide.sys            2.0.7.0                               
    CNG              CNG                                                                     cng.sys               6.1.7601.18739                        
    Compbatt         Compbatt                                                                compbatt.sys          6.1.7600.16385                        
    CompositeBus                                          CompositeBus.sys      6.1.7601.17514                        
    crcdisk          Crcdisk Filter Driver                                                   crcdisk.sys           6.1.7600.16385                        
    CSC                                                               csc.sys               6.1.7601.17514                        
    DfsC             DFS Namespace Client Driver                                             dfsc.sys              6.1.7601.17514             
    discache         System Attribute Cache                                                  discache.sys          6.1.7600.16385                        
    Disk                                                                         disk.sys              6.1.7600.16385                        
    dmvsc            dmvsc                                                                   dmvsc.sys             6.1.7601.17514                        
    drmkaud                                                 drmkaud.sys           6.1.7600.16385                        
    DrvAgent64       DrvAgent64                                                              DrvAgent64.SYS        1.0.0.1                               
    DXGKrnl          LDDM Graphics Subsystem                                                 dxgkrnl.sys           6.1.7601.18510                        
    EagleX64         EagleX64                                                                EagleX64.sys                                                
    ebdrv            Broadcom NetXtreme II 10 GigE VBD                                       evbda.sys             4.8.13.0                              
    elxstor          elxstor                                                                 elxstor.sys           7.2.10.211                            
    ErrDev           Microsoft Hardware Error Device Driver                                  errdev.sys            6.1.7600.16385                        
    exfat            exFAT File System Driver                                                                                                 
    fastfat          FAT12/16/32 File System Driver                                                                                           
    fdc              Floppy Disk Controller Driver                                           fdc.sys               6.1.7600.16385                        
    FileInfo         File Information FS MiniFilter                                          fileinfo.sys          6.1.7600.16385             
    Filetrace        Filetrace                                                               filetrace.sys         6.1.7600.16385             
    flpydisk         Floppy Disk Driver                                                      flpydisk.sys          6.1.7600.16385                        
    FltMgr                                                                  fltmgr.sys            6.1.7601.17514             
    FsDepends        File System Dependency Minifilter                                       FsDepends.sys         6.1.7600.16385             
    fvevol               Bitlocker                              fvevol.sys            6.1.7601.18062                        
    gagp30kx         Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms             gagp30kx.sys          6.1.7600.16385                        
    GEARAspiWDM      GEAR ASPI Filter Driver                                                 GEARAspiWDM.sys       2.2.3.0                               
    hcw85cir         Hauppauge Consumer Infrared Receiver                                    hcw85cir.sys          1.31.27127.0                          
    HdAudAddService    UAA   High Definition Audio (Microsoft),  1.1  HdAudio.sys           6.1.7601.17514                        
    HDAudBus            UAA  High Definition Audio (Microsoft)              HDAudBus.sys          6.1.7601.17514                        
    HidBatt          HID UPS Battery Driver                                                  HidBatt.sys           6.1.7600.16385                        
    HidBth           Microsoft Bluetooth HID Miniport                                        hidbth.sys            6.1.7600.16385                        
    HidIr            Microsoft Infrared HID Driver                                           hidir.sys             6.1.7600.16385                        
    HidUsb             HID Microsoft                                            hidusb.sys            6.1.7601.17514                        
    HpSAMD           HpSAMD                                                                  HpSAMD.sys            6.12.6.64                             
    HTTP             HTTP                                                                    HTTP.sys              6.1.7601.17514                        
    hwpolicy         Hardware Policy Driver                                                  hwpolicy.sys          6.1.7601.17514                        
    i8042prt          i8042-     PS/2                          i8042prt.sys          6.1.7600.16385                        
    iaStorV          iaStorV                                                                 iaStorV.sys           8.6.2.1014                            
    iirsp            iirsp                                                                   iirsp.sys             5.4.22.0                              
    intelide         intelide                                                                intelide.sys          6.1.7600.16385                        
    intelppm         Intel Processor Driver                                                  intelppm.sys          6.1.7600.16385                        
    IpFilterDriver     IP-                                              ipfltdrv.sys          6.1.7601.17514                        
    IPMIDRV          IPMIDRV                                                                 IPMIDrv.sys           6.1.7601.17514                        
    IPNAT            IP Network Address Translator                                           ipnat.sys             6.1.7600.16385                        
    IRENUM           IR Bus Enumerator                                                       irenum.sys            6.1.7600.16385                        
    isapnp           isapnp                                                                  isapnp.sys            6.1.7600.16385                        
    iScsiPrt          iScsiPort                                                       msiscsi.sys           6.1.7601.18386                        
    kbdclass                                                          kbdclass.sys          6.1.7600.16385                        
    kbdhid             HID                                                  kbdhid.sys            6.1.7601.17514                        
    kl1              kl1                                                                     kl1.sys               6.8.0.35                              
    klflt            klflt                                                                   klflt.sys             1.3.0.60                              
    KLIF             Kaspersky Lab Driver                                                    klif.sys              8.13.0.399                 
    KLIM6            Kaspersky Anti-Virus NDIS 6 Filter                                      klim6.sys             8.0.0.71                              
    klkbdflt         Kaspersky Lab KLKBDFLT                                                  klkbdflt.sys          8.10.0.50                             
    klmouflt         Kaspersky Lab KLMOUFLT                                                  klmouflt.sys          8.10.0.41                             
    klpd             klpd                                                                    klpd.sys              1.0.0.22                              
    kltdi            kltdi                                                                   kltdi.sys             1.5.0.26                              
    kneps            kneps                                                                   kneps.sys             5.5.0.65                              
    KSecDD           KSecDD                                                                  ksecdd.sys            6.1.7601.18779                        
    KSecPkg          KSecPkg                                                                 ksecpkg.sys           6.1.7601.18779                        
    ksthunk          Kernel Streaming Thunks                                                 ksthunk.sys           6.1.7600.16385                        
    lltdio           Link-Layer Topology Discovery Mapper I/O Driver                         lltdio.sys            6.1.7600.16385                        
    LSI_FC           LSI_FC                                                                  lsi_fc.sys            1.28.3.52                             
    LSI_SAS          LSI_SAS                                                                 lsi_sas.sys           1.28.3.52                             
    LSI_SAS2         LSI_SAS2                                                                lsi_sas2.sys          2.0.2.71                              
    LSI_SCSI         LSI_SCSI                                                                lsi_scsi.sys          1.28.3.67                             
    luafv                                            luafv.sys             6.1.7600.16385             
    megasas          megasas                                                                 megasas.sys           4.5.1.64                              
    MegaSR           MegaSR                                                                  MegaSR.sys            13.5.409.2009                         
    Modem            Modem                                                                   modem.sys             6.1.7600.16385                        
    monitor          Microsoft Monitor Class Function Driver Service                         monitor.sys           6.1.7600.16385                        
    mouclass                                                                mouclass.sys          6.1.7600.16385                        
    mouhid             HID                                                        mouhid.sys            6.1.7600.16385                        
    mountmgr                                                        mountmgr.sys          6.1.7601.18741                        
    mpio             mpio                                                                    mpio.sys              6.1.7601.17514                        
    mpsdrv              Windows                                 mpsdrv.sys            6.1.7600.16385                        
    MRxDAV              WebDav                                 mrxdav.sys            6.1.7601.18706             
    mrxsmb              - SMB                              mrxsmb.sys            6.1.7601.17605             
    mrxsmb10         - SMB 1.x                                            mrxsmb10.sys          6.1.7601.17647             
    mrxsmb20         - SMB 2.0                                            mrxsmb20.sys          6.1.7601.17605             
    msahci           msahci                                                                  msahci.sys            6.1.7601.17514                        
    msdsm            msdsm                                                                   msdsm.sys             6.1.7601.17514                        
    Msfs             Msfs                                                                                                                     
    mshidkmdf        Pass-through HID to KMDF Filter Driver                                  mshidkmdf.sys         6.1.7600.16385                        
    msisadrv         msisadrv                                                                msisadrv.sys          6.1.7600.16385                        
    MSKSSRV             Microsoft                                   MSKSSRV.sys           6.1.7600.16385                        
    MSPCLOCK            Microsoft                               MSPCLOCK.sys          6.1.7600.16385                        
    MSPQM                Microsoft                     MSPQM.sys             6.1.7600.16385                        
    MsRPC            MsRPC                                                                                                                               
    mssmbios         Microsoft System Management BIOS                                 mssmbios.sys          6.1.7600.16385                        
    MSTEE              Tee/Sink-to-Sink Microsoft                      MSTEE.sys             6.1.7600.16385                        
    MTConfig         Microsoft Input Configuration Driver                                    MTConfig.sys          6.1.7600.16385                        
    MTsensor         ATK0110 ACPI UTILITY                                                    ASACPI.sys            1043.6.0.0                            
    Mup              Mup                                                                     mup.sys               6.1.7600.16385             
    NativeWifiP      NativeWiFi Filter                                                       nwifi.sys             6.1.7600.16385                        
    NDIS               NDIS                                                  ndis.sys              6.1.7601.17939                        
    NdisCap          NDIS Capture LightWeight Filter                                         ndiscap.sys           6.1.7600.16385                        
    NdisTapi         NDIS- TAPI                                      ndistapi.sys          6.1.7600.16385                        
    Ndisuio          NDIS Usermode I/O Protocol                                              ndisuio.sys           6.1.7601.17514                        
    NdisWan          NDIS- WAN                                       ndiswan.sys           6.1.7601.17514                        
    NDProxy          NDIS Proxy                                                                                                                          
    NetBIOS          NetBIOS Interface                                                       netbios.sys           6.1.7600.16385             
    NetBT            NetBT                                                                   netbt.sys             6.1.7601.17514                        
    nfrd960          nfrd960                                                                 nfrd960.sys           7.10.0.0                              
    Npfs             Npfs                                                                                                                     
    nsiproxy         NSI proxy service driver.                                               nsiproxy.sys          6.1.7600.16385                        
    Ntfs             Ntfs                                                                                                                     
    Null             Null                                                                                                                                
    nusb3hub         Renesas Electronics USB 3.0 Hub Driver                                  nusb3hub.sys          2.1.39.0                              
    nusb3xhc         Renesas Electronics USB 3.0 Host Controller Driver                      nusb3xhc.sys          2.1.39.0                              
    nv_agp           NVIDIA nForce AGP Bus Filter                                            nv_agp.sys            6.1.7600.16385                        
    nvlddmkm         nvlddmkm                                                                nvlddmkm.sys          9.18.13.4052                          
    nvraid           nvraid                                                                  nvraid.sys            10.6.0.18                             
    nvstor           nvstor                                                                  nvstor.sys            10.6.0.18                             
    NvStreamKms      NvStreamKms                                                             NvStreamKms.sys       1.0.0.0                               
    nvvad_WaveExtensible  NVIDIA Virtual Audio Device (Wave Extensible) (WDM)                     nvvad64v.sys          1.2.23.0                              
    ohci1394         1394 OHCI Compliant Host Controller (Legacy)                            ohci1394.sys          6.1.7600.16385                        
    Parport                                                         parport.sys           6.1.7600.16385                        
    partmgr                                                                 partmgr.sys           6.1.7601.17796                        
    pci               PCI                                                         pci.sys               6.1.7601.17514                        
    pciide           pciide                                                                  pciide.sys            6.1.7600.16385                        
    pcmcia           pcmcia                                                                  pcmcia.sys            6.1.7600.16385                        
    pcw              Performance Counters for Windows Driver                                 pcw.sys               6.1.7600.16385                        
    PEAUTH           PEAUTH                                                                  peauth.sys            6.1.7601.18741                        
    PptpMiniport     - WAN (PPTP)                                                    raspptp.sys           6.1.7601.17514                        
    Processor        Processor Driver                                                        processr.sys          6.1.7600.16385                        
    Psched             QoS                                                 pacer.sys             6.1.7601.17514                        
    ql2300           ql2300                                                                  ql2300.sys            9.1.8.6                               
    ql40xx           ql40xx                                                                  ql40xx.sys            2.1.3.20                              
    QWAVEdrv          QWAVE                                                           qwavedrv.sys          6.1.7600.16385                        
    RasAcd           Remote Access Auto Connection Driver                                    rasacd.sys            6.1.7600.16385                        
    RasAgileVpn      WAN Miniport (IKEv2)                                                    AgileVpn.sys          6.1.7600.16385                        
    Rasl2tp          - WAN (L2TP)                                                    rasl2tp.sys           6.1.7601.17514                        
    RasPppoe          PPPOE                                          raspppoe.sys          6.1.7600.16385                        
    RasSstp          - WAN (SSTP)                                                    rassstp.sys           6.1.7600.16385                        
    rdbss                                               rdbss.sys             6.1.7601.17514             
    rdpbus           Remote Desktop Device Redirector Bus Driver                             rdpbus.sys            6.1.7600.16385                        
    RDPCDD           RDPCDD                                                                  RDPCDD.sys            6.1.7600.16385                        
    RDPDR            Terminal Server Device Redirector Driver                                rdpdr.sys             6.1.7601.17514                        
    RDPENCDD         RDP Encoder Mirror Driver                                               rdpencdd.sys          6.1.7600.16385                        
    RDPREFMP         Reflector Display Driver used to gain access to graphics data           rdprefmp.sys          6.1.7600.16385                        
    RdpVideoMiniport  Remote Desktop Video Miniport Driver                                    rdpvideominiport.sys  6.2.9200.16398                        
    RDPWD            RDP Winstation Driver                                                                                                               
    rdyboost         ReadyBoost                                                              rdyboost.sys          6.1.7601.17514                        
    rspndr           Link-Layer Topology Discovery Responder                                 rspndr.sys            6.1.7600.16385                        
    RTL8167          Realtek 8167 NT Driver                                                  Rt64win7.sys          7.79.108.2014                         
    s3cap            s3cap                                                                   vms3cap.sys           6.1.7601.17514                        
    SAlphamHid       SteelHIDSvc                                                             SAlpham64.sys         2.4.2.5                               
    sbp2port         sbp2port                                                                sbp2port.sys          6.1.7601.17514                        
    scfilter           -  PnP                                  scfilter.sys          6.1.7601.17514                        
    ScreamBAudioSvc  ScreamBee Audio                                                         ScreamingBAudio64.sys  2.0.3.0                               
    secdrv           Security Driver                                                                                                                     
    Serenum          Nuvoton Serenum Filter Driver                                           nuvserenum.sys        6.1.7600.16385                        
    Serial           Nuvoton Serial driver                                                   nuvserial.sys         1.0.2011.1109                         
    sermouse         Serial Mouse Driver                                                     sermouse.sys          6.1.7600.16385                        
    sffdisk          SFF Storage Class Driver                                                sffdisk.sys           6.1.7600.16385                        
    sffp_mmc         SFF Storage Protocol Driver for MMC                                     sffp_mmc.sys          6.1.7600.16385                        
    sffp_sd          SFF Storage Protocol Driver for SDBus                                   sffp_sd.sys           6.1.7601.17514                        
    sfloppy          High-Capacity Floppy Disk Drive                                         sfloppy.sys           6.1.7600.16385                        
    SiSRaid2         SiSRaid2                                                                SiSRaid2.sys          5.1.1039.2600                         
    SiSRaid4         SiSRaid4                                                                sisraid4.sys          5.1.1039.3600                         
    Smb                TCP/IP  TCP/IPv6 ( SMB)                        smb.sys               6.1.7600.16385                        
    spldr            Security Processor Loader Driver                                                                                                    
    srv                Server SMB 1.xxx                                        srv.sys               6.1.7601.17608             
    srv2               Server SMB 2.xxx                                        srv2.sys              6.1.7601.17608             
    srvnet           srvnet                                                                  srvnet.sys            6.1.7601.17608             
    stexstor         stexstor                                                                stexstor.sys          5.0.1.1                               
    storflt                                   vmstorfl.sys          6.1.7601.17514                        
    storvsc          storvsc                                                                 storvsc.sys           6.1.7601.17514                        
    swenum                                                             swenum.sys            6.1.7600.16385                        
    Synth3dVsc       Synth3dVsc                                                              synth3dvsc.sys        6.1.7601.17514                        
    Tcpip              TCP/IP                                                tcpip.sys             6.1.7601.18438                        
    TCPIP6           Microsoft IPv6 Protocol Driver                                          tcpip.sys             6.1.7601.18438                        
    tcpipreg         TCP/IP Registry Compatibility                                           tcpipreg.sys          6.1.7601.17964                        
    TDPIPE           TDPIPE                                                                  tdpipe.sys            6.1.7600.16385                        
    TDTCP            TDTCP                                                                   tdtcp.sys             6.1.7601.17779                        
    tdx                NetIO Legacy TDI                                      tdx.sys               6.1.7601.18658                        
    TermDD                                                         termdd.sys            6.1.7601.17514                        
    terminpt         Microsoft Remote Desktop Input Driver                                   terminpt.sys          6.2.9200.16398                        
    tssecsrv         Remote Desktop Services Security Filter Driver                          tssecsrv.sys          6.1.7601.18540                        
    TsUsbFlt         TsUsbFlt                                                                tsusbflt.sys          6.3.9600.16415                        
    TsUsbGD          Remote Desktop Generic USB Device                                       TsUsbGD.sys           6.3.9600.16415                        
    tsusbhub         tsusbhub                                                                tsusbhub.sys          6.1.7601.17514                        
    tunnel                Microsoft                        tunnel.sys            6.1.7601.17514                        
    uagp35           Microsoft AGPv3.5 Filter                                                uagp35.sys            6.1.7600.16385                        
    udfs             udfs                                                                    udfs.sys              6.1.7601.17514             
    uliagpkx         Uli AGP Bus Filter                                                      uliagpkx.sys          6.1.7600.16385                        
    umbus            UMBus                                               umbus.sys             6.1.7601.17514                        
    UmPass           Microsoft UMPass Driver                                                 umpass.sys            6.1.7600.16385                        
    USBAAPL64        Apple Mobile USB Driver                                                 usbaapl64.sys         1.65.0.0                              
    usbaudio           USB (WDM)                                                 usbaudio.sys          6.1.7601.18208                        
    usbccgp              USB (Microsoft)         usbccgp.sys           6.1.7601.18328                        
    usbcir           eHome   (USBCIR)                                     usbcir.sys            6.1.7601.18208                        
    usbehci            Microsoft USB 2.0  -       usbehci.sys           6.1.7601.18328                        
    usbhub             USB- ()                      usbhub.sys            6.1.7601.18328                        
    usbohci            Microsoft USB  -              usbohci.sys           6.1.7601.18328                        
    usbprint         Microsoft USB PRINTER Class                                             usbprint.sys          6.1.7600.16385                        
    USBSTOR              USB                                  USBSTOR.SYS           6.1.7601.17577                        
    usbuhci            Microsoft USB  -         usbuhci.sys           6.1.7601.18328                        
    V0330VID         WebCam Vista/Live! Cam Chat VF0330                                      V0330Vid.sys          1.12.1.0                              
    vdrvroot             ()                   vdrvroot.sys          6.1.7600.16385                        
    vga              vga                                                                     vgapnp.sys            6.1.7600.16385                        
    VgaSave          VgaSave                                                                 vga.sys               6.1.7600.16385                        
    VGPU             VGPU                                                                    rdvgkmd.sys                                                 
    vhdmp            vhdmp                                                                   vhdmp.sys             6.1.7601.17514                        
    VIAHdAudAddService  VIA High Definition Audio Driver Service                                viahduaa.sys          6.0.11.300                            
    viaide           viaide                                                                  viaide.sys            6.0.6000.170                          
    vmbus            vmbus                                                                   vmbus.sys             6.1.7601.17514                        
    VMBusHID         VMBusHID                                                                VMBusHID.sys          6.1.7601.17514                        
    volmgr                                                             volmgr.sys            6.1.7601.17514                        
    volmgrx                                                        volmgrx.sys           6.1.7601.17514                        
    volsnap                                                         volsnap.sys           6.1.7601.17514                        
    vsmraid          vsmraid                                                                 vsmraid.sys           6.0.6000.6210                         
    vwifibus           Virtual WiFi                                               vwifibus.sys          6.1.7600.16385                        
    WacomPen         Wacom Serial Pen HID Driver                                             wacompen.sys          6.1.7600.16385                        
    WANARP              IP ARP                                       wanarp.sys            6.1.7601.17514                        
    Wanarpv6            IPv6 ARP                                     wanarp.sys            6.1.7601.17514                        
    Wd               Wd                                                                      wd.sys                6.1.7600.16385                        
    Wdf01000                                                 Wdf01000.sys          1.11.9200.16648                       
    WfpLwf           WFP Lightweight Filter                                                  wfplwf.sys            6.1.7600.16385                        
    WIMMount         WIMMount                                                                wimmount.sys          6.1.7600.16385             
    WinUsb           WinUsb                                                                  WinUsb.sys            6.1.7601.17514                        
    WmiAcpi          Microsoft Windows Management Interface for ACPI                         wmiacpi.sys           6.1.7600.16385                        
    ws2ifsl           WinSock IFS                                                     ws2ifsl.sys           6.1.7600.16385                        
    WudfPf           User Mode Driver Frameworks Platform Driver                             WudfPf.sys            6.2.9200.16384                        
    WUDFRd           WUDFRd                                                                  WUDFRd.sys            6.2.9200.16384                        


--------[  ]------------------------------------------------------------------------------------------------------

    ABBYY.Licensing.FineReader.Professional.12.0  ABBYY FineReader 12 PE Licensing Service                                NetworkLicenseServer.exe  3.4.2.39                       LocalSystem
    AdobeARMservice                    Adobe Acrobat Update Service                                            armsvc.exe            1.802.11.4130                  LocalSystem
    AdobeFlashPlayerUpdateSvc          Adobe Flash Player Update Service                                       FlashPlayerUpdateService.exe  16.0.0.305                     LocalSystem
    AeLookupSvc                                                              svchost.exe           6.1.7600.16385                       localSystem
    ALG                                                                             alg.exe               6.1.7600.16385                 NT AUTHORITY\LocalService
    AMD External Events Utility        AMD External Events Utility                                             atiesrxx.exe          6.14.11.1122                   LocalSystem
    AppIDSvc                                                                            svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    Appinfo                                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    Apple Mobile Device Service        Apple Mobile Device Service                                             AppleMobileDeviceService.exe  17.344.6.6                     LocalSystem
    AppMgmt                                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    aspnet_state                       ASP.NET State Service                                                   aspnet_state.exe      4.0.30319.34209                NT AUTHORITY\NetworkService
    AudioEndpointBuilder                   Windows Audio                        svchost.exe           6.1.7600.16385                       LocalSystem
    AudioSrv                           Windows Audio                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    AVP                                Kaspersky Anti-Virus Service                                            avp.exe               14.0.0.4764                    LocalSystem
    AxInstSV                            ActiveX (AxInstSV)                                           svchost.exe           6.1.7600.16385                       LocalSystem
    Backupper Service                  AOMEI Backupper Scheduler Service                                       ABService.exe         1.0.0.1                        LocalSystem
    BDESVC                                BitLocker                                      svchost.exe           6.1.7600.16385                       localSystem
    BFE                                                                                 svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    BITS                                   (BITS)                         svchost.exe           6.1.7600.16385                       LocalSystem
    Bonjour Service                     Bonjour                                                          mDNSResponder.exe     3.0.0.10                       LocalSystem
    Browser                                                                                  svchost.exe           6.1.7600.16385                       LocalSystem
    bthserv                              Bluetooth                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    CertPropSvc                                                                      svchost.exe           6.1.7600.16385                       LocalSystem
    clr_optimization_v2.0.50727_32     Microsoft .NET Framework NGEN v2.0.50727_X86                            mscorsvw.exe          2.0.50727.5483                 LocalSystem
    clr_optimization_v2.0.50727_64     Microsoft .NET Framework NGEN v2.0.50727_X64                            mscorsvw.exe          2.0.50727.5483                 LocalSystem
    clr_optimization_v4.0.30319_32     Microsoft .NET Framework NGEN v4.0.30319_X86                            mscorsvw.exe          4.0.30319.34209                LocalSystem
    clr_optimization_v4.0.30319_64     Microsoft .NET Framework NGEN v4.0.30319_X64                            mscorsvw.exe          4.0.30319.34209                LocalSystem
    COMSysApp                            COM+                                               dllhost.exe           6.1.7600.16385                 LocalSystem
    CryptSvc                                                                                 svchost.exe           6.1.7600.16385                       NT Authority\NetworkService
    CscService                                                                                  svchost.exe           6.1.7600.16385                       LocalSystem
    DcomLaunch                            DCOM-                                   svchost.exe           6.1.7600.16385                       LocalSystem
    defragsvc                                                                               svchost.exe           6.1.7600.16385                 localSystem
    Dhcp                               DHCP-                                                             svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    Dnscache                           DNS-                                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    dot3svc                                                                              svchost.exe           6.1.7600.16385                       localSystem
    DPS                                                                               svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    EapHost                                (EAP)                         svchost.exe           6.1.7600.16385                       localSystem
    EFS                                   (EFS)                                      lsass.exe             6.1.7601.18779                       LocalSystem
    ehRecvr                              Windows Media Center                                    ehRecvr.exe           6.1.7601.17514                 NT AUTHORITY\networkService
    ehSched                              Windows Media Center                                ehsched.exe           6.1.7600.16385                 NT AUTHORITY\networkService
    eventlog                             Windows                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    EventSystem                          COM+                                                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Fax                                                                                                    fxssvc.exe            6.1.7601.17514                 NT AUTHORITY\NetworkService
    fdPHost                                                                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    FDResPub                                                               svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    FontCache                             Windows                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    FontCache3.0.0.0                     Windows Presentation Foundation 3.0.0.0                     PresentationFontCache.exe  3.0.6920.5011                  NT Authority\LocalService
    gpsvc                                                                               svchost.exe           6.1.7600.16385                 LocalSystem
    gupdate                             Google Update (gupdate)                                          GoogleUpdate.exe      1.3.21.103                     LocalSystem
    gupdatem                            Google Update (gupdatem)                                         GoogleUpdate.exe      1.3.21.103                     LocalSystem
    hidserv                              HID-                                                svchost.exe           6.1.7600.16385                       LocalSystem
    hkmsvc                                                      svchost.exe           6.1.7600.16385                       localSystem
    HomeGroupListener                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    HomeGroupProvider                                                                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    idsvc                              Windows CardSpace                                                       infocard.exe          3.0.4506.5464                        LocalSystem
    IEEtwCollectorService              Internet Explorer ETW Collector Service                                 IEEtwCollector.exe    11.0.9600.17689                LocalSystem
    IKEEXT                               IPsec        IP     svchost.exe           6.1.7600.16385                       LocalSystem
    IPBusEnum                           IP- PnP-X                                              svchost.exe           6.1.7600.16385                       LocalSystem
    iphlpsvc                             IP                                               svchost.exe           6.1.7600.16385                       LocalSystem
    iPod Service                        iPod                                                             iPodService.exe       12.1.1.4                       LocalSystem
    KeyIso                               CNG                                                     lsass.exe             6.1.7601.18779                       LocalSystem
    KtmRm                              KtmRm                            svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    LanmanServer                                                                                         svchost.exe           6.1.7600.16385                       LocalSystem
    LanmanWorkstation                                                                            svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    lltdsvc                                                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    lmhosts                              NetBIOS  TCP/IP                                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Mcx2Svc                              Media Center                                      svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    MMCSS                                                                         svchost.exe           6.1.7600.16385                       LocalSystem
    MpsSvc                              Windows                                                      svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    MSDTC                                                                   msdtc.exe             2001.12.8530.16385                NT AUTHORITY\NetworkService
    MSiSCSI                               iSCSI                                      svchost.exe           6.1.7600.16385                       LocalSystem
    msiserver                           Windows                                                      msiexec.exe           5.0.7601.17514                 LocalSystem
    napagent                                                                         svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    Netlogon                                                                                lsass.exe             6.1.7601.18779                       LocalSystem
    Netman                                                                                   svchost.exe           6.1.7600.16385                       LocalSystem
    NetMsmqActivator                   Net.Msmq Listener Adapter                                               SMSvcHost.exe         4.0.30319.34209                      NT AUTHORITY\NetworkService
    NetPipeActivator                   Net.Pipe Listener Adapter                                               SMSvcHost.exe         4.0.30319.34209                      NT AUTHORITY\LocalService
    netprofm                                                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    NetTcpActivator                    Net.Tcp Listener Adapter                                                SMSvcHost.exe         4.0.30319.34209                      NT AUTHORITY\LocalService
    NetTcpPortSharing                  Net.Tcp Port Sharing Service                                            SMSvcHost.exe         4.0.30319.34209                      NT AUTHORITY\LocalService
    NlaSvc                                                                     svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    nsi                                                                          svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    NvNetworkService                   NVIDIA Network Service                                                  NvNetworkService.exe  1.0.8.24                       LocalSystem
    NvStreamSvc                        NVIDIA Streamer Service                                                 nvstreamsvc.exe       3.1.100.0                      LocalSystem
    nvsvc                              NVIDIA Display Driver Service                                           nvvsvc.exe            8.17.13.4052                   LocalSystem
    ose                                Office  Source Engine                                                   OSE.EXE               15.0.4454.1000                 LocalSystem
    osppsvc                            Office Software Protection Platform                                     OSPPSVC.EXE           15.0.169.500                   NT AUTHORITY\NetworkService
    p2pimsvc                                                            svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    p2psvc                                                                         svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PcaSvc                                                               svchost.exe           6.1.7600.16385                       LocalSystem
    PeerDistSvc                        BranchCache                                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    PerfHost                                                           perfhost.exe          6.1.7600.16385                 NT AUTHORITY\LocalService
    pla                                                                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PlugPlay                           Plug-and-Play                                                           svchost.exe           6.1.7600.16385                       LocalSystem
    PNRPAutoReg                            PNRP                                 svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PNRPsvc                             PNRP                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    PolicyAgent                          IPsec                                                    svchost.exe           6.1.7600.16385                       NT Authority\NetworkService
    Power                                                                                               svchost.exe           6.1.7600.16385                       LocalSystem
    ProfSvc                                                                         svchost.exe           6.1.7600.16385                       LocalSystem
    ProtectedStorage                                                                        lsass.exe             6.1.7601.18779                       LocalSystem
    QWAVE                              Quality Windows Audio Video Experience                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    RasAuto                                                 svchost.exe           6.1.7600.16385                       localSystem
    RasMan                                                                svchost.exe           6.1.7600.16385                       localSystem
    RemoteAccess                                                                  svchost.exe           6.1.7600.16385                       localSystem
    RemoteRegistry                                                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    RpcEptMapper                          RPC                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    RpcLocator                             (RPC)                                locator.exe           6.1.7600.16385                 NT AUTHORITY\NetworkService
    RpcSs                                 (RPC)                                          svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    SamSs                                                                   lsass.exe             6.1.7601.18779                       LocalSystem
    SCardSvr                           -                                                             svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Schedule                                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    SCPolicySvc                          -                                            svchost.exe           6.1.7600.16385                       LocalSystem
    SDRSVC                              Windows                                                       svchost.exe           6.1.7600.16385                 localSystem
    seclogon                                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    SENS                                                                    svchost.exe           6.1.7600.16385                       LocalSystem
    SensrSvc                                                                       svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    SessionEnv                                                           svchost.exe           6.1.7600.16385                       localSystem
    SharedAccess                             (ICS)                            svchost.exe           6.1.7600.16385                       LocalSystem
    ShellHWDetection                                                            svchost.exe           6.1.7600.16385                       LocalSystem
    SkypeUpdate                        Skype Updater                                                           Updater.exe           7.0.0.386                      LocalSystem
    SNMPTRAP                            SNMP                                                            snmptrap.exe          6.1.7600.16385                 NT AUTHORITY\LocalService
    Spooler                                                                                     spoolsv.exe           6.1.7601.17777                 LocalSystem
    sppsvc                                                                        sppsvc.exe            6.1.7601.17514                 NT AUTHORITY\NetworkService
    sppuinotify                          SPP                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    SSDPSRV                             SSDP                                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    SstpSvc                             SSTP                                                             svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    Steam Client Service               Steam Client Service                                                    SteamService.exe      2.68.54.25                     LocalSystem
    Stereo Service                     NVIDIA Stereoscopic 3D Driver Service                                   nvSCPAPISvr.exe       7.17.13.4052                   LocalSystem
    stisvc                                Windows (WIA)                               svchost.exe           6.1.7600.16385                 NT Authority\LocalService
    swprv                                  (Microsoft)                  svchost.exe           6.1.7600.16385                 LocalSystem
    SysMain                            Superfetch                                                              svchost.exe           6.1.7600.16385                       LocalSystem
    TabletInputService                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    TapiSrv                                                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    TBS                                                           svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    TermService                                                                    svchost.exe           6.1.7600.16385                       NT Authority\NetworkService
    Themes                                                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    THREADORDER                                                                       svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    TrkWks                                                                 svchost.exe           6.1.7600.16385                       LocalSystem
    TrustedInstaller                     Windows                                              TrustedInstaller.exe  6.1.7601.17514                 localSystem
    UI0Detect                                                                     UI0Detect.exe         6.1.7600.16385                 LocalSystem
    UmRdpService                                svchost.exe           6.1.7600.16385                       localSystem
    upnphost                             PNP-                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    UxSms                                                           svchost.exe           6.1.7600.16385                       localSystem
    VaultSvc                                                                             lsass.exe             6.1.7601.18779                       LocalSystem
    vds                                                                                         vds.exe               6.1.7601.17514                 LocalSystem
    VIAKaraokeService                  VIA Karaoke digital mixer Service                                       viakaraokesrv.exe     0.1.0.0                              LocalSystem
    VSS                                                                                  vssvc.exe             6.1.7601.17514                 LocalSystem
    W32Time                              Windows                                                  svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WatAdminSvc                           Windows                                     WatAdminSvc.exe       7.1.7600.16395                 LocalSystem
    wbengine                                                                wbengine.exe          6.1.7601.17514                 localSystem
    WbioSrvc                             Windows                                           svchost.exe           6.1.7600.16385                       LocalSystem
    wcncsvc                              Windows -                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WcsPlugInService                     Windows (WCS)                                          svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WdiServiceHost                                                                        svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WdiSystemHost                                                                        svchost.exe           6.1.7600.16385                       LocalSystem
    WebClient                          -                                                              svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Wecsvc                               Windows                                                 svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    wercplsupport                          "     "  svchost.exe           6.1.7600.16385                       localSystem
    WerSvc                                Windows                                       svchost.exe           6.1.7600.16385                       localSystem
    WinDefend                           Windows                                                        svchost.exe           6.1.7600.16385                       LocalSystem
    WinHttpAutoProxySvc                   - WinHTTP                   svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    Winmgmt                              Windows                                       svchost.exe           6.1.7600.16385                       localSystem
    WinRM                                 Windows (WS-Management)                    svchost.exe           6.1.7600.16385                       NT AUTHORITY\NetworkService
    Wlansvc                              WLAN                                               svchost.exe           6.1.7600.16385                       LocalSystem
    wmiApSrv                           WMI Performance Adapter                                                 WmiApSrv.exe          6.1.7600.16385                 localSystem
    WMPNetworkSvc                           Windows Media               wmpnetwk.exe                                         NT AUTHORITY\NetworkService
    WPCSvc                             Parental Controls                                                       svchost.exe           6.1.7600.16385                       NT Authority\LocalService
    WPDBusEnum                                                           svchost.exe           6.1.7600.16385                       LocalSystem
    wscsvc                                                                         svchost.exe           6.1.7600.16385                       NT AUTHORITY\LocalService
    WSearch                            Windows Search                                                          SearchIndexer.exe     7.0.7601.17610                 LocalSystem
    wuauserv                             Windows                                                svchost.exe           6.1.7600.16385                       LocalSystem
    wudfsvc                            Windows Driver Foundation - User-mode Driver Framework                  svchost.exe           6.1.7600.16385                       LocalSystem
    WwanSvc                             WWAN                                                      svchost.exe           6.1.7600.16385                       NT Authority\LocalService


--------[  AX ]----------------------------------------------------------------------------------------------------

    bdaplgin.ax                6.1.7600.16385              Microsoft BDA Device Control Plug-in for MPEG2 based networks.
    g711codc.ax                6.1.7601.17514              Intel G711 CODEC
    iac25_32.ax                2.0.5.53                      Indeo audio
    ir41_32.ax                 4.51.16.3                   Intel Indeo Video 4.5
    ivfsrc.ax                  5.10.2.51                    Intel Indeo video IVF  5.10
    ksproxy.ax                 6.1.7601.17514              WDM Streaming ActiveMovie Proxy
    kstvtune.ax                6.1.7601.17514               - WDM
    kswdmcap.ax                6.1.7601.17514                WDM
    ksxbar.ax                  6.1.7601.17514              WDM Streaming Crossbar
    mpeg2data.ax               6.6.7601.17514              Microsoft MPEG-2 Section and Table Acquisition Module
    mpg2splt.ax                6.6.7601.17528              DirectShow MPEG-2 Splitter.
    msdvbnp.ax                 6.6.7601.17514              Microsoft Network Provider for MPEG2 based networks.
    msnp.ax                    6.6.7601.17514              Microsoft Network Provider for MPEG2 based networks.
    psisrndr.ax                6.6.7601.17669              Microsoft Transport Information Filter for MPEG2 based networks.
    v0330ext.ax                1.12.1.0                    DirectShow/VFW Extension property page
    vbicodec.ax                6.6.7601.17514              Microsoft VBI Codec
    vbisurf.ax                 6.1.7601.17514              VBI Surface Allocator Filter
    vidcap.ax                  6.1.7600.16385              Video Capture Interface Server
    wstpager.ax                6.6.7601.17514              Microsoft Teletext Server
    xvid.ax                                                


--------[  DLL ]---------------------------------------------------------------------------------------------------

    aaclient.dll               6.1.7601.17514              Anywhere access client
    accessibilitycpl.dll       6.1.7601.17514                 
    acctres.dll                6.1.7600.16385                     (Microsoft)
    acledit.dll                6.1.7600.16385                 ACL
    aclui.dll                  6.1.7600.16385                
    acppage.dll                6.1.7601.17514                  ""
    actioncenter.dll           6.1.7601.17514               
    actioncentercpl.dll        6.1.7601.17514                 
    activeds.dll               6.1.7601.17514               DLL   AD
    actxprxy.dll               6.1.7601.17514              ActiveX Interface Marshaling Library
    admparse.dll               8.0.7600.16385              IEAK Global Policy Template Parser
    admtmpl.dll                6.1.7601.17514               " "
    adprovider.dll             6.1.7601.18409               DLL adprovider
    adsldp.dll                 6.1.7601.17514              ADs LDAP Provider DLL
    adsldpc.dll                6.1.7600.16385               DLL  LDAP AD
    adsmsext.dll               6.1.7600.16385              ADs LDAP Provider DLL
    adsnt.dll                  6.1.7600.16385               DLL    Windows NT
    adtschema.dll              6.1.7601.18779                 
    advapi32.dll               6.1.7601.18247                API Windows 32
    advpack.dll                8.0.7600.16385              ADVPACK
    aecache.dll                6.1.7600.16385              AECache Sysprep Plugin
    aeevts.dll                 6.1.7600.16385                  
    alttab.dll                 6.1.7600.16385              Windows Shell Alt Tab
    amdpcom32.dll              8.14.10.23                  Radeon PCOM Universal Driver
    amstream.dll               6.6.7601.17514              DirectShow Runtime.
    amxread.dll                6.1.7600.16385              API Tracing Manifest Read Library
    anim.dll                   3.1.0.0                     Animation Core
    apds.dll                   6.1.7600.16385                  Microsoft
    apilogen.dll               6.1.7600.16385                 API
    api-ms-win-core-console-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-datetime-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-debug-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-delayload-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-errorhandling-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-fibers-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-file-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-handle-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-heap-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-interlocked-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-io-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-libraryloader-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-localization-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-localregistry-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-memory-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-misc-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-namedpipe-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-processenvironment-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-processthreads-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-profile-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-rtlsupport-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-string-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-synch-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-sysinfo-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-threadpool-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-util-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-core-xstate-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-downlevel-advapi32-l1-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-advapi32-l2-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-normaliz-l1-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-ole32-l1-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-shell32-l1-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-shlwapi-l1-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-shlwapi-l2-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-user32-l1-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-downlevel-version-l1-1-0.dll  6.2.9200.16492              ApiSet Stub DLL
    api-ms-win-security-base-l1-1-0.dll  6.1.7601.18229              ApiSet Stub DLL
    api-ms-win-security-lsalookup-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-security-sddl-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-core-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-management-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-management-l2-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    api-ms-win-service-winsvc-l1-1-0.dll  6.1.7600.16385              ApiSet Stub DLL
    apircl.dll                 6.1.7600.16385              Microsoft InfoTech IR Local DLL
    apisetschema.dll           6.1.7601.18741              ApiSet Schema DLL
    apphelp.dll                6.1.7601.17514                 
    apphlpdm.dll               6.1.7600.16385                 
    appidapi.dll               6.1.7601.18741               API-  
    appidpolicyengineapi.dll   6.1.7600.16385              AppId Policy Engine API Module
    appmgmts.dll               6.1.7600.16385                
    appmgr.dll                 6.1.7601.17514                 
    apss.dll                   6.1.7600.16385              Microsoft InfoTech Storage System Library
    asferror.dll               12.0.7600.16385               ASF
    aspnet_counters.dll        4.0.30319.34209             Microsoft ASP.NET Performance Counter Shim DLL
    asycfilt.dll               6.1.7601.17514              
    ati2edxx.dll               6.14.10.2514                ati2edxx
    atiadlxy.dll               6.14.10.1104                ADL
    aticalcl.dll               6.14.10.1734                ATI CAL compiler runtime
    aticaldd.dll               6.14.10.1734                ATI CAL DD
    aticalrt.dll               6.14.10.1734                ATI CAL runtime
    aticfx32.dll               8.17.10.1129                aticfx32.dll
    atidxx32.dll               8.17.10.436                 atidxx32.dll
    atigktxx.dll               8.14.1.6264                 atigktxx.dll
    atiglpxx.dll               8.14.1.6264                 atiglpxx.dll
    atimpc32.dll               8.14.10.23                  Radeon PCOM Universal Driver
    atioglxx.dll               6.14.10.11672               AMD OpenGL driver
    atiu9pag.dll               8.14.1.6264                 atiu9pag.dll
    atiumdag.dll               7.14.10.911                 atiumdag.dll
    atiumdmv.dll               7.14.10.184                 Radeon Video Acceleration Universal Driver
    atiumdva.dll               8.14.10.359                 Radeon Video Acceleration Universal Driver
    atiuxpag.dll               8.14.1.6264                 atiuxpag.dll
    atl.dll                    3.5.2284.0                  ATL Module for Windows XP (Unicode)
    atl100.dll                 10.0.40219.325              ATL Module for Windows
    atl110.dll                 11.0.60610.1                ATL Module for Windows
    atl70.dll                  7.0.9975.0                  ATL Module for Windows (Unicode)
    atl71.dll                  7.10.6101.0                 ATL Module for Windows (Unicode)
    atmfd.dll                  5.1.2.241                   Windows NT OpenType/Type 1 Font Driver
    atmlib.dll                 5.1.2.241                   Windows NT OpenType/Type 1 API Library.
    atrc.dll                   17.0.6.13                   Sony ATRAC3 Audio Codec for RealAudio 8(tm)
    audiodev.dll               6.1.7601.17514                   
    audioeng.dll               6.1.7601.18741              Audio Engine
    audiokse.dll               6.1.7601.18741              Audio Ks Endpoint
    audioses.dll               6.1.7601.18741                
    auditnativesnapin.dll      6.1.7600.16385                    
    auditpolicygpinterop.dll   6.1.7600.16385                 
    auditpolmsg.dll            6.1.7600.16385                MMC  
    authfwcfg.dll              6.1.7600.16385               Windows      
    authfwgp.dll               6.1.7600.16385               Windows c      
    authfwsnapin.dll           6.1.7601.17514              Microsoft.WindowsFirewall.SnapIn
    authfwwizfwk.dll           6.1.7600.16385              Wizard Framework
    authui.dll                 6.1.7601.18493                
    authz.dll                  6.1.7600.16385              Authorization Framework
    autoplay.dll               6.1.7601.17514               ( )
    auxiliarydisplayapi.dll    6.1.7600.16385              Microsoft Windows SideShow API
    auxiliarydisplaycpl.dll    6.1.7601.17514                Microsoft Windows SideShow
    avicap32.dll               6.1.7600.16385                 AVI
    avifil32.dll               6.1.7601.17514                 AVI
    avrt.dll                   6.1.7600.16385              Multimedia Realtime Runtime
    azroles.dll                6.1.7601.17514              azroles Module
    azroleui.dll               6.1.7601.17514               
    azsqlext.dll               6.1.7601.17514              AzMan Sql Audit Extended Stored Procedures Dll
    basecsp.dll                6.1.7601.17514                 - (Microsoft)
    batmeter.dll               6.1.7601.17514              Battery Meter Helper DLL
    bcrypt.dll                 6.1.7600.16385              Windows Cryptographic Primitives Library (Wow64)
    bcryptprimitives.dll       6.1.7600.16385              Windows Cryptographic Primitives Library
    bidispl.dll                6.1.7600.16385              Bidispl DLL
    binkw32.dll                1.5.21.0                    RAD Video Tools
    biocredprov.dll            6.1.7600.16385                 WinBio
    bitsperf.dll               7.5.7601.17514              Perfmon Counter Access
    bitsprx2.dll               7.5.7600.16385              Background Intelligent Transfer Service Proxy
    bitsprx3.dll               7.5.7600.16385              Background Intelligent Transfer Service 2.0 Proxy
    bitsprx4.dll               7.5.7600.16385              Background Intelligent Transfer Service 2.5 Proxy
    bitsprx5.dll               7.5.7600.16385              Background Intelligent Transfer Service 3.0 Proxy
    bitsprx6.dll               7.5.7600.16385              Background Intelligent Transfer Service 4.0 Proxy
    blackbox.dll               11.0.7601.18741             BlackBox DLL
    bootvid.dll                6.1.7600.16385              VGA Boot Driver
    browcli.dll                6.1.7601.17887              Browser Service Client DLL
    browseui.dll               6.1.7601.17514              Shell Browser UI Library
    btpanui.dll                6.1.7600.16385                Bluetooth   
    bwcontexthandler.dll       1.0.0.1                      ContextH
    bwunpairelevated.dll       6.1.7600.16385              BWUnpairElevated Proxy Dll
    c_g18030.dll               6.1.7600.16385              GB18030 DBCS-Unicode Conversion DLL
    c_is2022.dll               6.1.7600.16385              ISO-2022 Code Page Translation DLL
    c_iscii.dll                6.1.7601.17514              ISCII Code Page Translation DLL
    cabinet.dll                6.1.7601.17514              Microsoft Cabinet File API
    cabview.dll                6.1.7601.17514                 CAB-
    camcodec.dll               1.5.0.0                     CamStudio Lossless Video Codec
    capiprovider.dll           6.1.7601.18409               DLL capiprovider
    capisp.dll                 6.1.7600.16385              Sysprep cleanup dll for CAPI
    catsrv.dll                 2001.12.8530.16385          COM+ Configuration Catalog Server
    catsrvps.dll               2001.12.8530.16385          COM+ Configuration Catalog Server Proxy/Stub
    catsrvut.dll               2001.12.8530.16385          COM+ Configuration Catalog Server Utilities
    cca.dll                    6.6.7601.17514              CCA DirectShow Filter.
    cdosys.dll                 6.6.7601.17857              Microsoft CDO for Windows Library
    certcli.dll                6.1.7601.17514                 Microsoft Active Directory
    certcredprovider.dll       6.1.7600.16385                 
    certenc.dll                6.1.7601.18151              Active Directory Certificate Services Encoding
    certenroll.dll             6.1.7601.17514                  Active Directory Microsoft
    certenrollui.dll           6.1.7600.16385                  X509
    certmgr.dll                6.1.7601.17514                
    certpoleng.dll             6.1.7601.17514                
    cewmdm.dll                 12.0.7600.16385               Windows CE WMDM
    cfgbkend.dll               6.1.7600.16385              Configuration Backend Interface
    cfgmgr32.dll               6.1.7601.17621              Configuration Manager DLL
    cfhd.dll                   3.2.2.185                   CineForm VFW CODEC
    chsbrkr.dll                6.1.7600.16385              Simplified Chinese Word Breaker
    chtbrkr.dll                6.1.7600.16385              Chinese Traditional Word Breaker
    chxreadingstringime.dll    6.1.7600.16385              CHxReadingStringIME
    cic.dll                    6.1.7600.16385                CIC - MMC   
    clb.dll                    6.1.7600.16385                
    clbcatq.dll                2001.12.8530.16385          COM+ Configuration Catalog
    clfsw32.dll                6.1.7600.16385              Common Log Marshalling Win32 DLL
    cliconfg.dll               6.1.7600.16385              SQL Client Configuration Utility DLL
    clusapi.dll                6.1.7601.17514               API 
    cmcfg32.dll                7.2.7600.16385                  Microsoft
    cmdial32.dll               7.2.7600.16385               
    cmicryptinstall.dll        6.1.7600.16385              Installers for cryptographic elements of CMI objects
    cmifw.dll                  6.1.7600.16385              Windows Firewall rule configuration plug-in
    cmipnpinstall.dll          6.1.7600.16385              PNP plugin installer for CMI
    cmlua.dll                  7.2.7600.16385                API   
    cmpbk32.dll                7.2.7600.16385              Microsoft Connection Manager Phonebook
    cmstplua.dll               7.2.7600.16385                API      
    cmutil.dll                 7.2.7600.16385                  (Microsoft)
    cngaudit.dll               6.1.7600.16385              Windows Cryptographic Next Generation audit library
    cngprovider.dll            6.1.7601.18409               DLL cngprovider
    cnvfat.dll                 6.1.7600.16385              FAT File System Conversion Utility DLL
    colbact.dll                2001.12.8530.16385          COM+
    colorcnv.dll               6.1.7600.16385              Windows Media Color Conversion
    colorui.dll                6.1.7600.16385                 
    comcat.dll                 6.1.7600.16385              Microsoft Component Category Manager Library
    comctl32.dll               5.82.7601.18201                  
    comdlg32.dll               6.1.7601.17514                 
    compobj.dll                2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    compstui.dll               6.1.7600.16385                   
    comrepl.dll                2001.12.8530.16385          COM+
    comres.dll                 2001.12.8530.16385           COM+
    comsnap.dll                2001.12.8530.16385          COM+ Explorer MMC Snapin
    comsvcs.dll                2001.12.8530.16385          COM+ Services
    comuid.dll                 2001.12.8530.16385          COM+ Explorer UI
    connect.dll                6.1.7600.16385               
    console.dll                6.1.7600.16385                 
    cook.dll                   17.0.6.13                   Cooker G2 Audio Codec for RealAudio(tm)
    corpol.dll                 8.0.7600.16385              Microsoft COM Runtime Execution Engine
    cpfilters.dll              6.6.7601.17528               PTFilter & Encypter/Decrypter Tagger Filters.
    credssp.dll                6.1.7601.18779              Credential Delegation Security Package
    credui.dll                 6.1.7601.18276                 
    crtdll.dll                 4.0.1183.1                  Microsoft C Runtime Library
    crypt32.dll                6.1.7601.18741              API32 
    cryptbase.dll              6.1.7600.16385              Base cryptographic API DLL
    cryptdlg.dll               6.1.7601.18150                
    cryptdll.dll               6.1.7600.16385              Cryptography Manager
    cryptext.dll               6.1.7600.16385                
    cryptnet.dll               6.1.7601.18741              Crypto Network Related API
    cryptsp.dll                6.1.7601.18741              Cryptographic Service Provider API
    cryptsvc.dll               6.1.7601.18741               
    cryptui.dll                6.1.7601.18741                
    cryptxml.dll               6.1.7600.16385              API- XML DigSig
    cscapi.dll                 6.1.7601.17514              Offline Files Win32 API
    cscdll.dll                 6.1.7601.17514              Offline Files Temporary Shim
    cscobj.dll                 6.1.7601.17514               COM-   CSC API
    ctcammgr.dll               1.7.2.0                     Creative CamHAL Manager
    ctl3d32.dll                2.31.0.0                    Ctl3D 3D Windows Controls
    cximage.dll                5.9.9.3                     cximage
    d2d1.dll                   6.2.9200.16765               Microsoft D2D
    d3d10.dll                  6.2.9200.16492              Direct3D 10 Runtime
    d3d10_1.dll                6.2.9200.16492              Direct3D 10.1 Runtime
    d3d10_1core.dll            6.2.9200.16492              Direct3D 10.1 Runtime
    d3d10core.dll              6.2.9200.16492              Direct3D 10 Runtime
    d3d10level9.dll            6.2.9200.16492              Direct3D 10 to Direct3D9 Translation Runtime
    d3d10warp.dll              6.2.9200.17033              Direct3D 10 Rasterizer
    d3d11.dll                  6.2.9200.16570              Direct3D 11 Runtime
    d3d8.dll                   6.1.7600.16385              Microsoft Direct3D
    d3d8thk.dll                6.1.7600.16385              Microsoft Direct3D OS Thunk Layer
    d3d9.dll                   6.1.7601.17514              Direct3D 9 Runtime
    d3dcompiler_33.dll         9.18.904.15                 Microsoft Direct3D
    d3dcompiler_34.dll         9.19.949.46                 Microsoft Direct3D
    d3dcompiler_35.dll         9.19.949.1104               Microsoft Direct3D
    d3dcompiler_36.dll         9.19.949.2111               Microsoft Direct3D
    d3dcompiler_37.dll         9.22.949.2248               Microsoft Direct3D
    d3dcompiler_38.dll         9.23.949.2378               Microsoft Direct3D
    d3dcompiler_39.dll         9.24.949.2307               Microsoft Direct3D
    d3dcompiler_40.dll         9.24.950.2656               Direct3D HLSL Compiler
    d3dcompiler_41.dll         9.26.952.2844               Direct3D HLSL Compiler
    d3dcompiler_42.dll         9.27.952.3022               Direct3D HLSL Compiler
    d3dcompiler_43.dll         9.29.952.3111               Direct3D HLSL Compiler
    d3dcsx_42.dll              9.27.952.3022               Direct3D 10.1 Extensions
    d3dcsx_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dim.dll                  6.1.7600.16385              Microsoft Direct3D
    d3dim700.dll               6.1.7600.16385              Microsoft Direct3D
    d3dramp.dll                6.1.7600.16385              Microsoft Direct3D
    d3dx10.dll                 9.16.843.0                  Microsoft Direct3D
    d3dx10_33.dll              9.18.904.21                 Microsoft Direct3D
    d3dx10_34.dll              9.19.949.46                 Microsoft Direct3D
    d3dx10_35.dll              9.19.949.1104               Microsoft Direct3D
    d3dx10_36.dll              9.19.949.2009               Microsoft Direct3D
    d3dx10_37.dll              9.19.949.2187               Microsoft Direct3D
    d3dx10_38.dll              9.23.949.2378               Microsoft Direct3D
    d3dx10_39.dll              9.24.949.2307               Microsoft Direct3D
    d3dx10_40.dll              9.24.950.2656               Direct3D 10.1 Extensions
    d3dx10_41.dll              9.26.952.2844               Direct3D 10.1 Extensions
    d3dx10_42.dll              9.27.952.3001               Direct3D 10.1 Extensions
    d3dx10_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dx11_42.dll              9.27.952.3022               Direct3D 10.1 Extensions
    d3dx11_43.dll              9.29.952.3111               Direct3D 10.1 Extensions
    d3dx9_24.dll               9.5.132.0                   Microsoft DirectX for Windows
    d3dx9_25.dll               9.6.168.0                   Microsoft DirectX for Windows
    d3dx9_26.dll               9.7.239.0                   Microsoft DirectX for Windows
    d3dx9_27.dll               9.8.299.0                   Microsoft DirectX for Windows
    d3dx9_28.dll               9.10.455.0                  Microsoft DirectX for Windows
    d3dx9_29.dll               9.11.519.0                  Microsoft DirectX for Windows
    d3dx9_30.dll               9.12.589.0                  Microsoft DirectX for Windows
    d3dx9_31.dll               9.15.779.0                  Microsoft DirectX for Windows
    d3dx9_32.dll               9.16.843.0                  Microsoft DirectX for Windows
    d3dx9_33.dll               9.18.904.15                 Microsoft DirectX for Windows
    d3dx9_34.dll               9.19.949.46                 Microsoft DirectX for Windows
    d3dx9_35.dll               9.19.949.1104               Microsoft DirectX for Windows
    d3dx9_36.dll               9.19.949.2111               Microsoft DirectX for Windows
    d3dx9_37.dll               9.22.949.2248               Microsoft DirectX for Windows
    d3dx9_38.dll               9.23.949.2378               Microsoft DirectX for Windows
    d3dx9_39.dll               9.24.949.2307               Microsoft DirectX for Windows
    d3dx9_40.dll               9.24.950.2656               Direct3D 9 Extensions
    d3dx9_41.dll               9.26.952.2844               Direct3D 9 Extensions
    d3dx9_42.dll               9.27.952.3001               Direct3D 9 Extensions
    d3dx9_43.dll               9.29.952.3111               Direct3D 9 Extensions
    d3dxof.dll                 6.1.7600.16385              DirectX Files DLL
    dataclen.dll               6.1.7600.16385                 Windows
    davclnt.dll                6.1.7601.18201              Web DAV Client DLL
    davhlpr.dll                6.1.7600.16385              DAV Helper DLL
    dbgeng.dll                 6.1.7601.17514              Windows Symbolic Debugger Engine
    dbghelp.dll                6.1.7601.17514              Windows Image Helper
    dbnetlib.dll               6.1.7600.16385              Winsock Oriented Net DLL for SQL Clients
    dbnmpntw.dll               6.1.7600.16385              Named Pipes Net DLL for SQL Clients
    dciman32.dll               6.1.7601.18768              DCI Manager
    ddaclsys.dll               6.1.7600.16385              SysPrep module for Reseting Data Drive ACL 
    ddoiproxy.dll              6.1.7600.16385              DDOI Interface Proxy
    ddores.dll                 6.1.7600.16385                  
    ddraw.dll                  6.1.7600.16385              Microsoft DirectDraw
    ddrawex.dll                6.1.7600.16385              Direct Draw Ex
    defaultlocationcpl.dll     6.1.7601.17514               :   
    deskadp.dll                6.1.7600.16385                 
    deskmon.dll                6.1.7600.16385                
    deskperf.dll               6.1.7600.16385                
    devenum.dll                6.6.7600.16385               .
    devicecenter.dll           6.1.7601.17514                
    devicedisplaystatusmanager.dll  6.1.7600.16385              Device Display Status Manager
    devicemetadataparsers.dll  6.1.7600.16385              Common Device Metadata parsers
    devicepairing.dll          6.1.7600.16385               ,   
    devicepairingfolder.dll    6.1.7601.17514                 
    devicepairinghandler.dll   6.1.7600.16385              Device Pairing Handler Dll
    devicepairingproxy.dll     6.1.7600.16385              Device Pairing Proxy Dll
    deviceuxres.dll            6.1.7600.16385              Windows Device User Experience Resource File
    devmgr.dll                 6.1.7600.16385                 
    devobj.dll                 6.1.7601.17621              Device Information Set DLL
    devrtl.dll                 6.1.7601.17621              Device Management Run Time Library
    dfscli.dll                 6.1.7600.16385              Windows NT Distributed File System Client DLL
    dfshim.dll                 4.0.41210.0                 ClickOnce Application Deployment Support Library
    dfsshlex.dll               6.1.7600.16385                   DFS
    dhcpcmonitor.dll           6.1.7600.16385               (DLL)   DHCP
    dhcpcore.dll               6.1.7601.17514               DHCP-
    dhcpcore6.dll              6.1.7601.17970               DHCPv6
    dhcpcsvc.dll               6.1.7600.16385               DHCP-
    dhcpcsvc6.dll              6.1.7601.17970               DHCPv6
    dhcpqec.dll                6.1.7600.16385                   Microsoft DHCP
    dhcpsapi.dll               6.1.7600.16385               API  DHCP-c
    difxapi.dll                2.1.0.0                     Driver Install Frameworks for API library module
    dimsjob.dll                6.1.7600.16385               DLL  DIMS
    dimsroam.dll               6.1.7601.18409               DLL  DIMS  
    dinput.dll                 6.1.7600.16385              Microsoft DirectInput
    dinput8.dll                6.1.7600.16385              Microsoft DirectInput
    directdb.dll               6.1.7600.16385              Microsoft Direct Database API
    diskcopy.dll               6.1.7600.16385              Windows DiskCopy
    dispex.dll                 5.8.7600.16385              Microsoft  DispEx
    display.dll                6.1.7601.17514                
    dmband.dll                 6.1.7600.16385              Microsoft DirectMusic Band
    dmcompos.dll               6.1.7600.16385              Microsoft DirectMusic Composer
    dmdlgs.dll                 6.1.7600.16385              Disk Management Snap-in Dialogs
    dmdskmgr.dll               6.1.7600.16385              Disk Management Snap-in Support Library
    dmdskres.dll               6.1.7600.16385                 
    dmdskres2.dll              6.1.7600.16385                 
    dmime.dll                  6.1.7600.16385              Microsoft DirectMusic Interactive Engine
    dmintf.dll                 6.1.7600.16385              Disk Management DCOM Interface Stub
    dmloader.dll               6.1.7600.16385              Microsoft DirectMusic Loader
    dmocx.dll                  6.1.7600.16385              TreeView OCX
    dmrc.dll                   6.1.7600.16385              Windows MRC
    dmscript.dll               6.1.7600.16385              Microsoft DirectMusic Scripting
    dmstyle.dll                6.1.7600.16385              Microsoft DirectMusic Style Engline
    dmsynth.dll                6.1.7600.16385              Microsoft DirectMusic Software Synthesizer
    dmusic.dll                 6.1.7600.16385                Microsoft DirectMusic
    dmutil.dll                 6.1.7600.16385                 
    dmvdsitf.dll               6.1.7600.16385              Disk Management Snap-in Support Library
    dnet.dll                   6.0.7.5189                  DolbyNet(tm) Audio Codec for RealAudio(tm)
    dnsapi.dll                 6.1.7601.17570                API DNS-
    dnscmmc.dll                6.1.7601.17514               DLL  DNS  MMC
    dnssd.dll                  3.0.0.10                    Bonjour Client Library
    dnssdx.dll                 3.0.0.10                    Bonjour COM Component Library
    docprop.dll                6.1.7600.16385                OLE
    dot3api.dll                6.1.7601.17514              802.3 Autoconfiguration API
    dot3cfg.dll                6.1.7601.17514               Netsh  802.3
    dot3dlg.dll                6.1.7600.16385                UI  802.3
    dot3gpclnt.dll             6.1.7600.16385                   802.3
    dot3gpui.dll               6.1.7600.16385               "   802.3"
    dot3hc.dll                 6.1.7600.16385                 Dot3
    dot3msm.dll                6.1.7601.17514                   802.3
    dot3ui.dll                 6.1.7601.17514                802.3
    dpapiprovider.dll          6.1.7601.18409               DLL dpapiprovider
    dplayx.dll                 6.1.7600.16385              Microsoft DirectPlay
    dpmodemx.dll               6.1.7600.16385                      DirectPlay
    dpnaddr.dll                6.1.7601.17514              Microsoft DirectPlay8 Address
    dpnathlp.dll               6.1.7600.16385              Microsoft DirectPlay NAT Helper UPnP
    dpnet.dll                  6.1.7601.17989              Microsoft DirectPlay
    dpnhpast.dll               6.1.7600.16385              Microsoft DirectPlay NAT Helper PAST
    dpnhupnp.dll               6.1.7600.16385              Microsoft DirectPlay NAT Helper UPNP
    dpnlobby.dll               6.1.7600.16385              Microsoft DirectPlay8 Lobby
    dpwsockx.dll               6.1.7600.16385                  TCP/IP  IPX  DirectPlay
    dpx.dll                    6.1.7601.17514              Microsoft(R) Delta Package Expander
    drmmgrtn.dll               11.0.7601.18741             DRM Migration DLL
    drmv2clt.dll               11.0.7601.18741             DRMv2 Client DLL
    drprov.dll                 6.1.7600.16385                   ,        ()
    drt.dll                    6.1.7600.16385                
    drtprov.dll                6.1.7600.16385              Distributed Routing Table Providers
    drttransport.dll           6.1.7600.16385              Distributed Routing Table Transport Provider
    drv1.dll                   17.0.6.13                   RealVideo 1.0
    drv2.dll                   17.0.6.13                   RealVideo G2
    drvc.dll                   17.0.6.13                   RealVideo 8+9
    drvstore.dll               6.1.7601.17514              Driver Store API
    ds32gt.dll                 6.1.7600.16385              ODBC Driver Setup Generic Thunk
    dsauth.dll                 6.1.7601.17514              DS Authorization for Services
    dsdmo.dll                  6.1.7600.16385              DirectSound Effects
    dshowrdpfilter.dll         1.0.0.0                           ()
    dskquota.dll               6.1.7600.16385               DLL    Windows
    dskquoui.dll               6.1.7601.17514               DLL   
    dsound.dll                 6.1.7600.16385              DirectSound
    dsprop.dll                 6.1.7600.16385                Active Directory
    dsquery.dll                6.1.7600.16385                 
    dsrole.dll                 6.1.7600.16385              DS Role Client DLL
    dssec.dll                  6.1.7600.16385                 
    dssenh.dll                 6.1.7600.16385              Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider
    dsuiext.dll                6.1.7601.17514                 
    dswave.dll                 6.1.7600.16385              Microsoft DirectMusic Wave
    dtsh.dll                   6.1.7600.16385               API     
    dui70.dll                  6.1.7600.16385               DirectUI Windows
    duser.dll                  6.1.7600.16385              Windows DirectUser Engine
    dwmapi.dll                 6.1.7600.16385               API     ()
    dwmcore.dll                6.1.7601.17514                Microsoft DWM
    dwrite.dll                 6.2.9200.16571               Microsoft DirectX Typography
    dxdiagn.dll                6.1.7601.17514                Microsoft DirectX
    dxgi.dll                   6.2.9200.16492              DirectX Graphics Infrastructure
    dxmasf.dll                 12.0.7601.18741             Microsoft Windows Media Component Removal File.
    dxptaskringtone.dll        6.1.7601.17514                 Microsoft
    dxptasksync.dll            6.1.7601.17514               Microsoft Windows DXP
    dxtmsft.dll                11.0.9600.17690             DirectX Media -- Image DirectX Transforms
    dxtrans.dll                11.0.9600.17690             DirectX Media -- DirectX Transform Core
    dxva2.dll                  6.1.7600.16385              DirectX Video Acceleration 2.0 DLL
    eapp3hst.dll               6.1.7601.17514              Microsoft ThirdPartyEapDispatcher
    eappcfg.dll                6.1.7600.16385                EAP
    eappgnui.dll               6.1.7601.17514                 EAP
    eapphost.dll               6.1.7601.17514                 EAPHost 
    eappprxy.dll               6.1.7600.16385              Microsoft EAPHost Peer Client DLL
    eapqec.dll                 6.1.7600.16385                   Microsoft EAP
    efsadu.dll                 6.1.7600.16385                
    efscore.dll                6.1.7601.17514              EFS Core Library
    efsutil.dll                6.1.7600.16385              EFS Utility Library
    ehstorapi.dll              6.1.7601.17514              Windows Enhanced Storage API
    ehstorpwdmgr.dll           6.1.7600.16385                Windows Enhanced Storage
    ehstorshell.dll            6.1.7600.16385               DLL   Windows Enhanced Storage
    els.dll                    6.1.7600.16385                
    elscore.dll                6.1.7600.16385               DLL   Els
    elshyph.dll                6.3.9600.16428              ELS Hyphenation Service
    elslad.dll                 6.1.7600.16385              ELS Language Detection
    elstrans.dll               6.1.7601.17514              ELS Transliteration Service
    encapi.dll                 6.1.7600.16385              Encoder API
    encdec.dll                 6.6.7601.17708                XDS     .
    eqossnap.dll               6.1.7600.16385                EQoS
    es.dll                     2001.12.8530.16385          COM+
    esent.dll                  6.1.7601.17577                  ESE  Microsoft(R) Windows(R)
    esentprf.dll               6.1.7600.16385              Extensible Storage Engine Performance Monitoring Library for Microsoft(R) Windows(R)
    eventcls.dll               6.1.7600.16385              Microsoft Volume Shadow Copy Service event class
    evr.dll                    6.1.7601.18741                DLL   
    explorerframe.dll          6.1.7601.17514              ExplorerFrame
    expsrv.dll                 6.0.72.9589                 Visual Basic for Applications Runtime - Expression Service
    f3ahvoas.dll               6.1.7600.16385              JP Japanese Keyboard Layout for Fujitsu FMV oyayubi-shift keyboard
    faultrep.dll               6.1.7601.17514                     Windows
    fdbth.dll                  6.1.7600.16385              Function Discovery Bluetooth Provider Dll
    fdbthproxy.dll             6.1.7600.16385              Bluetooth Provider Proxy Dll
    fde.dll                    6.1.7601.17514                 
    fdeploy.dll                6.1.7601.17514                  
    fdpnp.dll                  6.1.7600.16385              Pnp Provider Dll
    fdproxy.dll                6.1.7600.16385              Function Discovery Proxy Dll
    fdssdp.dll                 6.1.7600.16385              Function Discovery SSDP Provider Dll
    fdwcn.dll                  6.1.7600.16385              Windows Connect Now - Config Function Discovery Provider DLL
    fdwnet.dll                 6.1.7600.16385              Function Discovery WNet Provider Dll
    fdwsd.dll                  6.1.7600.16385              Function Discovery WS Discovery Provider Dll
    feclient.dll               6.1.7600.16385              Windows NT File Encryption Client Interfaces
    ff_vfw.dll                 1.3.4530.0                  ffdshow VFW
    filemgmt.dll               6.1.7600.16385                 
    findnetprinters.dll        6.1.7600.16385              Find Network Printers COM Component
    firewallapi.dll            6.1.7600.16385              API  Windows
    firewallcontrolpanel.dll   6.1.7601.17514                -  Windows
    fltlib.dll                 6.1.7600.16385               
    fm20.dll                   15.0.4687.1000              Microsoft Forms DLL
    fm20enu.dll                15.0.4420.1017              Microsoft Forms International DLL
    fmifs.dll                  6.1.7600.16385              FM IFS Utility DLL
    fms.dll                    1.1.6000.16384                
    fontext.dll                6.1.7601.17514                Windows
    fontsub.dll                6.1.7601.18768              Font Subsetting DLL
    fphc.dll                   6.1.7601.17514               Filtering Platform Helper
    framedyn.dll               6.1.7601.17514              WMI SDK Provider Framework
    framedynos.dll             6.1.7601.17514              WMI SDK Provider Framework
    fthsvc.dll                 6.1.7600.16385                  Microsoft Windows
    fundisc.dll                6.1.7600.16385              DLL  
    fwcfg.dll                  6.1.7600.16385                  Windows
    fwpuclnt.dll               6.1.7601.18283              API   FWP/IPsec
    fwremotesvr.dll            6.1.7600.16385              Windows Firewall Remote APIs Server
    fxsapi.dll                 6.1.7600.16385              Microsoft  Fax API Support DLL
    fxscom.dll                 6.1.7600.16385              Microsoft Fax Server COM Client Interface
    fxscomex.dll               6.1.7600.16385              Microsoft Fax Server Extended COM Client Interface
    fxsext32.dll               6.1.7600.16385              Microsoft  Fax Exchange Command Extension
    fxsresm.dll                6.1.7600.16385               DLL   (Microsoft)
    fxsxp32.dll                6.1.7600.16385              Microsoft  Fax Transport Provider
    gameux.dll                 6.1.7601.18020               
    gameuxlegacygdfs.dll       1.0.0.1                     Legacy GDF resource DLL
    gcdef.dll                  6.1.7600.16385                   
    gdi32.dll                  6.1.7601.18577              GDI Client DLL
    gdiplus.dll                6.1.7601.18455              Microsoft GDI+
    gearaspi.dll               2.1.3.1                     GEARAspi
    geocodec.dll               8.4.0.0                     GeoVision(R) Codec
    geocodec_readonly.dll      8.4.0.0                     GeoVision(R) Codec
    geocodecd.dll              8.4.0.0                     GeoVision(R) Codec
    getuname.dll               6.1.7600.16385                   UCE
    glmf32.dll                 6.1.7600.16385              OpenGL Metafiling DLL
    glu32.dll                  6.1.7600.16385                OpenGL
    gpapi.dll                  6.1.7600.16385                API  
    gpedit.dll                 6.1.7600.16385              GPEdit
    gpprefcl.dll               6.1.7601.17514                 
    gpprnext.dll               6.1.7600.16385                 
    gpscript.dll               6.1.7600.16385                
    gptext.dll                 6.1.7600.16385              GPTExt
    hbaapi.dll                 6.1.7601.17514              HBA API data interface dll for HBA_API_Rev_2-18_2002MAR1.doc
    hcproviders.dll            6.1.7600.16385                
    helppaneproxy.dll          6.1.7600.16385              Microsoft Help Proxy
    hgcpl.dll                  6.1.7601.17514                 
    hhsetup.dll                6.1.7600.16385              Microsoft HTML Help
    hid.dll                    6.1.7600.16385                HID
    hidserv.dll                6.1.7600.16385               HID
    hlink.dll                  6.1.7600.16385               Microsoft Office 2000
    hnetcfg.dll                6.1.7600.16385                 
    hnetmon.dll                6.1.7600.16385              DLL   
    httpapi.dll                6.1.7601.17514              HTTP Protocol Stack API
    htui.dll                   6.1.7600.16385                  
    ias.dll                    6.1.7600.16385                 (NPS)
    iasacct.dll                6.1.7601.17514                NPS
    iasads.dll                 6.1.7600.16385                Active Directory NPS
    iasdatastore.dll           6.1.7600.16385              NPS Datastore server
    iashlpr.dll                6.1.7600.16385                NPS
    iasmigplugin.dll           6.1.7600.16385              NPS Migration DLL
    iasnap.dll                 6.1.7600.16385              NPS NAP Provider
    iaspolcy.dll               6.1.7600.16385              NPS Pipeline
    iasrad.dll                 6.1.7601.17514                RADIUS NPS
    iasrecst.dll               6.1.7601.17514              NPS XML Datastore Access
    iassam.dll                 6.1.7600.16385              NPS NT SAM Provider
    iassdo.dll                 6.1.7600.16385               SDO NPS
    iassvcs.dll                6.1.7600.16385                NPS
    icardie.dll                11.0.9600.16428             Microsoft Information Card IE Helper
    icardres.dll               3.0.4506.5464               Windows CardSpace
    iccvid.dll                 1.10.0.13                    Cinepak
    icm32.dll                  6.1.7600.16385              Microsoft Color Management Module (CMM)
    icmp.dll                   6.1.7600.16385              ICMP DLL
    icmui.dll                  6.1.7600.16385                  
    iconcodecservice.dll       6.1.7600.16385              Converts a PNG part of the icon to a legacy bmp icon
    icsigd.dll                 6.1.7600.16385                 
    idndl.dll                  6.1.7600.16385              Downlevel DLL
    idstore.dll                6.1.7600.16385              Identity Store
    ieadvpack.dll              11.0.9600.16428             ADVPACK
    ieakeng.dll                8.0.7600.16385              Internet Explorer Administration Kit Engine Library
    ieaksie.dll                8.0.7600.16385              Internet Explorer Snap-in Extension to Group Policy
    ieakui.dll                 8.0.7600.16385              Microsoft IEAK Shared UI DLL
    ieapfltr.dll               11.0.9600.17689             Microsoft SmartScreen Filter
    iedkcs32.dll               18.0.9600.17689               IEAK
    ieetwproxystub.dll         11.0.9600.17689             IE ETW Collector Proxy Stub Resources
    ieframe.dll                11.0.9600.17690             
    iepeers.dll                11.0.9600.16428             Peer- Internet Explorer
    iernonce.dll               11.0.9600.17689               RunOnce   
    iertutil.dll               11.0.9600.17689             Run time utility for Internet Explorer
    iesetup.dll                11.0.9600.17689               IOD
    iesysprep.dll              11.0.9600.16428             IE Sysprep Provider
    ieui.dll                   11.0.9600.17689                Internet Explorer
    ifmon.dll                  6.1.7600.16385                IF
    ifsutil.dll                6.1.7601.17514              IFS Utility DLL
    ifsutilx.dll               6.1.7600.16385              IFS Utility Extension DLL
    imagehlp.dll               6.1.7601.18288              Windows NT Image Helper
    imageres.dll               6.1.7600.16385              Windows Image Resource
    imagesp1.dll               6.1.7600.16385              Windows SP1 Image Resource
    imapi.dll                  6.1.7600.16385               Image Mastering API
    imapi2.dll                 6.1.7601.17514              IMAPI  2
    imapi2fs.dll               6.1.7601.17514              Image Mastering File System Imaging API v2
    imgutil.dll                11.0.9600.16428             IE plugin image decoder support DLL
    imjp10k.dll                10.1.7601.18556             Microsoft IME
    imm32.dll                  6.1.7601.17514              Multi-User Windows IMM32 API Client DLL
    inetcomm.dll               6.1.7601.17609              Microsoft Internet Messaging API Resources
    inetmib1.dll               6.1.7601.17514              Microsoft MIB-II subagent
    inetres.dll                6.1.7600.16385               API  
    infocardapi.dll            3.0.4506.5461               Microsoft InfoCards
    inked.dll                  6.1.7600.16385              Microsoft Tablet PC InkEdit Control
    input.dll                  6.1.7601.17514               DLL  
    inseng.dll                 11.0.9600.16428              
    iologmsg.dll               6.1.7601.18386                /
    ipbusenumproxy.dll         6.1.7600.16385              Associated Device Presence Proxy Dll
    iphlpapi.dll               6.1.7601.17514              IP Helper API
    iprop.dll                  6.1.7600.16385              OLE PropertySet Implementation
    iprtprio.dll               6.1.7600.16385              IP Routing Protocol Priority DLL
    iprtrmgr.dll               6.1.7601.17514               IP-
    ipsecsnp.dll               6.1.7600.16385                 IP-
    ipsmsnap.dll               6.1.7601.17514                IP-
    ir32_32.dll                3.24.15.3                   32-  Intel Indeo(R) Video R3.2
    ir41_32.dll                4.11.15.94                  Intel Indeo(R) Video Interactive 32-bit Driver
    ir41_qc.dll                4.30.62.2                   Intel Indeo Video Interactive Quick Compressor
    ir41_qcx.dll               4.30.62.2                   Intel Indeo Video Interactive Quick Compressor
    ir50_32.dll                5.2562.15.55                Intel Indeo video 5.10
    ir50_qc.dll                5.0.63.48                   Intel Indeo video 5.10 Quick Compressor
    ir50_qcx.dll               5.0.63.48                   Intel Indeo video 5.10 Quick Compressor
    irclass.dll                6.1.7600.16385                 
    iscsicpl.dll               5.2.3790.1830                   iSCSI
    iscsidsc.dll               6.1.7600.16385              API-  iSCSI
    iscsied.dll                6.1.7600.16385              iSCSI Extension DLL
    iscsium.dll                6.1.7601.17514              iSCSI Discovery api
    iscsiwmi.dll               6.1.7600.16385              MS iSCSI Initiator WMI Provider
    itircl.dll                 6.1.7601.17514              Microsoft InfoTech IR Local DLL
    itss.dll                   6.1.7600.16385              Microsoft InfoTech Storage System Library
    itvdata.dll                6.6.7601.17514              iTV Data Filters.
    iyuv_32.dll                6.1.7601.17514              Intel Indeo(R) Video YUV 
    javascriptcollectionagent.dll  11.0.9600.17689             JavaScript Performance Collection Agent
    jdns_sd.dll                3.0.0.10                    Bonjour support for Java
    jscript.dll                5.8.9600.16428              Microsoft  JScript
    jscript9.dll               11.0.9600.17689             Microsoft  JScript
    jscript9diag.dll           11.0.9600.17689             Microsoft  JScript Diagnostics
    jsintl.dll                 6.3.9600.16428              Windows Globalization
    jsproxy.dll                11.0.9600.17689             JScript Proxy Auto-Configuration
    kbd101.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for 101
    kbd101a.dll                6.1.7600.16385              KO Hangeul Keyboard Layout for 101 (Type A)
    kbd101b.dll                6.1.7600.16385              KO Hangeul Keyboard Layout for 101(Type B)
    kbd101c.dll                6.1.7600.16385              KO Hangeul Keyboard Layout for 101(Type C)
    kbd103.dll                 6.1.7600.16385              KO Hangeul Keyboard Layout for 103
    kbd106.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for 106
    kbd106n.dll                6.1.7600.16385              JP Japanese Keyboard Layout for 106
    kbda1.dll                  6.1.7600.16385              Arabic_English_101 Keyboard Layout
    kbda2.dll                  6.1.7600.16385              Arabic_2 Keyboard Layout
    kbda3.dll                  6.1.7600.16385              Arabic_French_102 Keyboard Layout
    kbdal.dll                  6.1.7600.16385              Albania Keyboard Layout
    kbdarme.dll                6.1.7600.16385              Eastern Armenian Keyboard Layout
    kbdarmw.dll                6.1.7600.16385              Western Armenian Keyboard Layout
    kbdax2.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for AX2
    kbdaze.dll                 6.1.7600.16385              Azerbaijan_Cyrillic Keyboard Layout
    kbdazel.dll                6.1.7600.16385              Azeri-Latin Keyboard Layout
    kbdbash.dll                6.1.7601.18528              Bashkir Keyboard Layout
    kbdbe.dll                  6.1.7600.16385              Belgian Keyboard Layout
    kbdbene.dll                6.1.7600.16385              Belgian Dutch Keyboard Layout
    kbdbgph.dll                6.1.7600.16385              Bulgarian Phonetic Keyboard Layout
    kbdbgph1.dll               6.1.7600.16385              Bulgarian (Phonetic Traditional) Keyboard Layout
    kbdbhc.dll                 6.1.7600.16385              Bosnian (Cyrillic) Keyboard Layout
    kbdblr.dll                 6.1.7601.17514              Belarusian Keyboard Layout
    kbdbr.dll                  6.1.7600.16385              Brazilian Keyboard Layout
    kbdbu.dll                  6.1.7600.16385              Bulgarian (Typewriter) Keyboard Layout
    kbdbulg.dll                6.1.7601.17514              Bulgarian Keyboard Layout
    kbdca.dll                  6.1.7600.16385              Canadian Multilingual Keyboard Layout
    kbdcan.dll                 6.1.7600.16385              Canadian Multilingual Standard Keyboard Layout
    kbdcr.dll                  6.1.7600.16385              Croatian/Slovenian Keyboard Layout
    kbdcz.dll                  6.1.7600.16385              Czech Keyboard Layout
    kbdcz1.dll                 6.1.7601.17514              Czech_101 Keyboard Layout
    kbdcz2.dll                 6.1.7600.16385              Czech_Programmer's Keyboard Layout
    kbdda.dll                  6.1.7600.16385              Danish Keyboard Layout
    kbddiv1.dll                6.1.7600.16385              Divehi Phonetic Keyboard Layout
    kbddiv2.dll                6.1.7600.16385              Divehi Typewriter Keyboard Layout
    kbddv.dll                  6.1.7600.16385              Dvorak US English Keyboard Layout
    kbdes.dll                  6.1.7600.16385              Spanish Alernate Keyboard Layout
    kbdest.dll                 6.1.7600.16385              Estonia Keyboard Layout
    kbdfa.dll                  6.1.7600.16385              Persian Keyboard Layout
    kbdfc.dll                  6.1.7600.16385              Canadian French Keyboard Layout
    kbdfi.dll                  6.1.7600.16385              Finnish Keyboard Layout
    kbdfi1.dll                 6.1.7600.16385              Finnish-Swedish with Sami Keyboard Layout
    kbdfo.dll                  6.1.7600.16385              F?roese Keyboard Layout
    kbdfr.dll                  6.1.7600.16385              French Keyboard Layout
    kbdgae.dll                 6.1.7600.16385              Gaelic Keyboard Layout
    kbdgeo.dll                 6.1.7601.17514              Georgian Keyboard Layout
    kbdgeoer.dll               6.1.7600.16385              Georgian (Ergonomic) Keyboard Layout
    kbdgeoqw.dll               6.1.7600.16385              Georgian (QWERTY) Keyboard Layout
    kbdgkl.dll                 6.1.7601.17514              Greek_Latin Keyboard Layout
    kbdgr.dll                  6.1.7600.16385              German Keyboard Layout
    kbdgr1.dll                 6.1.7601.17514              German_IBM Keyboard Layout
    kbdgrlnd.dll               6.1.7600.16385              Greenlandic Keyboard Layout
    kbdhau.dll                 6.1.7600.16385              Hausa Keyboard Layout
    kbdhe.dll                  6.1.7600.16385              Greek Keyboard Layout
    kbdhe220.dll               6.1.7600.16385              Greek IBM 220 Keyboard Layout
    kbdhe319.dll               6.1.7600.16385              Greek IBM 319 Keyboard Layout
    kbdheb.dll                 6.1.7600.16385              KBDHEB Keyboard Layout
    kbdhela2.dll               6.1.7600.16385              Greek IBM 220 Latin Keyboard Layout
    kbdhela3.dll               6.1.7600.16385              Greek IBM 319 Latin Keyboard Layout
    kbdhept.dll                6.1.7600.16385              Greek_Polytonic Keyboard Layout
    kbdhu.dll                  6.1.7600.16385              Hungarian Keyboard Layout
    kbdhu1.dll                 6.1.7600.16385              Hungarian 101-key Keyboard Layout
    kbdibm02.dll               6.1.7600.16385              JP Japanese Keyboard Layout for IBM 5576-002/003
    kbdibo.dll                 6.1.7600.16385              Igbo Keyboard Layout
    kbdic.dll                  6.1.7600.16385              Icelandic Keyboard Layout
    kbdinasa.dll               6.1.7600.16385              Assamese (Inscript) Keyboard Layout
    kbdinbe1.dll               6.1.7600.16385              Bengali - Inscript (Legacy) Keyboard Layout
    kbdinbe2.dll               6.1.7600.16385              Bengali (Inscript) Keyboard Layout
    kbdinben.dll               6.1.7601.17514              Bengali Keyboard Layout
    kbdindev.dll               6.1.7600.16385              Devanagari Keyboard Layout
    kbdinguj.dll               6.1.7600.16385              Gujarati Keyboard Layout
    kbdinhin.dll               6.1.7601.17514              Hindi Keyboard Layout
    kbdinkan.dll               6.1.7601.17514              Kannada Keyboard Layout
    kbdinmal.dll               6.1.7600.16385              Malayalam Keyboard Layout Keyboard Layout
    kbdinmar.dll               6.1.7601.17514              Marathi Keyboard Layout
    kbdinori.dll               6.1.7601.17514              Oriya Keyboard Layout
    kbdinpun.dll               6.1.7600.16385              Punjabi/Gurmukhi Keyboard Layout
    kbdintam.dll               6.1.7601.17514              Tamil Keyboard Layout
    kbdintel.dll               6.1.7601.17514              Telugu Keyboard Layout
    kbdinuk2.dll               6.1.7600.16385              Inuktitut Naqittaut Keyboard Layout
    kbdir.dll                  6.1.7600.16385              Irish Keyboard Layout
    kbdit.dll                  6.1.7600.16385              Italian Keyboard Layout
    kbdit142.dll               6.1.7600.16385              Italian 142 Keyboard Layout
    kbdiulat.dll               6.1.7600.16385              Inuktitut Latin Keyboard Layout
    kbdjpn.dll                 6.1.7600.16385              JP Japanese Keyboard Layout Stub driver
    kbdkaz.dll                 6.1.7600.16385              Kazak_Cyrillic Keyboard Layout
    kbdkhmr.dll                6.1.7600.16385              Cambodian Standard Keyboard Layout
    kbdkor.dll                 6.1.7600.16385              KO Hangeul Keyboard Layout Stub driver
    kbdkyr.dll                 6.1.7600.16385              Kyrgyz Keyboard Layout
    kbdla.dll                  6.1.7600.16385              Latin-American Spanish Keyboard Layout
    kbdlao.dll                 6.1.7600.16385              Lao Standard Keyboard Layout
    kbdlk41a.dll               6.1.7601.17514              DEC LK411-AJ Keyboard Layout
    kbdlt.dll                  6.1.7600.16385              Lithuania Keyboard Layout
    kbdlt1.dll                 6.1.7601.17514              Lithuanian Keyboard Layout
    kbdlt2.dll                 6.1.7600.16385              Lithuanian Standard Keyboard Layout
    kbdlv.dll                  6.1.7600.16385              Latvia Keyboard Layout
    kbdlv1.dll                 6.1.7600.16385              Latvia-QWERTY Keyboard Layout
    kbdmac.dll                 6.1.7600.16385              Macedonian (FYROM) Keyboard Layout
    kbdmacst.dll               6.1.7600.16385              Macedonian (FYROM) - Standard Keyboard Layout
    kbdmaori.dll               6.1.7601.17514              Maori Keyboard Layout
    kbdmlt47.dll               6.1.7600.16385              Maltese 47-key Keyboard Layout
    kbdmlt48.dll               6.1.7600.16385              Maltese 48-key Keyboard Layout
    kbdmon.dll                 6.1.7601.17514              Mongolian Keyboard Layout
    kbdmonmo.dll               6.1.7600.16385              Mongolian (Mongolian Script) Keyboard Layout
    kbdne.dll                  6.1.7600.16385              Dutch Keyboard Layout
    kbdnec.dll                 6.1.7600.16385              JP Japanese Keyboard Layout for (NEC PC-9800)
    kbdnec95.dll               6.1.7600.16385              JP Japanese Keyboard Layout for (NEC PC-9800 Windows 95)
    kbdnecat.dll               6.1.7600.16385              JP Japanese Keyboard Layout for (NEC PC-9800 on PC98-NX)
    kbdnecnt.dll               6.1.7600.16385              JP Japanese NEC PC-9800 Keyboard Layout
    kbdnepr.dll                6.1.7601.17514              Nepali Keyboard Layout
    kbdno.dll                  6.1.7600.16385              Norwegian Keyboard Layout
    kbdno1.dll                 6.1.7600.16385              Norwegian with Sami Keyboard Layout
    kbdnso.dll                 6.1.7600.16385              Sesotho sa Leboa Keyboard Layout
    kbdpash.dll                6.1.7600.16385              Pashto (Afghanistan) Keyboard Layout
    kbdpl.dll                  6.1.7600.16385              Polish Keyboard Layout
    kbdpl1.dll                 6.1.7600.16385              Polish Programmer's Keyboard Layout
    kbdpo.dll                  6.1.7601.17514              Portuguese Keyboard Layout
    kbdro.dll                  6.1.7600.16385              Romanian (Legacy) Keyboard Layout
    kbdropr.dll                6.1.7600.16385              Romanian (Programmers) Keyboard Layout
    kbdrost.dll                6.1.7600.16385              Romanian (Standard) Keyboard Layout
    kbdru.dll                  6.1.7601.18528              Russian Keyboard Layout
    kbdru1.dll                 6.1.7601.18528              Russia(Typewriter) Keyboard Layout
    kbdsf.dll                  6.1.7601.17514              Swiss French Keyboard Layout
    kbdsg.dll                  6.1.7601.17514              Swiss German Keyboard Layout
    kbdsl.dll                  6.1.7600.16385              Slovak Keyboard Layout
    kbdsl1.dll                 6.1.7600.16385              Slovak(QWERTY) Keyboard Layout
    kbdsmsfi.dll               6.1.7600.16385              Sami Extended Finland-Sweden Keyboard Layout
    kbdsmsno.dll               6.1.7600.16385              Sami Extended Norway Keyboard Layout
    kbdsn1.dll                 6.1.7600.16385              Sinhala Keyboard Layout
    kbdsorex.dll               6.1.7600.16385              Sorbian Extended Keyboard Layout
    kbdsors1.dll               6.1.7600.16385              Sorbian Standard Keyboard Layout
    kbdsorst.dll               6.1.7600.16385              Sorbian Standard (Legacy) Keyboard Layout
    kbdsp.dll                  6.1.7600.16385              Spanish Keyboard Layout
    kbdsw.dll                  6.1.7600.16385              Swedish Keyboard Layout
    kbdsw09.dll                6.1.7600.16385              Sinhala - Wij 9 Keyboard Layout
    kbdsyr1.dll                6.1.7600.16385              Syriac Standard Keyboard Layout
    kbdsyr2.dll                6.1.7600.16385              Syriac Phoenetic Keyboard Layout
    kbdtajik.dll               6.1.7601.17514              Tajik Keyboard Layout
    kbdtat.dll                 6.1.7601.18528              Tatar (Legacy) Keyboard Layout
    kbdth0.dll                 6.1.7600.16385              Thai Kedmanee Keyboard Layout
    kbdth1.dll                 6.1.7600.16385              Thai Pattachote Keyboard Layout
    kbdth2.dll                 6.1.7600.16385              Thai Kedmanee (non-ShiftLock) Keyboard Layout
    kbdth3.dll                 6.1.7600.16385              Thai Pattachote (non-ShiftLock) Keyboard Layout
    kbdtiprc.dll               6.1.7600.16385              Tibetan (PRC) Keyboard Layout
    kbdtuf.dll                 6.1.7601.17514              Turkish F Keyboard Layout
    kbdtuq.dll                 6.1.7601.17514              Turkish Q Keyboard Layout
    kbdturme.dll               6.1.7601.17514              Turkmen Keyboard Layout
    kbdughr.dll                6.1.7600.16385              Uyghur (Legacy) Keyboard Layout
    kbdughr1.dll               6.1.7601.17514              Uyghur Keyboard Layout
    kbduk.dll                  6.1.7600.16385              United Kingdom Keyboard Layout
    kbdukx.dll                 6.1.7600.16385              United Kingdom Extended Keyboard Layout
    kbdur.dll                  6.1.7600.16385              Ukrainian Keyboard Layout
    kbdur1.dll                 6.1.7600.16385              Ukrainian (Enhanced) Keyboard Layout
    kbdurdu.dll                6.1.7600.16385              Urdu Keyboard Layout
    kbdus.dll                  6.1.7601.17514              United States Keyboard Layout
    kbdusa.dll                 6.1.7600.16385              US IBM Arabic 238_L Keyboard Layout
    kbdusl.dll                 6.1.7600.16385              Dvorak Left-Hand US English Keyboard Layout
    kbdusr.dll                 6.1.7600.16385              Dvorak Right-Hand US English Keyboard Layout
    kbdusx.dll                 6.1.7600.16385              US Multinational Keyboard Layout
    kbduzb.dll                 6.1.7600.16385              Uzbek_Cyrillic Keyboard Layout
    kbdvntc.dll                6.1.7600.16385              Vietnamese Keyboard Layout
    kbdwol.dll                 6.1.7600.16385              Wolof Keyboard Layout
    kbdyak.dll                 6.1.7601.18528              Sakha - Russia Keyboard Layout
    kbdyba.dll                 6.1.7600.16385              Yoruba Keyboard Layout
    kbdycc.dll                 6.1.7600.16385              Serbian (Cyrillic) Keyboard Layout
    kbdycl.dll                 6.1.7600.16385              Serbian (Latin) Keyboard Layout
    kerberos.dll               6.1.7601.18779                Kerberos
    kernel32.dll               6.1.7601.18409                Windows NT BASE API
    kernelbase.dll             6.1.7601.18409                Windows NT BASE API
    keyiso.dll                 6.1.7600.16385                 CNG
    keymgr.dll                 6.1.7600.16385                  
    korwbrkr.dll               6.1.7600.16385              korwbrkr
    ksuser.dll                 6.1.7600.16385              User CSA Library
    ktmw32.dll                 6.1.7600.16385              Windows KTM Win32 Client DLL
    l2gpstore.dll              6.1.7600.16385              Policy Storage dll
    l2nacp.dll                 6.1.7600.16385                 Onex Windows
    l2sechc.dll                6.1.7600.16385                    2
    lagarith.dll               1.3.27.0                    Lagarith
    laprxy.dll                 12.0.7600.16385             Windows Media Logagent Proxy
    libeay32.dll               1.0.1.5                     OpenSSL Shared Library
    libssl32.dll               1.0.1.5                     OpenSSL Shared Library
    licmgr10.dll               11.0.9600.16428              (DLL)    Microsoft
    linkinfo.dll               6.1.7600.16385              Windows Volume Tracking
    loadperf.dll               6.1.7600.16385                  
    localsec.dll               6.1.7601.17514               MMC "   "
    locationapi.dll            6.1.7600.16385              Microsoft Windows Location API
    loghours.dll               6.1.7600.16385               
    logoncli.dll               6.1.7601.17514              Net Logon Client DLL
    lpk.dll                    6.1.7601.18768              Language Pack
    lsmproxy.dll               6.1.7601.17514              LSM interfaces proxy Dll
    luainstall.dll             6.1.7601.17514              Lua manifest install
    lz32.dll                   6.1.7600.16385              LZ Expand/Compress API DLL
    macdll.dll                 3.9.9.1                     Monkey's Audio DLL Library
    magnification.dll          6.1.7600.16385               API  ()
    mapi32.dll                 1.0.2536.0                   MAPI 1.0  Windows NT
    mapistub.dll               1.0.2536.0                   MAPI 1.0  Windows NT
    mcewmdrmndbootstrap.dll    1.3.2302.0                  Windows Media Center WMDRM-ND Receiver Bridge Bootstrap DLL
    mciavi32.dll               6.1.7601.17514               MCI Video  Windows
    mcicda.dll                 6.1.7600.16385               MCI   cdaudio
    mciqtz32.dll               6.6.7601.17514               MCI DirectShow
    mciseq.dll                 6.1.7600.16385               MCI   MIDI
    mciwave.dll                6.1.7600.16385               MCI   
    mctres.dll                 6.1.7600.16385                MCT
    mdminst.dll                6.1.7600.16385               
    mediametadatahandler.dll   6.1.7601.17514              Media Metadata Handler
    mf.dll                     12.0.7601.18741               
    mf3216.dll                 6.1.7600.16385              32-bit to 16-bit Metafile Conversion DLL
    mfaacenc.dll               6.1.7600.16385              Media Foundation AAC Encoder
    mfc100.dll                 10.0.40219.325              MFCDLL Shared Library - Retail Version
    mfc100chs.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100cht.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100deu.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100enu.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100esn.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100fra.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100ita.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100jpn.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100kor.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100rus.dll              10.0.40219.325              MFC Language Specific Resources
    mfc100u.dll                10.0.40219.325              MFCDLL Shared Library - Retail Version
    mfc110.dll                 11.0.60610.1                MFCDLL Shared Library - Retail Version
    mfc110chs.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110cht.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110deu.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110enu.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110esn.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110fra.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110ita.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110jpn.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110kor.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110rus.dll              11.0.60610.1                MFC Language Specific Resources
    mfc110u.dll                11.0.60610.1                MFCDLL Shared Library - Retail Version
    mfc40.dll                  4.1.0.6151                    MFCDLL -  
    mfc40u.dll                 4.1.0.6151                    MFCDLL -  
    mfc42.dll                  6.6.8064.0                    MFCDLL -  
    mfc42u.dll                 6.6.8064.0                    MFCDLL -  
    mfc70.dll                  7.0.9975.0                  MFCDLL Shared Library - Retail Version
    mfc70chs.dll               7.0.9975.0                  MFC Language Specific Resources
    mfc70cht.dll               7.0.9975.0                  MFC Language Specific Resources
    mfc70deu.dll               7.0.9975.0                  MFC Language Specific Resources
    mfc70enu.dll               7.0.9975.0                  MFC Language Specific Resources
    mfc70esp.dll               7.0.9975.0                  MFC Language Specific Resources
    mfc70fra.dll               7.0.9975.0                  MFC Language Specific Resources
    mfc70ita.dll               7.0.9975.0                  MFC Language Specific Resources
    mfc70jpn.dll               7.0.9975.0                  MFC Language Specific Resources
    mfc70kor.dll               7.0.9975.0                  MFC Language Specific Resources
    mfc70u.dll                 7.0.9975.0                  MFCDLL Shared Library - Retail Version
    mfc71.dll                  7.10.6101.0                 MFCDLL Shared Library - Retail Version
    mfc71chs.dll               7.10.6101.0                 MFC Language Specific Resources
    mfc71cht.dll               7.10.6101.0                 MFC Language Specific Resources
    mfc71deu.dll               7.10.6101.0                 MFC Language Specific Resources
    mfc71enu.dll               7.10.6101.0                 MFC Language Specific Resources
    mfc71esp.dll               7.10.6101.0                 MFC Language Specific Resources
    mfc71fra.dll               7.10.6101.0                 MFC Language Specific Resources
    mfc71ita.dll               7.10.6101.0                 MFC Language Specific Resources
    mfc71jpn.dll               7.10.6101.0                 MFC Language Specific Resources
    mfc71kor.dll               7.10.6101.0                 MFC Language Specific Resources
    mfc71u.dll                 7.10.6101.0                 MFCDLL Shared Library - Retail Version
    mfcm100.dll                10.0.40219.325              MFC Managed Library - Retail Version
    mfcm100u.dll               10.0.40219.325              MFC Managed Library - Retail Version
    mfcm110.dll                11.0.60610.1                MFC Managed Library - Retail Version
    mfcm110u.dll               11.0.60610.1                MFC Managed Library - Retail Version
    mfcsubs.dll                2001.12.8530.16385          COM+
    mfds.dll                   12.0.7601.17514             Media Foundation Direct Show wrapper DLL
    mfdvdec.dll                6.1.7600.16385              Media Foundation DV Decoder
    mferror.dll                12.0.7601.18741                
    mfh264enc.dll              6.1.7600.16385              Media Foundation H264 Encoder
    mfmjpegdec.dll             6.1.7600.16385              Media Foundation MJPEG Decoder
    mfplat.dll                 12.0.7601.18741             Media Foundation Platform DLL
    mfplay.dll                 12.0.7601.17514             Media Foundation Playback API DLL
    mfps.dll                   12.0.7601.18741             Media Foundation Proxy DLL
    mfreadwrite.dll            12.0.7601.17514             Media Foundation ReadWrite DLL
    mfvdsp.dll                 6.1.7600.16385              Windows Media Foundation Video DSP Components
    mfwmaaec.dll               6.1.7600.16385              Windows Media Audio AEC for Media Foundation
    mgmtapi.dll                6.1.7600.16385              Microsoft SNMP Manager API (uses WinSNMP)
    midimap.dll                6.1.7600.16385              Microsoft MIDI Mapper
    migisol.dll                6.1.7601.17514              Migration System Isolation Layer
    miguiresource.dll          6.1.7600.16385               MIG wini32
    mimefilt.dll               2008.0.7601.17514            MIME
    mlang.dll                  6.1.7600.16385               DLL  
    mlc.dll                                                
    mmcbase.dll                6.1.7600.16385                DLL MMC
    mmci.dll                   6.1.7600.16385                
    mmcico.dll                 6.1.7600.16385              Media class co-installer
    mmcndmgr.dll               6.1.7601.17514                 MMC
    mmcshext.dll               6.1.7600.16385              MMC Shell Extension DLL
    mmdevapi.dll               6.1.7601.17514              MMDevice API
    mmres.dll                  6.1.7600.16385               
    modemui.dll                6.1.7600.16385                Windows
    moricons.dll               6.1.7600.16385              Windows NT Setup Icon Resources Library
    mp3dmod.dll                6.1.7600.16385              Microsoft MP3 Decoder DMO
    mp43decd.dll               6.1.7600.16385              Windows Media MPEG-4 Video Decoder
    mp4sdecd.dll               6.1.7600.16385              Windows Media MPEG-4 S Video Decoder
    mpg4decd.dll               6.1.7600.16385              Windows Media MPEG-4 Video Decoder
    mpr.dll                    6.1.7600.16385                   
    mprapi.dll                 6.1.7601.17514              Windows NT MP Router Administration DLL
    mprddm.dll                 6.1.7601.17514                  
    mprdim.dll                 6.1.7600.16385                
    mprmsg.dll                 6.1.7600.16385               (DLL)    
    msaatext.dll               2.0.10413.0                 Active Accessibility text support
    msac3enc.dll               6.1.7601.17514              Microsoft AC-3 Encoder
    msacm32.dll                6.1.7600.16385                 Microsoft
    msadce.dll                 6.1.7601.17514              OLE DB Cursor Engine
    msadcer.dll                6.1.7600.16385              OLE DB Cursor Engine Resources
    msadcf.dll                 6.1.7601.17514              Remote Data Services Data Factory
    msadcfr.dll                6.1.7600.16385              Remote Data Services Data Factory Resources
    msadco.dll                 6.1.7601.17857              Remote Data Services Data Control
    msadcor.dll                6.1.7600.16385              Remote Data Services Data Control Resources
    msadcs.dll                 6.1.7601.17514              Remote Data Services ISAPI Library
    msadds.dll                 6.1.7600.16385              OLE DB Data Shape Provider
    msaddsr.dll                6.1.7600.16385               OLE DB Data Shape Provider Resources
    msader15.dll               6.1.7600.16385              ActiveX Data Objects Resources
    msado15.dll                6.1.7601.17857              ActiveX Data Objects
    msadomd.dll                6.1.7601.17857              ActiveX Data Objects (Multi-Dimensional)
    msador15.dll               6.1.7601.17857              Microsoft ActiveX Data Objects Recordset
    msadox.dll                 6.1.7601.17857              ActiveX Data Objects Extensions
    msadrh15.dll               6.1.7600.16385              ActiveX Data Objects Rowset Helper
    msafd.dll                  6.1.7600.16385              Microsoft Windows Sockets 2.0 Service Provider
    msasn1.dll                 6.1.7601.17514              ASN.1 Runtime APIs
    msaudite.dll               6.1.7601.18779                 
    mscandui.dll               6.1.7600.16385                MSCANDUI
    mscat32.dll                6.1.7600.16385              MSCAT32 Forwarder DLL
    msclmd.dll                 6.1.7601.17514              Microsoft Class Mini-driver
    mscms.dll                  6.1.7601.17514              DLL-    
    mscoree.dll                4.0.40305.0                 Microsoft .NET Runtime Execution Engine
    mscorier.dll               2.0.50727.5483               IE    Microsoft .NET
    mscories.dll               2.0.50727.5483              Microsoft .NET IE SECURITY REGISTRATION
    mscpx32r.dll               6.1.7600.16385              ODBC Code Page Translator Resources
    mscpxl32.dll               6.1.7600.16385                 ODBC
    msctf.dll                  6.1.7601.18731                MSCTF
    msctfmonitor.dll           6.1.7600.16385              MsCtfMonitor DLL
    msctfp.dll                 6.1.7600.16385              MSCTFP Server DLL
    msctfui.dll                6.1.7600.16385                MSCTFUI
    msdadc.dll                 6.1.7600.16385              OLE DB Data Conversion Stub
    msdadiag.dll               6.1.7600.16385              Built-In Diagnostics
    msdaenum.dll               6.1.7600.16385              OLE DB Root Enumerator Stub
    msdaer.dll                 6.1.7600.16385              OLE DB Error Collection Stub
    msdaora.dll                6.1.7600.16385              OLE DB Provider for Oracle
    msdaorar.dll               6.1.7600.16385              OLE DB Provider for Oracle Resources
    msdaosp.dll                6.1.7601.17632              OLE DB Simple Provider
    msdaprsr.dll               6.1.7600.16385                OLE DB Persistence Services
    msdaprst.dll               6.1.7600.16385              OLE DB Persistence Services
    msdaps.dll                 6.1.7600.16385              OLE DB Interface Proxies/Stubs
    msdarem.dll                6.1.7601.17514              OLE DB Remote Provider
    msdaremr.dll               6.1.7600.16385              OLE DB Remote Provider Resources
    msdart.dll                 6.1.7600.16385              OLE DB Runtime Routines
    msdasc.dll                 6.1.7600.16385              OLE DB Service Components Stub
    msdasql.dll                6.1.7601.17514              OLE DB Provider for ODBC Drivers
    msdasqlr.dll               6.1.7600.16385              OLE DB Provider for ODBC Drivers Resources
    msdatl3.dll                6.1.7600.16385              OLE DB Implementation Support Routines
    msdatt.dll                 6.1.7600.16385              OLE DB Temporary Table Services
    msdaurl.dll                6.1.7600.16385              OLE DB RootBinder Stub
    msdelta.dll                6.1.7600.16385              Microsoft Patch Engine
    msdfmap.dll                6.1.7601.17514              Data Factory Handler
    msdmo.dll                  6.6.7601.17514              DMO Runtime
    msdrm.dll                  6.1.7601.18332                 Windows
    msdtcprx.dll               2001.12.8530.16385          Microsoft Distributed Transaction Coordinator OLE Transactions Interface Proxy DLL
    msdtcuiu.dll               2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Administrative DLL
    msdtcvsp1res.dll           2001.12.8530.16385               Vista SP1
    msexch40.dll               4.0.9756.0                  Microsoft Jet Exchange Isam
    msexcl40.dll               4.0.9756.0                  Microsoft Jet Excel Isam
    msfeeds.dll                11.0.9600.17689             Microsoft Feeds Manager
    msfeedsbs.dll              11.0.9600.16428               - ()
    msftedit.dll               5.41.21.2510                Rich Text Edit Control, v4.1
    mshtml.dll                 11.0.9600.17690               HTML Microsoft
    mshtmldac.dll              11.0.9600.17689             DAC for Trident DOM
    mshtmled.dll               11.0.9600.17690             Microsoft HTML Editing Component
    mshtmler.dll               11.0.9600.16428                 HTML (Microsoft)
    mshtmlmedia.dll            11.0.9600.17689             Microsoft (R) HTML Media DLL
    msi.dll                    5.0.7601.18637              Windows Installer
    msidcrl30.dll              6.1.7600.16385              IDCRL Dynamic Link Library
    msident.dll                6.1.7600.16385                (Microsoft)
    msidle.dll                 6.1.7600.16385              User Idle Monitor
    msidntld.dll               6.1.7600.16385                (Microsoft)
    msieftp.dll                6.1.7601.18300                Microsoft Internet Explorer  FTP
    msihnd.dll                 5.0.7601.18493              Windows installer
    msiltcfg.dll               5.0.7600.16385              Windows Installer Configuration API Stub
    msimg32.dll                6.1.7600.16385              GDIEXT Client DLL
    msimsg.dll                 5.0.7600.16385                 Windows
    msimtf.dll                 6.1.7600.16385              Active IMM Server DLL
    msisip.dll                 5.0.7600.16385              MSI Signature SIP Provider
    msjet40.dll                4.0.9756.0                  Microsoft Jet Engine Library
    msjetoledb40.dll           4.0.9756.0                  
    msjint40.dll               4.0.9756.0                       Microsoft Jet
    msjro.dll                  6.1.7601.17857              Jet and Replication Objects
    msjter40.dll               4.0.9756.0                  Microsoft Jet Database Engine Error DLL
    msjtes40.dll               4.0.9756.0                  Microsoft Jet Expression Service
    msls31.dll                 3.10.349.0                  Microsoft Line Services library file
    msltus40.dll               4.0.9756.0                  Microsoft Jet Lotus 1-2-3 Isam
    msmpeg2adec.dll            6.1.7140.0                  Microsoft DTV-DVD Audio Decoder
    msmpeg2enc.dll             6.1.7601.17514               Microsoft MPEG-2
    msmpeg2vdec.dll            12.0.9200.17037             Microsoft DTV-DVD Video Decoder
    msnetobj.dll               11.0.7601.18741             DRM ActiveX Network Object
    msobjs.dll                 6.1.7601.18779                 
    msoeacct.dll               6.1.7600.16385              Microsoft Internet Account Manager
    msoert2.dll                6.1.7600.16385              Microsoft Windows Mail RT Lib
    msorc32r.dll               6.1.7600.16385                ODBC  Oracle
    msorcl32.dll               6.1.7601.17514              ODBC Driver for Oracle
    mspatcha.dll               6.1.7600.16385              Microsoft File Patch Application API
    mspbde40.dll               4.0.9756.0                  Microsoft Jet Paradox Isam
    msports.dll                6.1.7600.16385                 
    msrating.dll               11.0.9600.17689                  
    msrd2x40.dll               4.0.9756.0                  Microsoft (R) Red ISAM
    msrd3x40.dll               4.0.9756.0                  Microsoft (R) Red ISAM
    msrdc.dll                  6.1.7600.16385              Remote Differential Compression COM server
    msrdpwebaccess.dll         6.3.9600.16415              Microsoft Remote Desktop Services Web Access Control
    msrepl40.dll               4.0.9756.0                  Microsoft Replication Library
    msrle32.dll                6.1.7601.17514              Microsoft RLE Compressor
    msscntrs.dll               7.0.7601.17610              msscntrs.dll
    msscp.dll                  11.0.7601.18741             Windows Media Secure Content Provider
    mssha.dll                  6.1.7600.16385                  Windows
    msshavmsg.dll              6.1.7600.16385                     Windows
    msshooks.dll               7.0.7600.16385              MSSHooks.dll
    mssign32.dll               6.1.7600.16385               API  
    mssip32.dll                6.1.7600.16385              MSSIP32 Forwarder DLL
    mssitlb.dll                7.0.7600.16385              mssitlb
    mssph.dll                  7.0.7601.17610                 Microsoft
    mssphtb.dll                7.0.7601.17610              Outlook MSSearch Connector
    mssprxy.dll                7.0.7600.16385              Microsoft Search Proxy
    mssrch.dll                 7.0.7601.17610              mssrch.dll
    msstdfmt.dll               6.1.98.16                   Microsoft Standard Data Formating Object DLL
    msstkprp.dll               6.1.98.16                   msprop32.ocx
    mssvp.dll                  7.0.7601.17610               Vista MSSearch
    msswch.dll                 6.1.7600.16385              msswch
    mstask.dll                 6.1.7601.17514                 
    mstext40.dll               4.0.9756.0                  Microsoft Jet Text Isam
    mstime.dll                 8.0.7601.17514              Microsoft (R) Timed Interactive Multimedia Extensions to HTML
    mstscax.dll                6.3.9600.17276              ActiveX-    
    msutb.dll                  6.1.7601.17514               (DLL)  MSUTB
    msv1_0.dll                 6.1.7601.18779              Microsoft Authentication Package v1.0
    msvbvm50.dll               5.2.82.44                   Visual Basic Virtual Machine
    msvbvm60.dll               6.0.98.15                   Visual Basic Virtual Machine
    msvci70.dll                7.0.9955.0                  Microsoft C++ Runtime Library
    msvcirt.dll                7.0.7600.16385              Windows NT IOStreams DLL
    msvcp100.dll               10.0.40219.325              Microsoft C Runtime Library
    msvcp110.dll               11.0.51106.1                Microsoft C Runtime Library
    msvcp110_clr0400.dll       12.0.51209.34209            Microsoft .NET Framework
    msvcp120.dll               12.0.21005.1                Microsoft C Runtime Library
    msvcp120_clr0400.dll       12.0.51209.34209            Microsoft C Runtime Library
    msvcp60.dll                7.0.7600.16385              Windows NT C++ Runtime Library DLL
    msvcp70.dll                7.0.9466.0                  Microsoft C++ Runtime Library
    msvcp71.dll                7.10.6052.0                 Microsoft C++ Runtime Library
    msvcr100.dll               10.0.40219.325              Microsoft C Runtime Library
    msvcr100_clr0400.dll       12.0.51209.34209            Microsoft .NET Framework
    msvcr110.dll               11.0.51106.1                Microsoft C Runtime Library
    msvcr110_clr0400.dll       12.0.51209.34209            Microsoft .NET Framework
    msvcr120.dll               12.0.21005.1                Microsoft C Runtime Library
    msvcr120_clr0400.dll       12.0.51677.34237            Microsoft C Runtime Library
    msvcr70.dll                7.0.9981.0                  Microsoft C Runtime Library
    msvcr71.dll                7.10.7031.4                 Microsoft C Runtime Library
    msvcrt.dll                 7.0.7601.17744              Windows NT CRT DLL
    msvcrt10.dll                                           
    msvcrt20.dll               2.12.0.0                    Microsoft C Runtime Library
    msvcrt40.dll               6.1.7600.16385              VC 4.x CRT DLL (Forwarded to msvcrt.dll)
    msvfw32.dll                6.1.7601.17514               Microsoft Video  Windows
    msvidc32.dll               6.1.7601.17514                Microsoft Video 1
    msvidctl.dll               6.5.7601.17514               ActiveX  
    mswdat10.dll               4.0.9756.0                  Microsoft Jet Sort Tables
    mswmdm.dll                 12.0.7600.16385               Windows Media Device Manager
    mswsock.dll                6.1.7601.18254                 API Microsoft Windows Sockets 2.0
    mswstr10.dll               4.0.9756.0                    Microsoft Jet
    msxactps.dll               6.1.7600.16385              OLE DB Transaction Proxies/Stubs
    msxbde40.dll               4.0.9756.0                  Microsoft Jet xBASE Isam
    msxml3.dll                 8.110.7601.18576            MSXML 3.0 SP11
    msxml3r.dll                8.110.7601.18576            XML Resources
    msxml6.dll                 6.30.7601.18431             MSXML 6.0 SP3
    msxml6r.dll                6.30.7601.18431             XML Resources
    msyuv.dll                  6.1.7601.17514              Microsoft UYVY Video Decompressor
    mtxclu.dll                 2001.12.8531.17514          Microsoft Distributed Transaction Coordinator Failover Clustering Support DLL
    mtxdm.dll                  2001.12.8530.16385          COM+
    mtxex.dll                  2001.12.8530.16385          COM+
    mtxlegih.dll               2001.12.8530.16385          COM+
    mtxoci.dll                 2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Database Support DLL for Oracle
    muifontsetup.dll           6.1.7601.17514              MUI Callback for font registry settings
    mycomput.dll               6.1.7600.16385               
    mydocs.dll                 6.1.7601.17514                 " "
    napcrypt.dll               6.1.7601.17514              NAP Cryptographic API helper
    napdsnap.dll               6.1.7601.17514               GPEdit    
    naphlpr.dll                6.1.7601.17514              NAP client config API helper
    napinsp.dll                6.1.7600.16385                    
    napipsec.dll               6.1.7600.16385                      IPSec
    napmontr.dll               6.1.7600.16385                NAP  Netsh
    nativehooks.dll            6.1.7600.16385              Microsoft Narrator Native hook handler
    naturallanguage6.dll       6.1.7601.17514              Natural Language Development Platform 6
    ncdprop.dll                6.1.7600.16385                 
    nci.dll                    6.1.7601.17514              CoInstaller: NET
    ncobjapi.dll               6.1.7600.16385              Microsoft Windows Operating System
    ncrypt.dll                 6.1.7601.18779                (Windows)
    ncryptui.dll               6.1.7601.17514               UI     Windows
    ncsi.dll                   6.1.7601.18685                 
    nddeapi.dll                6.1.7600.16385              Network DDE Share Management APIs
    ndfapi.dll                 6.1.7600.16385              API    
    ndfetw.dll                 6.1.7600.16385              Network Diagnostic Engine Event Interface
    ndfhcdiscovery.dll         6.1.7600.16385              Network Diagnostic Framework HC Discovery API
    ndiscapcfg.dll             6.1.7600.16385              NdisCap Notify Object
    ndishc.dll                 6.1.7600.16385                NDIS
    ndproxystub.dll            6.1.7600.16385              Network Diagnostic Engine Proxy/Stub
    negoexts.dll               6.1.7600.16385              NegoExtender Security Package
    netapi32.dll               6.1.7601.17887              Net Win32 API DLL
    netbios.dll                6.1.7600.16385              NetBIOS Interface Library
    netcenter.dll              6.1.7601.17514                 -  
    netcfgx.dll                6.1.7601.17514                
    netcorehc.dll              6.1.7601.17964                   
    netdiagfx.dll              6.1.7601.17514                
    netevent.dll               6.1.7601.17964                
    netfxperf.dll              4.0.40305.0                 Extensible Performance Counter Shim
    neth.dll                   6.1.7600.16385                 
    netid.dll                  6.1.7601.17514                  
    netiohlp.dll               6.1.7601.17514               DLL   Netio
    netjoin.dll                6.1.7601.17514              Domain Join DLL
    netlogon.dll               6.1.7601.17514                 Net Logon
    netmsg.dll                 6.1.7600.16385                
    netplwiz.dll               6.1.7601.17514                   
    netprof.dll                6.1.7600.16385                 
    netprofm.dll               6.1.7600.16385                
    netshell.dll               6.1.7601.17514                
    netutils.dll               6.1.7601.17514              Net Win32 API Helpers DLL
    networkexplorer.dll        6.1.7601.17514               
    networkitemfactory.dll     6.1.7600.16385                
    networkmap.dll             6.1.7601.17514               
    newdev.dll                 6.0.5054.0                    
    nlaapi.dll                 6.1.7601.18685              Network Location Awareness 2
    nlhtml.dll                 2008.0.7600.16385            HTML
    nlmgp.dll                  6.1.7600.16385                 
    nlmsprep.dll               6.1.7600.16385              Network List Manager Sysprep Module
    nlsbres.dll                6.1.7601.17514              NLSBuild resource DLL
    nlsdata0000.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0001.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0002.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0003.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0007.dll            6.1.7600.16385              Microsoft German Natural Language Server Data and Code
    nlsdata0009.dll            6.1.7600.16385              Microsoft English Natural Language Server Data and Code
    nlsdata000a.dll            6.1.7600.16385              Microsoft Spanish Natural Language Server Data and Code
    nlsdata000c.dll            6.1.7600.16385              Microsoft French Natural Language Server Data and Code
    nlsdata000d.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata000f.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0010.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0011.dll            6.1.7600.16385              Microsoft Japanese Natural Language Server Data and Code
    nlsdata0013.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0018.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0019.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001b.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata001d.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0020.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0021.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0022.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0024.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0026.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0027.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata002a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0039.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata003e.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0045.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0046.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0047.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0049.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004b.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004c.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata004e.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0414.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0416.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0816.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata081a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdata0c1a.dll            6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsdl.dll                  6.1.7600.16385              Nls Downlevel DLL
    nlslexicons0001.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0002.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0003.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0007.dll        6.1.7600.16385              Microsoft German Natural Language Server Data and Code
    nlslexicons0009.dll        6.1.7600.16385              Microsoft English Natural Language Server Data and Code
    nlslexicons000a.dll        6.1.7600.16385              Microsoft Spanish Natural Language Server Data and Code
    nlslexicons000c.dll        6.1.7600.16385              Microsoft French Natural Language Server Data and Code
    nlslexicons000d.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons000f.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0010.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0011.dll        6.1.7600.16385              Microsoft Japanese Natural Language Server Data and Code
    nlslexicons0013.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0018.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0019.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001b.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons001d.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0020.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0021.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0022.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0024.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0026.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0027.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons002a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0039.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons003e.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0045.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0046.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0047.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0049.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004b.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004c.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons004e.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0414.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0416.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0816.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons081a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlslexicons0c1a.dll        6.1.7600.16385              Microsoft Neutral Natural Language Server Data and Code
    nlsmodels0011.dll          6.1.7600.16385              Microsoft Japanese Natural Language Server Data and Code
    normaliz.dll               6.1.7600.16385              Unicode Normalization DLL
    npmproxy.dll               6.1.7600.16385              Network List Manager Proxy
    nshhttp.dll                6.1.7600.16385               DLL netsh  HTTP
    nshipsec.dll               6.1.7601.17514               DLL  IPSec  Net
    nshwfp.dll                 6.1.7601.18283                  Windows  Netsh
    nsi.dll                    6.1.7600.16385              NSI User-mode interface DLL
    ntdll.dll                  6.1.7601.18247                NT
    ntdsapi.dll                6.1.7600.16385              Active Directory Domain Services API
    ntlanman.dll               6.1.7601.17514              Microsoft LAN Manager
    ntlanui2.dll               6.1.7600.16385                  
    ntmarta.dll                6.1.7600.16385               Windows NT MARTA
    ntprint.dll                6.1.7601.17514                  
    ntshrui.dll                6.1.7601.17755               ,    
    ntvdm64.dll                6.1.7601.18409              16-   NT64
    nvapi.dll                  9.18.13.4052                NVIDIA NVAPI Library, Version 340.52 
    nvaudcap32v.dll            1.2.23.0                    NVIDIA Virtual Audio Driver
    nvcompiler.dll             8.17.13.4052                NVIDIA Compiler, Version 340.52 
    nvcuda.dll                 8.17.13.4052                NVIDIA CUDA Driver, Version 340.52 
    nvcuvid.dll                7.17.13.4052                NVIDIA CUDA Video Decode API, Version 340.52 
    nvd3dum.dll                9.18.13.4052                NVIDIA WDDM D3D Driver, Version 340.52 
    nvfbc.dll                  6.14.13.4052                NVIDIA Front Buffer Capture Library, Version 
    nvifr.dll                  6.14.13.4052                NVIDIA In-band Frame Rendering Library, Version 
    nvoglv32.dll               9.18.13.4052                NVIDIA Compatible OpenGL ICD
    nvopencl.dll               8.17.13.4052                NVIDIA CUDA 6.5.12 OpenCL 1.1 Driver, Version 340.52 
    nvspbridge.dll             15.3.33.0                   NVIDIA GFE - Notification Bridge
    nvspcap.dll                15.3.33.0                   NVIDIA Capture Server Proxy
    nvwgf2um.dll               9.18.13.4052                NVIDIA D3D10 Driver, Version 340.52 
    objsel.dll                 6.1.7601.18409                
    occache.dll                11.0.9600.16428                 
    ocsetapi.dll               6.1.7601.17514              Windows Optional Component Setup API
    odbc32.dll                 6.1.7601.17514              ODBC Driver Manager
    odbc32gt.dll               6.1.7600.16385              ODBC Driver Generic Thunk
    odbcbcp.dll                6.1.7600.16385              BCP for ODBC
    odbcconf.dll               6.1.7601.17514              ODBC Driver Configuration Program
    odbccp32.dll               6.1.7601.17632              ODBC Installer
    odbccr32.dll               6.1.7601.17632              ODBC Cursor Library
    odbccu32.dll               6.1.7601.17632              ODBC Cursor Library
    odbcint.dll                6.1.7600.16385              ODBC Resources
    odbcji32.dll               6.1.7600.16385              Microsoft ODBC Desktop Driver Pack 3.5
    odbcjt32.dll               6.1.7601.17632              Microsoft ODBC Desktop Driver Pack 3.5
    odbctrac.dll               6.1.7601.17632              ODBC Driver Manager Trace
    oddbse32.dll               6.1.7600.16385              ODBC (3.0) driver for DBase
    odexl32.dll                6.1.7600.16385              ODBC (3.0) driver for Excel
    odfox32.dll                6.1.7600.16385              ODBC (3.0) driver for FoxPro
    odpdx32.dll                6.1.7600.16385              ODBC (3.0) driver for Paradox
    odtext32.dll               6.1.7600.16385              ODBC (3.0) driver for text files
    offfilt.dll                2008.0.7600.16385            OFFICE
    ogldrv.dll                 6.1.7600.16385              MSOGL
    ole2.dll                   2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    ole2disp.dll               2.10.3050.1                 OLE 2.1 16/32 Interoperability Library
    ole2nls.dll                2.10.3050.1                 OLE 2.1 16/32 Interoperability Library
    ole32.dll                  6.1.7601.17514              Microsoft OLE   Windows
    oleacc.dll                 7.0.0.0                     Active Accessibility Core Component
    oleacchooks.dll            7.0.0.0                     Active Accessibility Event Hooks Library
    oleaccrc.dll               7.0.0.0                     Active Accessibility Resource DLL
    oleaut32.dll               6.1.7601.18679              
    olecli32.dll               6.1.7600.16385                OLE
    oledb32.dll                6.1.7601.17514              OLE DB Core Services
    oledb32r.dll               6.1.7600.16385                 OLE DB
    oledlg.dll                 6.1.7600.16385                 OLE
    oleprn.dll                 6.1.7600.16385              Oleprn DLL
    olepro32.dll               6.1.7601.17514              
    oleres.dll                 6.1.7600.16385                OLE
    olesvr32.dll               6.1.7600.16385              Object Linking and Embedding Server Library
    olethk32.dll               6.1.7601.17514              Microsoft OLE for Windows
    onex.dll                   6.1.7601.17514                IEEE 802.1X
    onexui.dll                 6.1.7601.17514                 IEEE 802.1X
    onlineidcpl.dll            6.1.7601.17514                -  
    oobefldr.dll               6.1.7601.17514                
    opcservices.dll            6.1.7601.17514              Native Code OPC Services Library
    openal32.dll               6.14.357.25                 Standard OpenAL(TM) Implementation
    opencl.dll                 1.0.0.0                     OpenCL Client DLL
    opengl32.dll               6.1.7600.16385              OpenGL Client DLL
    osbaseln.dll               6.1.7600.16385              Service Reporting API
    osuninst.dll               6.1.7600.16385              Uninstall Interface
    p2p.dll                    6.1.7600.16385                
    p2pcollab.dll              6.1.7600.16385                  
    p2pgraph.dll               6.1.7600.16385              Peer-to-Peer Graphing
    p2pnetsh.dll               6.1.7600.16385                 NetSh
    packager.dll               6.1.7601.18645               2
    panmap.dll                 6.1.7600.16385              PANOSE(tm) Font Mapper
    pautoenr.dll               6.1.7600.16385                
    pcaui.dll                  6.1.7600.16385                  
    pcwum.dll                  6.1.7600.16385              Performance Counters for Windows Native DLL
    pdh.dll                    6.1.7601.17514                  Windows
    pdhui.dll                  6.1.7601.17514                
    peerdist.dll               6.1.7600.16385                BranchCache
    peerdistsh.dll             6.1.7600.16385                BranchCache Netshell
    perfcentercpl.dll          6.1.7601.17514               
    perfctrs.dll               6.1.7600.16385               
    perfdisk.dll               6.1.7600.16385                  Windows
    perfnet.dll                6.1.7600.16385                   Windows
    perfos.dll                 6.1.7600.16385                  Windows
    perfproc.dll               6.1.7600.16385                   Windows
    perfts.dll                 6.1.7601.17514              Windows Remote Desktop Services Performance Objects
    photometadatahandler.dll   6.1.7600.16385              Photo Metadata Handler
    photowiz.dll               6.1.7601.17514                
    pid.dll                    6.1.7600.16385              Microsoft PID
    pidgenx.dll                6.1.7600.16385              Pid Generation
    pifmgr.dll                 6.1.7601.17514              Windows NT PIF Manager Icon Resources Library
    pku2u.dll                  6.1.7601.18658              Pku2u Security Package
    pla.dll                    6.1.7601.17514                 
    playsndsrv.dll             6.1.7600.16385               PlaySound
    pmcsnap.dll                6.1.7600.16385              pmcsnap dll
    pncrt.dll                  4.20.0.0                    
    pngfilt.dll                11.0.9600.16428             IE PNG plugin image decoder
    pnidui.dll                 6.1.7601.17514                
    pnpsetup.dll               6.1.7600.16385              Pnp installer for CMI
    pnrpnsp.dll                6.1.7600.16385                 PNRP
    polstore.dll               6.1.7600.16385              Policy Storage dll
    portabledeviceapi.dll      6.1.7601.17514               API    Windows
    portabledeviceclassextension.dll  6.1.7600.16385              Windows Portable Device Class Extension Component
    portabledeviceconnectapi.dll  6.1.7600.16385              Portable Device Connection API Components
    portabledevicestatus.dll   6.1.7601.17514                  Microsoft Windows
    portabledevicesyncprovider.dll  6.1.7601.17514                 Microsoft Windows
    portabledevicetypes.dll    6.1.7600.16385              Windows Portable Device (Parameter) Types Component
    portabledevicewiacompat.dll  6.1.7600.16385              PortableDevice WIA Compatibility Driver
    portabledevicewmdrm.dll    6.1.7600.16385              Windows Portable Device WMDRM Component
    pots.dll                   6.1.7600.16385               
    powercpl.dll               6.1.7601.17514                
    powrprof.dll               6.1.7600.16385              DLL     
    ppcsnap.dll                6.1.7600.16385              ppcsnap DLL
    presentationcffrasterizernative_v0300.dll  3.0.6920.5459               WinFX OpenType/CFF Rasterizer
    presentationhostproxy.dll  4.0.40305.0                 Windows Presentation Foundation Host Proxy
    presentationnative_v0300.dll  3.0.6920.4902               PresentationNative_v0300.dll
    prflbmsg.dll               6.1.7600.16385                  
    printui.dll                6.1.7601.17514                 
    prncache.dll               6.1.7601.17514              Print UI Cache
    prnfldr.dll                6.1.7601.17514              prnfldr dll
    prnntfy.dll                6.1.7600.16385              prnntfy DLL
    prntvpt.dll                6.1.7601.17514              Print Ticket Services Module
    profapi.dll                6.1.7600.16385              User Profile Basic API
    propsys.dll                7.0.7601.17514                 (Microsoft)
    provsvc.dll                6.1.7601.17514                Windows
    provthrd.dll               6.1.7600.16385              WMI Provider Thread & Log Library
    psapi.dll                  6.1.7600.16385              Process Status Helper
    psbase.dll                 6.1.7600.16385                
    pshed.dll                  6.1.7600.16385                ,   
    psisdecd.dll               6.6.7601.17669              Microsoft SI/PSI parser for MPEG2 based networks.
    pstorec.dll                6.1.7600.16385              Protected Storage COM interfaces
    pstorsvc.dll               6.1.7600.16385              Protected storage server
    puiapi.dll                 6.1.7600.16385               DLL puiapi
    puiobj.dll                 6.1.7601.17514               DLL  PrintUI
    pwrshplugin.dll            6.1.7600.16385              pwrshplugin.dll
    qagent.dll                 6.1.7601.17514                
    qasf.dll                   12.0.7601.17514             DirectShow ASF Support
    qcap.dll                   6.6.7601.17514                DirecxX DirectShow.
    qcliprov.dll               6.1.7601.17514               WMI   
    qdv.dll                    6.6.7601.17514                DirecxX DirectShow.
    qdvd.dll                   6.6.7601.18741              DirectShow DVD PlayBack Runtime.
    qedit.dll                  6.6.7601.18501               DirectShow
    qedwipes.dll               6.6.7600.16385              DirectShow Editing SMPTE Wipes
    qmgrprxy.dll               7.5.7600.16385              Background Intelligent Transfer Service Proxy
    qshvhost.dll               6.1.7601.17514                SHV
    qsvrmgmt.dll               6.1.7601.17514                
    quartz.dll                 6.6.7601.18741                DirecxX DirectShow.
    query.dll                  6.1.7601.17514                  
    qutil.dll                  6.1.7601.17514                
    qwave.dll                  6.1.7600.16385              Windows NT
    raac.dll                   17.0.6.13                   RealAudio AAC Format -- the standard-compatible solution.
    racengn.dll                6.1.7601.17514                  
    racpldlg.dll               6.1.7600.16385                 
    radardt.dll                6.1.7600.16385                   Windows
    radarrs.dll                6.1.7600.16385                   Microsoft Windows
    rasadhlp.dll               6.1.7600.16385              Remote Access AutoDial Helper
    rasapi32.dll               6.1.7600.16385              Remote Access API
    rascfg.dll                 6.1.7600.16385                RAS
    raschap.dll                6.1.7601.17514                 PPP CHAP
    rasctrs.dll                6.1.7600.16385                     Windows NT
    rasdiag.dll                6.1.7600.16385                  RAS
    rasdlg.dll                 6.1.7600.16385              API     
    rasgcw.dll                 6.1.7600.16385                RAS
    rasman.dll                 6.1.7600.16385              Remote Access Connection Manager
    rasmm.dll                  6.1.7600.16385                RAS
    rasmontr.dll               6.1.7600.16385                RAS
    rasmxs.dll                 6.1.7600.16385              Remote Access Device DLL for modems, PADs and switches
    rasplap.dll                6.1.7600.16385                 RAS PLAP
    rasppp.dll                 6.1.7601.17514              Remote Access PPP
    rasser.dll                 6.1.7600.16385              Remote Access Media DLL for COM ports
    rastapi.dll                6.1.7601.17514              Remote Access TAPI Compliance Layer
    rastls.dll                 6.1.7601.18584                 PPP EAP-TLS
    rdpcore.dll                6.1.7601.17779              RDP Core DLL
    rdpd3d.dll                 6.1.7601.17514              RDP Direct3D Remoting DLL
    rdpencom.dll               6.1.7601.17514              RDPSRAPI COM Objects
    rdpendp.dll                6.1.7601.17514                 RDP
    rdpendp_winip.dll          6.2.9200.16398              RDP Audio Endpoint
    rdprefdrvapi.dll           6.1.7601.17514              Reflector Driver API
    rdvgumd32.dll              6.1.7601.17514                 ()
    rdvidcrl.dll               6.3.9600.16415              Remote Desktop Services Client for Microsoft Online Services
    reagent.dll                6.1.7601.17514               DLL   Microsoft Windows
    regapi.dll                 6.1.7601.17514              Registry Configuration APIs
    regctrl.dll                6.1.7600.16385              RegCtrl
    remotepg.dll               6.1.7601.17514              CPL-  
    resampledmo.dll            6.1.7600.16385              Windows Media Resampler
    resutils.dll               6.1.7601.17514              Microsoft Cluster Resource Utility DLL
    rgb9rast.dll               6.1.7600.16385              Microsoft Windows Operating System
    riched20.dll               5.31.23.1230                Rich Text Edit Control, v3.1
    riched32.dll               6.1.7601.17514              Wrapper Dll for Richedit 1.0
    rnr20.dll                  6.1.7600.16385              Windows Socket2 NameSpace DLL
    rpcdiag.dll                6.1.7600.16385              RPC Diagnostics
    rpchttp.dll                6.1.7601.17514              RPC HTTP DLL
    rpcndfp.dll                1.0.0.1                        RPC NDF
    rpcns4.dll                 6.1.7600.16385                    (RPC)
    rpcnsh.dll                 6.1.7600.16385                RPC Netshell
    rpcrt4.dll                 6.1.7601.18532                 
    rpcrtremote.dll            6.1.7601.17514              Remote RPC Extension
    rsaenh.dll                 6.1.7600.16385              Microsoft Enhanced Cryptographic Provider
    rshx32.dll                 6.1.7600.16385                
    rstrtmgr.dll               6.1.7600.16385               
    rtffilt.dll                2008.0.7600.16385            RTF
    rtm.dll                    6.1.7600.16385                
    rtutils.dll                6.1.7601.17514              Routing Utilities
    rv10.dll                   17.0.6.13                   RealVideo 1.0
    rv20.dll                   16.0.3.51                   RealVideo G2
    rv30.dll                   17.0.6.13                   RealVideo
    rv40.dll                   17.0.6.13                   RealVideo
    samcli.dll                 6.1.7601.17514              Security Accounts Manager Client DLL
    samlib.dll                 6.1.7600.16385              SAM Library DLL
    sampleres.dll              6.1.7600.16385               (Microsoft)
    sas.dll                    6.1.7600.16385              WinLogon Software SAS Library
    sbe.dll                    6.6.7601.17528              DirectShow Stream Buffer Filter.
    sbeio.dll                  12.0.7600.16385             Stream Buffer IO DLL
    sberes.dll                 6.6.7600.16385                  DirectShow.
    scansetting.dll            6.1.7601.17514                    Microsoft Windows(TM)
    scarddlg.dll               6.1.7600.16385              SCardDlg -   -
    scecli.dll                 6.1.7601.17514                 
    scesrv.dll                 6.1.7601.18686                
    schannel.dll               6.1.7601.18779              TLS / SSL Security Provider
    schedcli.dll               6.1.7601.17514              Scheduler Service Client DLL
    scksp.dll                  6.1.7600.16385              Microsoft Smart Card Key Storage Provider
    scripto.dll                6.6.7600.16385              Microsoft ScriptO
    scrobj.dll                 5.8.7600.16385              Windows  Script Component Runtime
    scrptadm.dll               6.1.7601.17514                
    scrrun.dll                 5.8.7601.18283              Microsoft  Script Runtime
    sdiageng.dll               6.1.7600.16385                 
    sdiagprv.dll               6.1.7600.16385              API    Windows
    sdohlp.dll                 6.1.7600.16385                 SDO NPS
    searchfolder.dll           6.1.7601.17514              SearchFolder
    sechost.dll                6.1.7600.16385              Host for SCM/SDDL/LSA Lookup APIs
    secproc.dll                6.1.7601.18332              Windows Rights Management Desktop Security Processor
    secproc_isv.dll            6.1.7601.18332              Windows Rights Management Desktop Security Processor
    secproc_ssp.dll            6.1.7601.18332              Windows Rights Management Services Server Security Processor
    secproc_ssp_isv.dll        6.1.7601.18332              Windows Rights Management Services Server Security Processor (Pre-production)
    secur32.dll                6.1.7601.18779              Security Support Provider Interface
    security.dll               6.1.7600.16385              Security Support Provider Interface
    sendmail.dll               6.1.7600.16385               
    sens.dll                   6.1.7600.16385                   (SENS)
    sensapi.dll                6.1.7600.16385              SENS Connectivity API DLL
    sensorsapi.dll             6.1.7600.16385              Sensor API
    sensorscpl.dll             6.1.7601.17514                "    "
    serialui.dll               6.1.7600.16385                
    serwvdrv.dll               6.1.7600.16385                Unimodem
    sessenv.dll                6.1.7601.17514                   
    setupapi.dll               6.1.7601.17514              Windows Setup API
    setupcln.dll               6.1.7601.17514                
    sfc.dll                    6.1.7600.16385              Windows File Protection
    sfc_os.dll                 6.1.7600.16385              Windows File Protection
    shacct.dll                 6.1.7601.17514              Shell Accounts Classes
    shdocvw.dll                6.1.7601.18222                    
    shell32.dll                6.1.7601.18762                 Windows
    shellstyle.dll             6.1.7600.16385              Windows Shell Style Resource Dll
    shfolder.dll               6.1.7600.16385              Shell Folder Service
    shgina.dll                 6.1.7601.17514              Windows Shell User Logon
    shimeng.dll                6.1.7600.16385              Shim Engine DLL
    shimgvw.dll                6.1.7601.17514               
    shlwapi.dll                6.1.7601.17514                 
    shpafact.dll               6.1.7600.16385              Windows Shell LUA/PA Elevation Factory Dll
    shsetup.dll                6.1.7601.17514              Shell setup helper
    shsvcs.dll                 6.1.7601.17514               DLL   Windows
    shunimpl.dll               6.1.7601.17514              Windows Shell Obsolete APIs
    shwebsvc.dll               6.1.7601.17514              -  Windows
    signdrv.dll                6.1.7600.16385              WMI provider for Signed Drivers
    sipr.dll                   17.0.6.13                   ACELP-NET Voice Codec for RealAudio(tm)
    sisbkup.dll                6.1.7601.17514              Single-Instance Store Backup Support Functions
    slc.dll                    6.1.7600.16385              Software Licensing Client DLL
    slcext.dll                 6.1.7600.16385              Software Licensing Client Extension Dll
    slwga.dll                  6.1.7601.17514              Software Licensing WGA API
    smackw32.dll               3.0.0.0                     Smacker Video Technology
    smartcardcredentialprovider.dll  6.1.7601.18276                 - Windows
    smbhelperclass.dll         1.0.0.1                        SMB (   )    
    sndvolsso.dll              6.1.7601.17514               SCA 
    snmpapi.dll                6.1.7600.16385              SNMP Utility Library
    softkbd.dll                6.1.7600.16385                  
    softpub.dll                6.1.7600.16385              Softpub Forwarder DLL
    sortserver2003compat.dll   6.1.7600.16385              Sort Version Server 2003
    sortwindows6compat.dll     6.1.7600.16385              Sort Version Windows 6.0
    spbcd.dll                  6.1.7601.17514              BCD Sysprep Plugin
    spfileq.dll                6.1.7600.16385              Windows SPFILEQ
    spinf.dll                  6.1.7600.16385              Windows SPINF
    spnet.dll                  6.1.7600.16385              Net Sysprep Plugin
    spopk.dll                  6.1.7601.17514              OPK Sysprep Plugin
    spp.dll                    6.1.7601.17514                  Microsoft Windows
    sppc.dll                   6.1.7601.17514              Software Licensing Client DLL
    sppcc.dll                  6.1.7600.16385                  
    sppcext.dll                6.1.7600.16385              Software Protection Platform Client Extension Dll
    sppcomapi.dll              6.1.7601.17514                 
    sppcommdlg.dll             6.1.7600.16385              API     
    sppinst.dll                6.1.7601.17514              SPP CMI Installer Plug-in DLL
    sppwmi.dll                 6.1.7600.16385              Software Protection Platform WMI provider
    spwinsat.dll               6.1.7600.16385              WinSAT Sysprep Plugin
    spwizeng.dll               6.1.7601.17514              Setup Wizard Framework
    spwizimg.dll               6.1.7600.16385              Setup Wizard Framework Resources
    spwizres.dll               6.1.7601.17514                 
    spwmp.dll                  6.1.7601.18741              Windows Media Player System Preparation DLL
    sqlceoledb30.dll           3.0.7600.0                  Microsoft SQL Mobile
    sqlceqp30.dll              3.0.7600.0                  Microsoft SQL Mobile
    sqlcese30.dll              3.0.7601.0                  Microsoft SQL Mobile
    sqloledb.dll               6.1.7601.17514              OLE DB Provider for SQL Server
    sqlsrv32.dll               6.1.7601.17514              SQL Server ODBC Driver
    sqlunirl.dll               2000.80.728.0               String Function .DLL for SQL Enterprise Components
    sqlwid.dll                 1999.10.20.0                Unicode Function .DLL for SQL Enterprise Components
    sqlwoa.dll                 1999.10.20.0                Unicode/ANSI Function .DLL for SQL Enterprise Components
    sqlxmlx.dll                6.1.7600.16385              XML extensions for SQL Server
    sqmapi.dll                 6.1.7601.17514              SQM Client
    srchadmin.dll              7.0.7601.17514               
    srclient.dll               6.1.7601.18741              Microsoft Windows System Restore Client Library
    srhelper.dll               6.1.7600.16385              Microsoft Windows driver and windows update enumeration library
    srpuxnativesnapin.dll      6.1.7600.16385                     
    srvcli.dll                 6.1.7601.17514              Server Service Client DLL
    sscore.dll                 6.1.7601.17514               DLL-  
    ssdpapi.dll                6.1.7600.16385              SSDP Client API DLL
    ssleay32.dll               1.0.1.5                     OpenSSL Shared Library
    sspicli.dll                6.1.7601.18779              Security Support Provider Interface
    ssshim.dll                 6.1.7600.16385              Windows Componentization Platform Servicing API
    stclient.dll               2001.12.8530.16385          COM+ Configuration Catalog Client
    sti.dll                    6.1.7600.16385                   
    stobject.dll               6.1.7601.17514                 Systray
    storage.dll                2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    storagecontexthandler.dll  6.1.7600.16385                   
    storprop.dll               6.1.7600.16385                  
    structuredquery.dll        7.0.7601.17514              Structured Query
    sud.dll                    6.1.7601.17514                SUD
    sxproxy.dll                6.1.7600.16385                  Microsoft Windows
    sxs.dll                    6.1.7601.17514              Fusion 2.5
    sxshared.dll               6.1.7600.16385              Microsoft Windows SX Shared Library
    sxsstore.dll               6.1.7600.16385              Sxs Store DLL
    synccenter.dll             6.1.7601.17514                
    synceng.dll                6.1.7601.17959              Windows Briefcase Engine
    synchostps.dll             6.1.7600.16385              Proxystub for sync host
    syncinfrastructure.dll     6.1.7600.16385                Microsoft Windows.
    syncinfrastructureps.dll   6.1.7600.16385              Microsoft Windows sync infrastructure proxy stub.
    syncreg.dll                2007.94.7600.16385          Microsoft Synchronization Framework Registration
    syncui.dll                 6.1.7601.17514               Windows
    syssetup.dll               6.1.7601.17514              Windows NT System Setup
    systemcpl.dll              6.1.7601.17514              CPL 
    t2embed.dll                6.1.7601.17514              Microsoft T2Embed Font Embedding
    tapi3.dll                  6.1.7600.16385              Microsoft TAPI3
    tapi32.dll                 6.1.7600.16385               API  Microsoft Windows
    tapimigplugin.dll          6.1.7600.16385              Microsoft Windows(TM) TAPI Migration Plugin Dll
    tapiperf.dll               6.1.7600.16385              Microsoft Windows(TM) Telephony Performance Monitor
    tapisrv.dll                6.1.7601.17514                 Microsoft Windows
    tapisysprep.dll            6.1.7600.16385              Microsoft Windows(TM) Telephony Sysprep Work
    tapiui.dll                 6.1.7600.16385               DLL   Microsoft Windows
    taskcomp.dll               6.1.7601.17514                  
    taskschd.dll               6.1.7601.17514              Task Scheduler COM API
    taskschdps.dll             6.1.7600.16385              Task Scheduler Interfaces Proxy
    tbs.dll                    6.1.7600.16385              TBS
    tcpipcfg.dll               6.1.7601.17514                
    tcpmonui.dll               6.1.7600.16385                  TCP/IP
    tdh.dll                    6.1.7601.18247                 
    termmgr.dll                6.1.7601.17514              Microsoft TAPI3 Terminal Manager
    thawbrkr.dll               6.1.7600.16385              Thai Word Breaker
    themecpl.dll               6.1.7601.17514              CPL 
    themeui.dll                6.1.7601.17514              API   Windows
    thumbcache.dll             6.1.7601.17514                
    timedatemuicallback.dll    6.1.7600.16385              Time Date Control UI Language Change plugin
    tlscsp.dll                 6.1.7601.17514              Microsoft Remote Desktop Services Cryptographic Utility
    tpmcompc.dll               6.1.7600.16385                
    tquery.dll                 7.0.7601.17610              tquery.dll
    traffic.dll                6.1.7600.16385              Microsoft Traffic Control 1.0 DLL
    trapi.dll                  6.1.7601.17514              Microsoft Narrator Text Renderer
    tsbyuv.dll                 6.1.7601.17514              Toshiba Video Codec
    tschannel.dll              6.1.7600.16385              Task Scheduler Proxy
    tsgqec.dll                 6.3.9600.16415                      
    tsmf.dll                   6.1.7601.17514                MF    
    tspkg.dll                  6.1.7601.18779              Web Service Security Package
    tsworkspace.dll            6.1.7601.18546                      RemoteApp
    tvratings.dll              6.6.7600.16385              Module for managing TV ratings
    twext.dll                  6.1.7601.17514              :  
    txflog.dll                 2001.12.8530.16385          COM+
    txfw32.dll                 6.1.7600.16385              TxF Win32 DLL
    typelib.dll                2.10.3029.1                 OLE 2.1 16/32 Interoperability Library
    tzres.dll                  6.1.7601.18656               DLL   
    ubpm.dll                   6.1.7601.18741               DLL    
    ucmhc.dll                  6.1.7600.16385                 UCM
    udhisapi.dll               6.1.7600.16385              UPnP Device Host ISAPI Extension
    uexfat.dll                 6.1.7600.16385              eXfat Utility DLL
    ufat.dll                   6.1.7600.16385              FAT Utility DLL
    uianimation.dll            6.2.9200.16492              Windows Animation Manager
    uiautomationcore.dll       7.0.0.0                        Microsoft UI
    uicom.dll                  6.1.7600.16385              Add/Remove Modems
    uiribbon.dll               6.1.7601.17514                Windows
    uiribbonres.dll            6.1.7601.17514              Windows Ribbon Framework Resources
    ulib.dll                   6.1.7600.16385              DLL   
    umdmxfrm.dll               6.1.7600.16385              Unimodem Tranform Module
    unicows.dll                1.1.3790.0                  Microsoft Layer for Unicode on Win9x Systems (MSLU)
    unimdmat.dll               6.1.7601.17514              - AT   Unimodem
    uniplat.dll                6.1.7600.16385              Unimodem AT Mini Driver Platform Driver for Windows NT
    unrar.dll                  5.1.100.1066                
    untfs.dll                  6.1.7601.17514              NTFS Utility DLL
    upnp.dll                   6.1.7601.17514              API   UPnP
    upnphost.dll               6.1.7600.16385                PNP-
    ureg.dll                   6.1.7600.16385              Registry Utility DLL
    url.dll                    11.0.9600.16428             Internet Shortcut Shell Extension DLL
    urlmon.dll                 11.0.9600.17689              OLE32  Win32
    usbceip.dll                6.1.7600.16385               USBCEIP
    usbperf.dll                6.1.7600.16385               DLL   USB
    usbui.dll                  6.1.7600.16385              USB UI Dll
    user32.dll                 6.1.7601.17514                 USER API Windows
    useraccountcontrolsettings.dll  6.1.7601.17514                  
    usercpl.dll                6.1.7601.17514                
    userenv.dll                6.1.7601.17514              Userenv
    usp10.dll                  1.626.7601.18454            Uniscribe Unicode script processor
    utildll.dll                6.1.7601.17514                WinStation
    utv_core.dll                                           
    utv_dmo.dll                1.0.0.1                     TODO: <???????>
    utv_mft.dll                1.0.0.1                     TODO: <???????>
    utv_vcm.dll                                            
    uudf.dll                   6.1.7600.16385              UDF Utility DLL
    uxinit.dll                 6.1.7600.16385              Windows User Experience Session Initialization Dll
    uxlib.dll                  6.1.7601.17514              Setup Wizard Framework
    uxlibres.dll               6.1.7600.16385              UXLib Resources
    uxtheme.dll                6.1.7600.16385                UxTheme (Microsoft)
    v0330cvw.dll               1.12.1.0                    Live! Cam Console
    v0330hwx.dll               1.10.1.0                    HWX Driver
    v0330vfw.dll               1.0.3.6784                  32-bit Video for Windows (VFW) driver
    van.dll                    6.1.7601.17514                
    vault.dll                  6.1.7601.17514                -  Windows
    vaultcli.dll               6.1.7600.16385              Credential Vault Client Library
    vb40016.dll                4.0.24.22                   Visual Basic 4.0 runtime library
    vb40032.dll                4.0.29.24                   Visual Basic 4.0 runtime library
    vbajet32.dll               6.0.1.9431                  Visual Basic for Applications Development Environment - Expression Service Loader
    vbrun100.dll                                           
    vbrun200.dll               2.0.9.8                     Visual Basic 2.0 runtime library
    vbrun300.dll               3.0.5.38                    Visual Basic 3.0 runtime library
    vbscript.dll               5.8.9600.17689              Microsoft  VBScript
    vcamp110.dll               11.0.51106.1                Microsoft C++ AMP Runtime
    vccorlib110.dll            11.0.51106.1                Microsoft  VC WinRT core library
    vccorlib120.dll            12.0.21005.1                Microsoft  VC WinRT core library
    vcomp100.dll               10.0.40219.325              Microsoft C/C++ OpenMP Runtime
    vcomp110.dll               11.0.51106.1                Microsoft C/C++ OpenMP Runtime
    vcomp90.dll                9.0.30729.6161              Microsoft C/C++ OpenMP Runtime
    vdmdbg.dll                 6.1.7600.16385              VDMDBG.DLL
    vds_ps.dll                 6.1.7600.16385              Microsoft Virtual Disk Service proxy/stub
    vdsbas.dll                 6.1.7601.17514                  
    vdsdyn.dll                 6.1.7600.16385                  VDS,  2.1.0.1
    vdsvd.dll                  6.1.7600.16385              VDS Virtual Disk Provider, Version 1.0
    verifier.dll               6.1.7600.16385              Standard application verifier provider dll
    version.dll                6.1.7600.16385              Version Checking and File Installation Libraries
    vfpodbc.dll                1.0.2.0                     vfpodbc
    vfwwdm32.dll               6.1.7601.17514               VfW MM Driver    WDM-
    vidreszr.dll               6.1.7600.16385              Windows Media Resizer
    virtdisk.dll               6.1.7600.16385              Virtual Disk API DLL
    vm3dgl.dll                 2.2.13.0                    VMware SVGA 3D (Microsoft Corporation - WDDM) Usermode OpenGL Driver
    vm3dum.dll                 7.14.1.1131                 VMware SVGA 3D (Microsoft Corporation - WDDM) Usermode
    vmapo232.dll               1.2.16.44                   Creative Audio Processing Object Module
    vmapo32.dll                1.0.54.0                    Creative Audio Processing Object Module
    vmguestlib.dll             8.8.0.7539                  VMware Guest API
    vmguestlibjava.dll         8.8.0.7539                  VMware Guest API Java Support
    vmhgfs.dll                 8.0.45.0                    VMware HGFS Provider
    vmnc.dll                   7.1.2.14247                 VMware Movie decoder
    vmthx32.dll                1.0.15.150                  Creative Audio Processing Object Module
    vp8vfw.dll                 1.2.0.0                     Google VP8 VFW Video Codec
    vpnikeapi.dll              6.1.7601.17514              VPN IKE API's
    vsocklib.dll               9.2.1.0                     VSockets Library
    vss_ps.dll                 6.1.7600.16385              Microsoft Volume Shadow Copy Service proxy/stub
    vssapi.dll                 6.1.7601.17514              Microsoft Volume Shadow Copy Requestor/Writer Services API DLL
    vsstrace.dll               6.1.7600.16385                    Microsoft
    w32topl.dll                6.1.7600.16385              Windows NT Topology Maintenance Tool
    w95inf16.dll               4.71.704.0                  WExtract 16bit Library
    w95inf32.dll               4.71.16.0                   W95INF32
    wab32.dll                  6.1.7601.17699              Microsoft (R) Contacts DLL
    wab32res.dll               6.1.7600.16385               Microsoft (R) DLL
    wabsyncprovider.dll        6.1.7600.16385                 Microsoft Windows
    wavemsp.dll                6.1.7601.17514              Microsoft Wave MSP
    wbemcomn.dll               6.1.7601.17514              WMI
    wbhelp2.dll                1.5.0.0                     WindowBlinds Helper DLL
    wcnapi.dll                 6.1.7600.16385              Windows Connect Now - API Helper DLL
    wcncsvc.dll                6.1.7601.17514                Windows -   
    wcneapauthproxy.dll        6.1.7600.16385              Windows Connect Now - WCN EAP Authenticator Proxy
    wcneappeerproxy.dll        6.1.7600.16385              Windows Connect Now - WCN EAP PEER Proxy
    wcnwiz.dll                 6.1.7600.16385                Windows Connect Now
    wcspluginservice.dll       6.1.7600.16385               DLL WcsPlugInService
    wdc.dll                    6.1.7601.17514               
    wdi.dll                    6.1.7601.18713                Windows
    wdigest.dll                6.1.7601.18779              Microsoft Digest Access
    wdscore.dll                6.1.7601.17514              Panther Engine Module
    webcheck.dll               11.0.9600.16428              -
    webclnt.dll                6.1.7601.18201               DLL - DAV
    webio.dll                  6.1.7601.17725              API    
    webservices.dll            6.1.7601.17514                - Windows
    wecapi.dll                 6.1.7600.16385              Event Collector Configuration API
    wer.dll                    6.1.7601.18381                  Windows
    werdiagcontroller.dll      6.1.7600.16385              WER Diagnostic Controller
    werui.dll                  6.1.7600.16385               DLL      Windows
    wevtapi.dll                6.1.7600.16385              API    
    wevtfwd.dll                6.1.7600.16385              WS-Management Event Forwarding Plug-in
    wfapigp.dll                6.1.7600.16385              Windows Firewall GPO Helper dll
    wfhc.dll                   6.1.7600.16385               Windows.   
    whealogr.dll               6.1.7600.16385                WHEA
    whhelper.dll               6.1.7600.16385              DLL     winHttp
    wiaaut.dll                 6.1.7600.16385               WIA-
    wiadefui.dll               6.1.7601.17514                  WIA
    wiadss.dll                 6.1.7600.16385               WIA -  TWAIN
    wiaextensionhost64.dll     6.1.7600.16385              WIA Extension Host for thunking APIs from 32-bit to 64-bit process
    wiascanprofiles.dll        6.1.7600.16385              Microsoft Windows ScanProfiles
    wiashext.dll               6.1.7600.16385                     
    wiatrace.dll               6.1.7600.16385              WIA Tracing
    wiavideo.dll               6.1.7601.17514              WIA Video
    wimgapi.dll                6.1.7601.17514               Windows Imaging
    win32spl.dll               6.1.7601.18142                    
    winbio.dll                 6.1.7600.16385              API   Windows
    winbrand.dll               6.1.7600.16385              Windows Branding Resources
    wincredprovider.dll        6.1.7601.18409               DLL wincredprovider
    windowsaccessbridge-32.dll  2.0.4.0                     Java Access Bridge for Windows
    windowscodecs.dll          6.2.9200.17251              Microsoft Windows Codecs Library
    windowscodecsext.dll       6.2.9200.16492              Microsoft Windows Codecs Extended Library
    winfax.dll                 6.1.7600.16385              Microsoft  Fax API Support DLL
    winhttp.dll                6.1.7601.17514               HTTP Windows
    wininet.dll                11.0.9600.17689                Win32
    winipsec.dll               6.1.7600.16385              Windows IPsec SPD Client DLL
    winmm.dll                  6.1.7601.17514              MCI API DLL
    winnsi.dll                 6.1.7600.16385              Network Store Information RPC interface
    winrnr.dll                 6.1.7600.16385              LDAP RnR Provider DLL
    winrscmd.dll               6.1.7600.16385              remtsvc
    winrsmgr.dll               6.1.7600.16385              WSMan Shell API
    winrssrv.dll               6.1.7600.16385              winrssrv
    winsatapi.dll              6.1.7601.17514              Windows System Assessment Tool API
    winscard.dll               6.1.7601.17514              API - (Microsoft)
    winshfhc.dll               6.1.7600.16385              File Risk Estimation
    winsockhc.dll              6.1.7600.16385                   Winsock
    winsrpc.dll                6.1.7600.16385              WINS RPC LIBRARY
    winsta.dll                 6.1.7601.18540              Winstation Library
    winsync.dll                2007.94.7600.16385          Synchronization Framework
    winsyncmetastore.dll       2007.94.7600.16385          Windows Synchronization Metadata Store
    winsyncproviders.dll       2007.94.7600.16385          Windows Synchronization Provider Framework
    wintrust.dll               6.1.7601.18741              Microsoft Trust Verification APIs
    winusb.dll                 6.1.7600.16385              Windows USB Driver User Library
    wkscli.dll                 6.1.7601.17514              Workstation Service Client DLL
    wksprtps.dll               6.3.9600.16415              WorkspaceRuntime ProxyStub DLL
    wlanapi.dll                6.1.7600.16385              Windows WLAN AutoConfig Client Side API DLL
    wlancfg.dll                6.1.7600.16385               DLL    Netsh  WLAN
    wlanconn.dll               6.1.7600.16385                Dot11
    wlandlg.dll                6.1.7600.16385                   
    wlangpui.dll               6.1.7601.17514               "   "
    wlanhlp.dll                6.1.7600.16385              Windows Wireless LAN 802.11 Client Side Helper API
    wlaninst.dll               6.1.7600.16385              Windows NET Device Class Co-Installer for Wireless LAN
    wlanmm.dll                 6.1.7600.16385                Dot11   
    wlanmsm.dll                6.1.7601.17514              Windows Wireless LAN 802.11 MSM DLL
    wlanpref.dll               6.1.7601.17514                
    wlansec.dll                6.1.7600.16385              Windows Wireless LAN 802.11 MSM Security Module DLL
    wlanui.dll                 6.1.7601.17514                 
    wlanutil.dll               6.1.7600.16385               DLL     Windows   802.11
    wldap32.dll                6.1.7601.17514              Win32 LDAP API DLL
    wlgpclnt.dll               6.1.7600.16385                 802.11
    wls0wndh.dll               6.1.7600.16385              Session0 Viewer Window Hook DLL
    wmadmod.dll                6.1.7601.17514              Windows Media Audio Decoder
    wmadmoe.dll                6.1.7600.16385              Windows Media Audio 10 Encoder/Transcoder
    wmasf.dll                  12.0.7600.16385             Windows Media ASF DLL
    wmcodecdspps.dll           6.1.7600.16385              Windows Media CodecDSP Proxy Stub Dll
    wmdmlog.dll                12.0.7600.16385             Windows Media Device Manager Logger
    wmdmps.dll                 12.0.7600.16385             Windows Media Device Manager Proxy Stub
    wmdrmdev.dll               12.0.7601.17514             Windows Media DRM for Network Devices Registration DLL
    wmdrmnet.dll               12.0.7601.17514             Windows Media DRM for Network Devices DLL
    wmdrmsdk.dll               11.0.7601.18741             Windows Media DRM SDK DLL
    wmerror.dll                12.0.7600.16385               Windows Media ()
    wmi.dll                    6.1.7601.17787              WMI DC and DP functionality
    wmidx.dll                  12.0.7600.16385             Windows Media Indexer DLL
    wmiprop.dll                6.1.7600.16385                  WDM
    wmnetmgr.dll               12.0.7601.17514             Windows Media Network Plugin Manager DLL
    wmp.dll                    12.0.7601.18741             Windows Media Player
    wmpcm.dll                  12.0.7600.16385             Windows Media Player Compositing Mixer
    wmpdui.dll                 12.0.7600.16385             Windows DirectUser Engine
    wmpdxm.dll                 12.0.7601.17514             Windows Media Player Extension
    wmpeffects.dll             12.0.7601.17514             Windows Media Player Effects
    wmpencen.dll               12.0.7601.17514             Windows Media Player Encoding Module
    wmphoto.dll                6.2.9200.17254               Windows Media
    wmploc.dll                 12.0.7601.18741               Windows Media
    wmpmde.dll                 12.0.7601.17514             WMPMDE DLL
    wmpps.dll                  12.0.7601.17514             Windows Media Player Proxy Stub Dll
    wmpshell.dll               12.0.7601.17514                Windows Media
    wmpsrcwp.dll               12.0.7601.17514             WMPSrcWp Module
    wmsgapi.dll                6.1.7600.16385              WinLogon IPC Client
    wmspdmod.dll               6.1.7601.17514              Windows Media Audio Voice Decoder
    wmspdmoe.dll               6.1.7600.16385              Windows Media Audio Voice Encoder
    wmvcore.dll                12.0.7601.17514             Windows Media Playback/Authoring DLL
    wmvdecod.dll               6.1.7601.18221              Windows Media Video Decoder
    wmvdspa.dll                6.1.7600.16385              Windows Media Video DSP Components - Advanced
    wmvencod.dll               6.1.7600.16385              Windows Media Video 9 Encoder
    wmvsdecd.dll               6.1.7601.17514              Windows Media Screen Decoder
    wmvsencd.dll               6.1.7600.16385              Windows Media Screen Encoder
    wmvxencd.dll               6.1.7600.16385              Windows Media Video Encoder
    wow32.dll                  6.1.7601.18409              Wow32
    wpc.dll                    1.0.0.1                        
    wpcao.dll                  6.1.7600.16385                WPC
    wpcsvc.dll                 1.0.0.1                         Windows
    wpdshext.dll               6.1.7601.17514                  
    wpdshserviceobj.dll        6.1.7601.17514              Windows Portable Device Shell Service Object
    wpdsp.dll                  6.1.7601.17514              WMDM Service Provider for Windows Portable Devices
    wpdwcn.dll                 6.1.7601.17514                    WCN
    wrap_oal.dll               2.2.0.7                     OpenAL32
    ws2_32.dll                 6.1.7601.17514              32-  Windows Socket 2.0
    ws2help.dll                6.1.7600.16385              Windows Socket 2.0 Helper for Windows NT
    wscapi.dll                 6.1.7601.17514              Windows Security Center API
    wscinterop.dll             6.1.7600.16385              Windows Health Center WSC Interop
    wscisvif.dll               6.1.7600.16385              Windows Security Center ISV API
    wscmisetup.dll             6.1.7600.16385              Installers for Winsock Transport and Name Space Providers
    wscproxystub.dll           6.1.7600.16385              Windows Security Center ISV Proxy Stub
    wsdapi.dll                 6.1.7601.17514              -   DLL API- 
    wsdchngr.dll               6.1.7601.17514              WSD Challenge Component
    wsecedit.dll               6.1.7600.16385                 
    wshbth.dll                 6.1.7601.17514              Windows Sockets Helper DLL
    wshcon.dll                 5.8.7600.16385              Microsoft  Windows Script Controller
    wshelper.dll               6.1.7600.16385               DLL    Winsock Net
    wshext.dll                 5.8.7600.16385              Microsoft  Shell Extension for Windows Script Host
    wship6.dll                 6.1.7600.16385               DLL  Winsock2 (TL/IPv6)
    wshirda.dll                6.1.7601.17514              Windows Sockets Helper DLL
    wshqos.dll                 6.1.7600.16385               DLL   QoS Winsock2
    wshrm.dll                  6.1.7600.16385                DLL   Windows  PGM
    wshtcpip.dll               6.1.7600.16385               DLL   Winsock2 (TL/IPv4)
    wsmanmigrationplugin.dll   6.1.7601.18619              WinRM Migration Plugin
    wsmauto.dll                6.1.7601.18619              WSMAN Automation
    wsmplpxy.dll               6.1.7600.16385              wsmplpxy
    wsmres.dll                 6.1.7600.16385               DLL  WSMan
    wsmsvc.dll                 6.1.7601.18619               WSMan
    wsmwmipl.dll               6.1.7601.18619              WSMAN WMI Provider
    wsnmp32.dll                6.1.7601.17514              Microsoft WinSNMP v2.0 Manager API
    wsock32.dll                6.1.7600.16385              Windows Socket 32-Bit DLL
    wtsapi32.dll               6.1.7601.17514              Windows Remote Desktop Session Host Server SDK APIs
    wuapi.dll                  7.6.7600.320                API    Windows
    wudriver.dll               7.6.7600.320                Windows Update WUDriver Stub
    wups.dll                   7.6.7600.320                Windows Update client proxy stub
    wuwebv.dll                 7.6.7600.320                Windows Update Vista Web Control
    wvc.dll                    6.1.7601.17514              Windows Visual Components
    wwanapi.dll                6.1.7600.16385              Mbnapi
    wwapi.dll                  8.1.2.0                     WWAN API
    wzcdlg.dll                 6.1.7600.16385              Windows Connect Now - Flash Config Enrollee
    x3daudio1_0.dll            9.11.519.0                  X3DAudio
    x3daudio1_1.dll            9.15.779.0                  X3DAudio
    x3daudio1_2.dll            9.21.1148.0                 X3DAudio
    x3daudio1_3.dll            9.22.1284.0                 X3DAudio
    x3daudio1_4.dll            9.23.1350.0                 X3DAudio
    x3daudio1_5.dll            9.25.1476.0                 X3DAudio
    x3daudio1_6.dll            9.26.1590.0                 3D Audio Library
    x3daudio1_7.dll            9.28.1886.0                 3D Audio Library
    xactengine2_0.dll          9.11.519.0                  XACT Engine API
    xactengine2_1.dll          9.12.589.0                  XACT Engine API
    xactengine2_10.dll         9.21.1148.0                 XACT Engine API
    xactengine2_2.dll          9.13.644.0                  XACT Engine API
    xactengine2_3.dll          9.14.701.0                  XACT Engine API
    xactengine2_4.dll          9.15.779.0                  XACT Engine API
    xactengine2_5.dll          9.16.857.0                  XACT Engine API
    xactengine2_6.dll          9.17.892.0                  XACT Engine API
    xactengine2_7.dll          9.18.944.0                  XACT Engine API
    xactengine2_8.dll          9.19.1007.0                 XACT Engine API
    xactengine2_9.dll          9.20.1057.0                 XACT Engine API
    xactengine3_0.dll          9.22.1284.0                 XACT Engine API
    xactengine3_1.dll          9.23.1350.0                 XACT Engine API
    xactengine3_2.dll          9.24.1400.0                 XACT Engine API
    xactengine3_3.dll          9.25.1476.0                 XACT Engine API
    xactengine3_4.dll          9.26.1590.0                 XACT Engine API
    xactengine3_5.dll          9.27.1734.0                 XACT Engine API
    xactengine3_6.dll          9.28.1886.0                 XACT Engine API
    xactengine3_7.dll          9.29.1962.0                 XACT Engine API
    xapofx1_0.dll              9.23.1350.0                 XAPOFX
    xapofx1_1.dll              9.24.1400.0                 XAPOFX
    xapofx1_2.dll              9.25.1476.0                 XAPOFX
    xapofx1_3.dll              9.26.1590.0                 Audio Effect Library
    xapofx1_4.dll              9.28.1886.0                 Audio Effect Library
    xapofx1_5.dll              9.29.1962.0                 Audio Effect Library
    xaudio2_0.dll              9.22.1284.0                 XAudio2 Game Audio API
    xaudio2_1.dll              9.23.1350.0                 XAudio2 Game Audio API
    xaudio2_2.dll              9.24.1400.0                 XAudio2 Game Audio API
    xaudio2_3.dll              9.25.1476.0                 XAudio2 Game Audio API
    xaudio2_4.dll              9.26.1590.0                 XAudio2 Game Audio API
    xaudio2_5.dll              9.27.1734.0                 XAudio2 Game Audio API
    xaudio2_6.dll              9.28.1886.0                 XAudio2 Game Audio API
    xaudio2_7.dll              9.29.1962.0                 XAudio2 Game Audio API
    xinput1_1.dll              9.12.589.0                  Microsoft Common Controller API
    xinput1_2.dll              9.14.701.0                  Microsoft Common Controller API
    xinput1_3.dll              9.18.944.0                  Microsoft Common Controller API
    xinput9_1_0.dll            6.1.7600.16385                XNA
    xmlfilter.dll              2008.0.7600.16385            XML
    xmllite.dll                1.3.1001.0                  Microsoft XmlLite Library
    xmlprovi.dll               6.1.7600.16385              Network Provisioning Service Client API
    xmlrw.dll                  2011.110.2809.27            Microsoft XML Slim Library
    xmlrwbin.dll               2011.110.2809.27            Microsoft XML Slim Library
    xolehlp.dll                2001.12.8530.16385          Microsoft Distributed Transaction Coordinator Helper APIs DLL
    xpsfilt.dll                6.1.7600.16385              XML Paper Specification Document IFilter
    xpsgdiconverter.dll        6.2.9200.16492              XPS to GDI Converter
    xpsprint.dll               6.2.9200.16492              XPS Printing DLL
    xpsrasterservice.dll       6.1.7601.17514              XPS Rasterization Service Component
    xpsservices.dll            6.1.7601.17514              Xps Object Model in memory creation and deserialization
    xpsshhdr.dll               6.1.7600.16385              Package Document Shell Extension Handler
    xpssvcs.dll                6.1.7600.16385              Native Code Xps Services Library
    xvidcore.dll                                           
    xvidvfw.dll                                            
    xwizards.dll               6.1.7600.16385                 
    xwreg.dll                  6.1.7600.16385              Extensible Wizard Registration Manager Module
    xwtpdui.dll                6.1.7600.16385                   DUI
    xwtpw32.dll                6.1.7600.16385                   Win32
    zipfldr.dll                6.1.7601.17514               ZIP-


--------[   ]------------------------------------------------------------------------------------------------

     :
                         06.04.2015 20:56:42
                           06.04.2015 20:58:51
                                            06.04.2015 21:13:29
                                             908  (0 ., 0 , 15 , 8 )

      :
                                     20.12.2014 12:08:27
                            20.12.2014 2:29:13
                                        3253306  (37 ., 15 , 41 , 46 )
                                       6058973  (70 ., 3 , 2 , 53 )
                                  349504  (4 ., 1 , 5 , 4 )
                                 269518  (3 ., 2 , 51 , 58 )
                                       241
                                34.94%

      (" "):
                                        20.12.2014 12:21:55
                                     06.04.2015 15:58:08
                                              48

    :
                                                    


--------[   ]-----------------------------------------------------------------------------------------------

    Users                                                                              C:\Users
    ADMIN$                                    Admin                           C:\Windows
    C$                                                           C:\
    E$                                                           E:\
    IPC$                            IPC            IPC                             


--------[  ]------------------------------------------------------------------------------------------------

       :
                                          
                                             zaq-
                              
                      
      ./.                      0 / 42 .
                                  0 
                                     
                                       
                                30 
                                30 


--------[    ]----------------------------------------------------------------------------------------------

    zaq                                           ZAQ-                    zaq-
    zaq                                           ZAQ-                    zaq-


--------[  ]------------------------------------------------------------------------------------------------

  [ HomeGroupUser$ ]

     :
                                         HomeGroupUser$
                                               HomeGroupUser$
                                                       
                                               HomeUsers
                                     0
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [ zaq ]

     :
                                         zaq
                                               zaq
                                               HomeUsers; 
                                     663
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [  ]

     :
                                         
                                               
                                                 /
                                               HomeUsers; 
                                     6
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            

  [  ]

     :
                                         
                                               
                                                      
                                               
                                     0
                                           -

     :
                         
                                     
                             
                                  
                                         
                                      
                            


--------[   ]--------------------------------------------------------------------------------------------

  [ HomeUsers ]

      :
                                             HomeUsers Security Group

     :
      HomeGroupUser$                                    HomeGroupUser$
      zaq                                               
                                           

  [ IIS_IUSRS ]

      :
                                              ,    IIS.

     :
      IUSR                                              

  [  ]

      :
                                               ,         

     :
      zaq                                               
                                           

  [  ]

      :
                                                   ,   ,     "",     .

     :
                                                   

  [   ]

      :
                                                 .

  [   ]

      :
                                                         .

  [    ]

      :
                                                         

  [   ]

      :
                                                        

  [  DCOM ]

      :
                                                 ,     DCOM   .

  [    ]

      :
                                                     ,         ,        .

  [    ]

      :
                                                  ,       

  [     ]

      :
                                                     

  [  ]

      :
                                                         

     :
                                           
                                       

  [  ]

      :
                                                 

  [    ]

      :
                                                      


--------[   ]-------------------------------------------------------------------------------------------

  [ None ]

      :
                                             Ordinary users

     :
      HomeGroupUser$                                    HomeGroupUser$
      zaq                                               
                                           
                                                   


--------[  ]------------------------------------------------------------------------------------------------------

    @Arial Unicode MS                         Swiss                               14 x 43   40 %
    @Arial Unicode MS                         Swiss                             14 x 43   40 %
    @Arial Unicode MS                         Swiss                            14 x 43   40 %
    @Arial Unicode MS                         Swiss                              14 x 43   40 %
    @Arial Unicode MS                         Swiss                               14 x 43   40 %
    @Arial Unicode MS                         Swiss                                  14 x 43   40 %
    @Arial Unicode MS                         Swiss                          14 x 43   40 %
    @Arial Unicode MS                         Swiss                (2312)        14 x 43   40 %
    @Arial Unicode MS                         Swiss                (BIG5)        14 x 43   40 %
    @Arial Unicode MS                         Swiss                                14 x 43   40 %
    @Arial Unicode MS                         Swiss                               14 x 43   40 %
    @Arial Unicode MS                         Swiss                (Johab)         14 x 43   40 %
    @Arial Unicode MS                         Swiss                                14 x 43   40 %
    @Arial Unicode MS                         Swiss                  14 x 43   40 %
    @Arial Unicode MS                         Swiss                               14 x 43   40 %
    @Batang                                   Roman       Regular                      16 x 32   40 %
    @Batang                                   Roman       Regular                       16 x 32   40 %
    @Batang                                   Roman       Regular                        16 x 32   40 %
    @Batang                                   Roman       Regular                   16 x 32   40 %
    @Batang                                   Roman       Regular                        16 x 32   40 %
    @Batang                                   Roman       Regular                         16 x 32   40 %
    @Batang                                   Roman       Regular           16 x 32   40 %
    @BatangChe                                Modern      Regular                      16 x 32   40 %
    @BatangChe                                Modern      Regular                       16 x 32   40 %
    @BatangChe                                Modern      Regular                        16 x 32   40 %
    @BatangChe                                Modern      Regular                   16 x 32   40 %
    @BatangChe                                Modern      Regular                        16 x 32   40 %
    @BatangChe                                Modern      Regular                         16 x 32   40 %
    @BatangChe                                Modern      Regular           16 x 32   40 %
    @DFKai-SB                                 Script      Regular                        16 x 32   40 %
    @DFKai-SB                                 Script      Regular         (BIG5)        16 x 32   40 %
    @Dotum                                    Swiss       Regular                      16 x 32   40 %
    @Dotum                                    Swiss       Regular                       16 x 32   40 %
    @Dotum                                    Swiss       Regular                        16 x 32   40 %
    @Dotum                                    Swiss       Regular                   16 x 32   40 %
    @Dotum                                    Swiss       Regular                        16 x 32   40 %
    @Dotum                                    Swiss       Regular                         16 x 32   40 %
    @Dotum                                    Swiss       Regular           16 x 32   40 %
    @DotumChe                                 Modern      Regular                      16 x 32   40 %
    @DotumChe                                 Modern      Regular                       16 x 32   40 %
    @DotumChe                                 Modern      Regular                        16 x 32   40 %
    @DotumChe                                 Modern      Regular                   16 x 32   40 %
    @DotumChe                                 Modern      Regular                        16 x 32   40 %
    @DotumChe                                 Modern      Regular                         16 x 32   40 %
    @DotumChe                                 Modern      Regular           16 x 32   40 %
    @FangSong                                 Modern                              16 x 32   40 %
    @FangSong                                 Modern               (2312)        16 x 32   40 %
    @Gulim                                    Swiss       Regular                      16 x 32   40 %
    @Gulim                                    Swiss       Regular                       16 x 32   40 %
    @Gulim                                    Swiss       Regular                        16 x 32   40 %
    @Gulim                                    Swiss       Regular                   16 x 32   40 %
    @Gulim                                    Swiss       Regular                        16 x 32   40 %
    @Gulim                                    Swiss       Regular                         16 x 32   40 %
    @Gulim                                    Swiss       Regular           16 x 32   40 %
    @GulimChe                                 Modern      Regular                      16 x 32   40 %
    @GulimChe                                 Modern      Regular                       16 x 32   40 %
    @GulimChe                                 Modern      Regular                        16 x 32   40 %
    @GulimChe                                 Modern      Regular                   16 x 32   40 %
    @GulimChe                                 Modern      Regular                        16 x 32   40 %
    @GulimChe                                 Modern      Regular                         16 x 32   40 %
    @GulimChe                                 Modern      Regular           16 x 32   40 %
    @Gungsuh                                  Roman       Regular                      16 x 32   40 %
    @Gungsuh                                  Roman       Regular                       16 x 32   40 %
    @Gungsuh                                  Roman       Regular                        16 x 32   40 %
    @Gungsuh                                  Roman       Regular                   16 x 32   40 %
    @Gungsuh                                  Roman       Regular                        16 x 32   40 %
    @Gungsuh                                  Roman       Regular                         16 x 32   40 %
    @Gungsuh                                  Roman       Regular           16 x 32   40 %
    @GungsuhChe                               Modern      Regular                      16 x 32   40 %
    @GungsuhChe                               Modern      Regular                       16 x 32   40 %
    @GungsuhChe                               Modern      Regular                        16 x 32   40 %
    @GungsuhChe                               Modern      Regular                   16 x 32   40 %
    @GungsuhChe                               Modern      Regular                        16 x 32   40 %
    @GungsuhChe                               Modern      Regular                         16 x 32   40 %
    @GungsuhChe                               Modern      Regular           16 x 32   40 %
    @KaiTi                                    Modern                              16 x 32   40 %
    @KaiTi                                    Modern               (2312)        16 x 32   40 %
    @Malgun Gothic                            Swiss       Regular                        15 x 43   40 %
    @Malgun Gothic                            Swiss       Regular                         15 x 43   40 %
    @Meiryo UI                                Swiss                             17 x 41   40 %
    @Meiryo UI                                Swiss                              17 x 41   40 %
    @Meiryo UI                                Swiss                               17 x 41   40 %
    @Meiryo UI                                Swiss                          17 x 41   40 %
    @Meiryo UI                                Swiss                               17 x 41   40 %
    @Meiryo UI                                Swiss                  17 x 41   40 %
    @Meiryo UI                                Swiss                               17 x 41   40 %
    @Meiryo                                   Swiss                             31 x 48   40 %
    @Meiryo                                   Swiss                              31 x 48   40 %
    @Meiryo                                   Swiss                               31 x 48   40 %
    @Meiryo                                   Swiss                          31 x 48   40 %
    @Meiryo                                   Swiss                               31 x 48   40 %
    @Meiryo                                   Swiss                  31 x 48   40 %
    @Meiryo                                   Swiss                               31 x 48   40 %
    @Microsoft JhengHei UI                    Swiss                              15 x 41   40 %
    @Microsoft JhengHei UI                    Swiss                               15 x 41   40 %
    @Microsoft JhengHei UI                    Swiss                (BIG5)        15 x 41   40 %
    @Microsoft JhengHei                       Swiss                              15 x 43   40 %
    @Microsoft JhengHei                       Swiss                               15 x 43   40 %
    @Microsoft JhengHei                       Swiss                (BIG5)        15 x 43   40 %
    @Microsoft YaHei UI                       Swiss                              15 x 41   40 %
    @Microsoft YaHei UI                       Swiss                               15 x 41   40 %
    @Microsoft YaHei UI                       Swiss                          15 x 41   40 %
    @Microsoft YaHei UI                       Swiss                (2312)        15 x 41   40 %
    @Microsoft YaHei UI                       Swiss                               15 x 41   40 %
    @Microsoft YaHei UI                       Swiss                  15 x 41   40 %
    @Microsoft YaHei                          Swiss                              15 x 42   40 %
    @Microsoft YaHei                          Swiss                               15 x 42   40 %
    @Microsoft YaHei                          Swiss                          15 x 42   40 %
    @Microsoft YaHei                          Swiss                (2312)        15 x 42   40 %
    @Microsoft YaHei                          Swiss                               15 x 42   40 %
    @Microsoft YaHei                          Swiss                  15 x 42   40 %
    @MingLiU_HKSCS                            Roman       Regular                        16 x 32   40 %
    @MingLiU_HKSCS                            Roman       Regular         (BIG5)        16 x 32   40 %
    @MingLiU_HKSCS-ExtB                       Roman       Regular                        16 x 32   40 %
    @MingLiU_HKSCS-ExtB                       Roman       Regular         (BIG5)        16 x 32   40 %
    @MingLiU                                  Modern      Regular                        16 x 32   40 %
    @MingLiU                                  Modern      Regular         (BIG5)        16 x 32   40 %
    @MingLiU-ExtB                             Roman       Regular                        16 x 32   40 %
    @MingLiU-ExtB                             Roman       Regular         (BIG5)        16 x 32   40 %
    @MS Gothic                                Modern      Regular                      16 x 32   40 %
    @MS Gothic                                Modern      Regular                       16 x 32   40 %
    @MS Gothic                                Modern      Regular                        16 x 32   40 %
    @MS Gothic                                Modern      Regular                   16 x 32   40 %
    @MS Gothic                                Modern      Regular                        16 x 32   40 %
    @MS Gothic                                Modern      Regular           16 x 32   40 %
    @MS Gothic                                Modern      Regular                        16 x 32   40 %
    @MS Mincho                                Modern      Regular                      16 x 32   40 %
    @MS Mincho                                Modern      Regular                       16 x 32   40 %
    @MS Mincho                                Modern      Regular                        16 x 32   40 %
    @MS Mincho                                Modern      Regular                   16 x 32   40 %
    @MS Mincho                                Modern      Regular                        16 x 32   40 %
    @MS Mincho                                Modern      Regular           16 x 32   40 %
    @MS Mincho                                Modern      Regular                        16 x 32   40 %
    @MS PGothic                               Swiss       Regular                      13 x 32   40 %
    @MS PGothic                               Swiss       Regular                       13 x 32   40 %
    @MS PGothic                               Swiss       Regular                        13 x 32   40 %
    @MS PGothic                               Swiss       Regular                   13 x 32   40 %
    @MS PGothic                               Swiss       Regular                        13 x 32   40 %
    @MS PGothic                               Swiss       Regular           13 x 32   40 %
    @MS PGothic                               Swiss       Regular                        13 x 32   40 %
    @MS PMincho                               Roman       Regular                      13 x 32   40 %
    @MS PMincho                               Roman       Regular                       13 x 32   40 %
    @MS PMincho                               Roman       Regular                        13 x 32   40 %
    @MS PMincho                               Roman       Regular                   13 x 32   40 %
    @MS PMincho                               Roman       Regular                        13 x 32   40 %
    @MS PMincho                               Roman       Regular           13 x 32   40 %
    @MS PMincho                               Roman       Regular                        13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                      13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                       13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                        13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                   13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                        13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular           13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular                        13 x 32   40 %
    @NSimSun                                  Modern      Regular                        16 x 32   40 %
    @NSimSun                                  Modern      Regular         (2312)        16 x 32   40 %
    @PMingLiU                                 Roman       Regular                        16 x 32   40 %
    @PMingLiU                                 Roman       Regular         (BIG5)        16 x 32   40 %
    @PMingLiU-ExtB                            Roman       Regular                        16 x 32   40 %
    @PMingLiU-ExtB                            Roman       Regular         (BIG5)        16 x 32   40 %
    @SimHei                                   Modern                              16 x 32   40 %
    @SimHei                                   Modern               (2312)        16 x 32   40 %
    @SimSun                                   Special     Regular                        16 x 32   40 %
    @SimSun                                   Special     Regular         (2312)        16 x 32   40 %
    @SimSun-ExtB                              Modern                              16 x 32   40 %
    @SimSun-ExtB                              Modern               (2312)        16 x 32   40 %
    Aharoni                                   Special                             15 x 32   70 %
    Andalus                                   Roman       Regular                        15 x 49   40 %
    Andalus                                   Roman       Regular                        15 x 49   40 %
    Angsana New                               Roman                                8 x 43   40 %
    Angsana New                               Roman                                 8 x 43   40 %
    AngsanaUPC                                Roman                                8 x 43   40 %
    AngsanaUPC                                Roman                                 8 x 43   40 %
    Aparajita                                 Swiss       Regular                        16 x 38   40 %
    Arabic Typesetting                        Script                               9 x 36   40 %
    Arabic Typesetting                        Script                             9 x 36   40 %
    Arabic Typesetting                        Script                               9 x 36   40 %
    Arabic Typesetting                        Script                               9 x 36   40 %
    Arabic Typesetting                        Script                  9 x 36   40 %
    Arial Black                               Swiss                             18 x 45   90 %
    Arial Black                               Swiss                              18 x 45   90 %
    Arial Black                               Swiss                               18 x 45   90 %
    Arial Black                               Swiss                          18 x 45   90 %
    Arial Black                               Swiss                               18 x 45   90 %
    Arial Black                               Swiss                  18 x 45   90 %
    Arial Narrow                              Swiss                             12 x 36   40 %
    Arial Narrow                              Swiss                              12 x 36   40 %
    Arial Narrow                              Swiss                               12 x 36   40 %
    Arial Narrow                              Swiss                          12 x 36   40 %
    Arial Narrow                              Swiss                               12 x 36   40 %
    Arial Narrow                              Swiss                  12 x 36   40 %
    Arial Unicode MS                          Swiss                               14 x 43   40 %
    Arial Unicode MS                          Swiss                             14 x 43   40 %
    Arial Unicode MS                          Swiss                            14 x 43   40 %
    Arial Unicode MS                          Swiss                              14 x 43   40 %
    Arial Unicode MS                          Swiss                               14 x 43   40 %
    Arial Unicode MS                          Swiss                                  14 x 43   40 %
    Arial Unicode MS                          Swiss                          14 x 43   40 %
    Arial Unicode MS                          Swiss                (2312)        14 x 43   40 %
    Arial Unicode MS                          Swiss                (BIG5)        14 x 43   40 %
    Arial Unicode MS                          Swiss                                14 x 43   40 %
    Arial Unicode MS                          Swiss                               14 x 43   40 %
    Arial Unicode MS                          Swiss                (Johab)         14 x 43   40 %
    Arial Unicode MS                          Swiss                                14 x 43   40 %
    Arial Unicode MS                          Swiss                  14 x 43   40 %
    Arial Unicode MS                          Swiss                               14 x 43   40 %
    Arial                                     Swiss                               14 x 36   40 %
    Arial                                     Swiss                             14 x 36   40 %
    Arial                                     Swiss                            14 x 36   40 %
    Arial                                     Swiss                              14 x 36   40 %
    Arial                                     Swiss                               14 x 36   40 %
    Arial                                     Swiss                                  14 x 36   40 %
    Arial                                     Swiss                          14 x 36   40 %
    Arial                                     Swiss                               14 x 36   40 %
    Arial                                     Swiss                  14 x 36   40 %
    Arimo                                     Swiss       Bold                         19 x 36   70 %
    Arimo                                     Swiss       Bold                        19 x 36   70 %
    Arimo                                     Swiss       Bold                          19 x 36   70 %
    Arimo                                     Swiss       Bold                           19 x 36   70 %
    Arimo                                     Swiss       Bold                              19 x 36   70 %
    Arimo                                     Swiss       Bold                      19 x 36   70 %
    Arimo                                     Swiss       Bold                           19 x 36   70 %
    Arimo                                     Swiss       Bold              19 x 36   70 %
    Batang                                    Roman       Regular                      16 x 32   40 %
    Batang                                    Roman       Regular                       16 x 32   40 %
    Batang                                    Roman       Regular                        16 x 32   40 %
    Batang                                    Roman       Regular                   16 x 32   40 %
    Batang                                    Roman       Regular                        16 x 32   40 %
    Batang                                    Roman       Regular                         16 x 32   40 %
    Batang                                    Roman       Regular           16 x 32   40 %
    BatangChe                                 Modern      Regular                      16 x 32   40 %
    BatangChe                                 Modern      Regular                       16 x 32   40 %
    BatangChe                                 Modern      Regular                        16 x 32   40 %
    BatangChe                                 Modern      Regular                   16 x 32   40 %
    BatangChe                                 Modern      Regular                        16 x 32   40 %
    BatangChe                                 Modern      Regular                         16 x 32   40 %
    BatangChe                                 Modern      Regular           16 x 32   40 %
    Book Antiqua                              Roman                             14 x 40   40 %
    Book Antiqua                              Roman                              14 x 40   40 %
    Book Antiqua                              Roman                               14 x 40   40 %
    Book Antiqua                              Roman                          14 x 40   40 %
    Book Antiqua                              Roman                               14 x 40   40 %
    Book Antiqua                              Roman                  14 x 40   40 %
    Bookman Old Style                         Roman                             16 x 36   30 %
    Bookman Old Style                         Roman                              16 x 36   30 %
    Bookman Old Style                         Roman                               16 x 36   30 %
    Bookman Old Style                         Roman                          16 x 36   30 %
    Bookman Old Style                         Roman                               16 x 36   30 %
    Bookman Old Style                         Roman                  16 x 36   30 %
    Bookshelf Symbol 7                        Special     Regular                      21 x 32   40 %
    Browallia New                             Swiss       Regular                         9 x 40   40 %
    Browallia New                             Swiss       Regular                          9 x 40   40 %
    BrowalliaUPC                              Swiss       Regular                         9 x 40   40 %
    BrowalliaUPC                              Swiss       Regular                          9 x 40   40 %
    Calibri Light                             Swiss       Italic                       17 x 39   30 %
    Calibri Light                             Swiss       Italic                      17 x 39   30 %
    Calibri Light                             Swiss       Italic                        17 x 39   30 %
    Calibri Light                             Swiss       Italic                         17 x 39   30 %
    Calibri Light                             Swiss       Italic                    17 x 39   30 %
    Calibri Light                             Swiss       Italic                         17 x 39   30 %
    Calibri Light                             Swiss       Italic            17 x 39   30 %
    Calibri                                   Swiss       Regular                      17 x 39   40 %
    Calibri                                   Swiss       Regular                     17 x 39   40 %
    Calibri                                   Swiss       Regular                       17 x 39   40 %
    Calibri                                   Swiss       Regular                        17 x 39   40 %
    Calibri                                   Swiss       Regular                   17 x 39   40 %
    Calibri                                   Swiss       Regular                        17 x 39   40 %
    Calibri                                   Swiss       Regular           17 x 39   40 %
    Cambria Math                              Roman       Regular                      20 x 179   40 %
    Cambria Math                              Roman       Regular                     20 x 179   40 %
    Cambria Math                              Roman       Regular                       20 x 179   40 %
    Cambria Math                              Roman       Regular                        20 x 179   40 %
    Cambria Math                              Roman       Regular                   20 x 179   40 %
    Cambria Math                              Roman       Regular                        20 x 179   40 %
    Cambria Math                              Roman       Regular           20 x 179   40 %
    Cambria                                   Roman       Regular                      20 x 38   40 %
    Cambria                                   Roman       Regular                     20 x 38   40 %
    Cambria                                   Roman       Regular                       20 x 38   40 %
    Cambria                                   Roman       Regular                        20 x 38   40 %
    Cambria                                   Roman       Regular                   20 x 38   40 %
    Cambria                                   Roman       Regular                        20 x 38   40 %
    Cambria                                   Roman       Regular           20 x 38   40 %
    Candara                                   Swiss       Regular                      17 x 39   40 %
    Candara                                   Swiss       Regular                     17 x 39   40 %
    Candara                                   Swiss       Regular                       17 x 39   40 %
    Candara                                   Swiss       Regular                        17 x 39   40 %
    Candara                                   Swiss       Regular                   17 x 39   40 %
    Candara                                   Swiss       Regular                        17 x 39   40 %
    Candara                                   Swiss       Regular           17 x 39   40 %
    Century Gothic                            Swiss                             16 x 38   40 %
    Century Gothic                            Swiss                              16 x 38   40 %
    Century Gothic                            Swiss                               16 x 38   40 %
    Century Gothic                            Swiss                          16 x 38   40 %
    Century Gothic                            Swiss                               16 x 38   40 %
    Century Gothic                            Swiss                  16 x 38   40 %
    Century                                   Roman                             15 x 38   40 %
    Century                                   Roman                              15 x 38   40 %
    Century                                   Roman                               15 x 38   40 %
    Century                                   Roman                          15 x 38   40 %
    Century                                   Roman                               15 x 38   40 %
    Century                                   Roman                  15 x 38   40 %
    Comic Sans MS                             Script                            15 x 45   40 %
    Comic Sans MS                             Script                             15 x 45   40 %
    Comic Sans MS                             Script                              15 x 45   40 %
    Comic Sans MS                             Script                         15 x 45   40 %
    Comic Sans MS                             Script                              15 x 45   40 %
    Comic Sans MS                             Script                 15 x 45   40 %
    Consolas                                  Modern      Regular                      18 x 37   40 %
    Consolas                                  Modern      Regular                     18 x 37   40 %
    Consolas                                  Modern      Regular                       18 x 37   40 %
    Consolas                                  Modern      Regular                        18 x 37   40 %
    Consolas                                  Modern      Regular                   18 x 37   40 %
    Consolas                                  Modern      Regular                        18 x 37   40 %
    Consolas                                  Modern      Regular           18 x 37   40 %
    Constantia                                Roman       Regular                      17 x 39   40 %
    Constantia                                Roman       Regular                     17 x 39   40 %
    Constantia                                Roman       Regular                       17 x 39   40 %
    Constantia                                Roman       Regular                        17 x 39   40 %
    Constantia                                Roman       Regular                   17 x 39   40 %
    Constantia                                Roman       Regular                        17 x 39   40 %
    Constantia                                Roman       Regular           17 x 39   40 %
    Corbel                                    Swiss       Regular                      17 x 39   40 %
    Corbel                                    Swiss       Regular                     17 x 39   40 %
    Corbel                                    Swiss       Regular                       17 x 39   40 %
    Corbel                                    Swiss       Regular                        17 x 39   40 %
    Corbel                                    Swiss       Regular                   17 x 39   40 %
    Corbel                                    Swiss       Regular                        17 x 39   40 %
    Corbel                                    Swiss       Regular           17 x 39   40 %
    Cordia New                                Swiss       Regular                         9 x 44   40 %
    Cordia New                                Swiss       Regular                          9 x 44   40 %
    CordiaUPC                                 Swiss       Regular                         9 x 44   40 %
    CordiaUPC                                 Swiss       Regular                          9 x 44   40 %
    Courier New                               Modern                              19 x 36   40 %
    Courier New                               Modern                            19 x 36   40 %
    Courier New                               Modern                           19 x 36   40 %
    Courier New                               Modern                             19 x 36   40 %
    Courier New                               Modern                              19 x 36   40 %
    Courier New                               Modern                                 19 x 36   40 %
    Courier New                               Modern                         19 x 36   40 %
    Courier New                               Modern                              19 x 36   40 %
    Courier New                               Modern                 19 x 36   40 %
    Courier                                   Roman                                  8 x 13   40 %
    DaunPenh                                  Special                             12 x 43   40 %
    David                                     Swiss       Regular                           13 x 31   40 %
    DejaVu Sans Condensed                     Swiss       Bold Oblique                 16 x 37   70 %
    DejaVu Sans Condensed                     Swiss       Bold Oblique                16 x 37   70 %
    DejaVu Sans Condensed                     Swiss       Bold Oblique                  16 x 37   70 %
    DejaVu Sans Condensed                     Swiss       Bold Oblique                   16 x 37   70 %
    DejaVu Sans Condensed                     Swiss       Bold Oblique                      16 x 37   70 %
    DejaVu Sans Condensed                     Swiss       Bold Oblique              16 x 37   70 %
    DejaVu Sans Condensed                     Swiss       Bold Oblique                   16 x 37   70 %
    DejaVu Sans Condensed                     Swiss       Bold Oblique      16 x 37   70 %
    DejaVu Sans Light                         Swiss       ExtraLight                   16 x 37   20 %
    DejaVu Sans Light                         Swiss       ExtraLight                  16 x 37   20 %
    DejaVu Sans Light                         Swiss       ExtraLight                    16 x 37   20 %
    DejaVu Sans Light                         Swiss       ExtraLight                     16 x 37   20 %
    DejaVu Sans Light                         Swiss       ExtraLight                16 x 37   20 %
    DejaVu Sans Light                         Swiss       ExtraLight                     16 x 37   20 %
    DejaVu Sans Light                         Swiss       ExtraLight        16 x 37   20 %
    DejaVu Sans Mono                          Modern      Book                           19 x 37   40 %
    DejaVu Sans Mono                          Modern      Book                         19 x 37   40 %
    DejaVu Sans Mono                          Modern      Book                        19 x 37   40 %
    DejaVu Sans Mono                          Modern      Book                          19 x 37   40 %
    DejaVu Sans Mono                          Modern      Book                           19 x 37   40 %
    DejaVu Sans Mono                          Modern      Book                      19 x 37   40 %
    DejaVu Sans Mono                          Modern      Book                           19 x 37   40 %
    DejaVu Sans Mono                          Modern      Book              19 x 37   40 %
    DejaVu Sans                               Swiss       Book                           16 x 37   40 %
    DejaVu Sans                               Swiss       Book                         16 x 37   40 %
    DejaVu Sans                               Swiss       Book                        16 x 37   40 %
    DejaVu Sans                               Swiss       Book                          16 x 37   40 %
    DejaVu Sans                               Swiss       Book                           16 x 37   40 %
    DejaVu Sans                               Swiss       Book                              16 x 37   40 %
    DejaVu Sans                               Swiss       Book                      16 x 37   40 %
    DejaVu Sans                               Swiss       Book                           16 x 37   40 %
    DejaVu Sans                               Swiss       Book              16 x 37   40 %
    DejaVu Serif Condensed                    Roman       Bold Italic                  16 x 38   70 %
    DejaVu Serif Condensed                    Roman       Bold Italic                   16 x 38   70 %
    DejaVu Serif Condensed                    Roman       Bold Italic                    16 x 38   70 %
    DejaVu Serif Condensed                    Roman       Bold Italic               16 x 38   70 %
    DejaVu Serif Condensed                    Roman       Bold Italic                    16 x 38   70 %
    DejaVu Serif Condensed                    Roman       Bold Italic       16 x 38   70 %
    DejaVu Serif                              Roman       Bold Italic                  18 x 38   70 %
    DejaVu Serif                              Roman       Bold Italic                   18 x 38   70 %
    DejaVu Serif                              Roman       Bold Italic                    18 x 38   70 %
    DejaVu Serif                              Roman       Bold Italic               18 x 38   70 %
    DejaVu Serif                              Roman       Bold Italic                    18 x 38   70 %
    DejaVu Serif                              Roman       Bold Italic       18 x 38   70 %
    DFKai-SB                                  Script      Regular                        16 x 32   40 %
    DFKai-SB                                  Script      Regular         (BIG5)        16 x 32   40 %
    DilleniaUPC                               Roman                                9 x 42   40 %
    DilleniaUPC                               Roman                                 9 x 42   40 %
    DokChampa                                 Swiss                               19 x 62   40 %
    DokChampa                                 Swiss                                19 x 62   40 %
    Dotum                                     Swiss       Regular                      16 x 32   40 %
    Dotum                                     Swiss       Regular                       16 x 32   40 %
    Dotum                                     Swiss       Regular                        16 x 32   40 %
    Dotum                                     Swiss       Regular                   16 x 32   40 %
    Dotum                                     Swiss       Regular                        16 x 32   40 %
    Dotum                                     Swiss       Regular                         16 x 32   40 %
    Dotum                                     Swiss       Regular           16 x 32   40 %
    DotumChe                                  Modern      Regular                      16 x 32   40 %
    DotumChe                                  Modern      Regular                       16 x 32   40 %
    DotumChe                                  Modern      Regular                        16 x 32   40 %
    DotumChe                                  Modern      Regular                   16 x 32   40 %
    DotumChe                                  Modern      Regular                        16 x 32   40 %
    DotumChe                                  Modern      Regular                         16 x 32   40 %
    DotumChe                                  Modern      Regular           16 x 32   40 %
    Ebrima                                    Special                           19 x 43   40 %
    Ebrima                                    Special                             19 x 43   40 %
    Ebrima                                    Special                             19 x 43   40 %
    Ebrima                                    Special                19 x 43   40 %
    Estrangelo Edessa                         Script                              16 x 36   40 %
    EucrosiaUPC                               Roman                                9 x 39   40 %
    EucrosiaUPC                               Roman                                 9 x 39   40 %
    Euphemia                                  Swiss       Regular                        22 x 42   40 %
    FangSong                                  Modern                              16 x 32   40 %
    FangSong                                  Modern               (2312)        16 x 32   40 %
    Fixedsys                                  Swiss                                  8 x 16   40 %
    Franklin Gothic Medium                    Swiss                             14 x 36   40 %
    Franklin Gothic Medium                    Swiss                              14 x 36   40 %
    Franklin Gothic Medium                    Swiss                               14 x 36   40 %
    Franklin Gothic Medium                    Swiss                          14 x 36   40 %
    Franklin Gothic Medium                    Swiss                               14 x 36   40 %
    Franklin Gothic Medium                    Swiss                  14 x 36   40 %
    FrankRuehl                                Swiss       Regular                           13 x 30   40 %
    FreesiaUPC                                Swiss       Regular                         9 x 38   40 %
    FreesiaUPC                                Swiss       Regular                          9 x 38   40 %
    Gabriola                                  Decorative  Regular                      16 x 59   40 %
    Gabriola                                  Decorative  Regular                       16 x 59   40 %
    Gabriola                                  Decorative  Regular                        16 x 59   40 %
    Gabriola                                  Decorative  Regular                   16 x 59   40 %
    Gabriola                                  Decorative  Regular                        16 x 59   40 %
    Gabriola                                  Decorative  Regular           16 x 59   40 %
    Gadugi                                    Swiss                               18 x 43   40 %
    Garamond                                  Roman                             12 x 36   40 %
    Garamond                                  Roman                              12 x 36   40 %
    Garamond                                  Roman                               12 x 36   40 %
    Garamond                                  Roman                          12 x 36   40 %
    Garamond                                  Roman                               12 x 36   40 %
    Garamond                                  Roman                  12 x 36   40 %
    Gautami                                   Swiss       Regular                        18 x 56   40 %
    Gentium Basic                             Special     Regular                        16 x 37   40 %
    Gentium Basic                             Special     Regular                        16 x 37   40 %
    Gentium Basic                             Special     Regular           16 x 37   40 %
    Gentium Book Basic                        Special     Bold                           17 x 37   70 %
    Gentium Book Basic                        Special     Bold                           17 x 37   70 %
    Gentium Book Basic                        Special     Bold              17 x 37   70 %
    Georgia                                   Roman                             14 x 36   40 %
    Georgia                                   Roman                              14 x 36   40 %
    Georgia                                   Roman                               14 x 36   40 %
    Georgia                                   Roman                          14 x 36   40 %
    Georgia                                   Roman                               14 x 36   40 %
    Georgia                                   Roman                  14 x 36   40 %
    Gisha                                     Swiss                               16 x 38   40 %
    Gisha                                     Swiss                                  16 x 38   40 %
    Gulim                                     Swiss       Regular                      16 x 32   40 %
    Gulim                                     Swiss       Regular                       16 x 32   40 %
    Gulim                                     Swiss       Regular                        16 x 32   40 %
    Gulim                                     Swiss       Regular                   16 x 32   40 %
    Gulim                                     Swiss       Regular                        16 x 32   40 %
    Gulim                                     Swiss       Regular                         16 x 32   40 %
    Gulim                                     Swiss       Regular           16 x 32   40 %
    GulimChe                                  Modern      Regular                      16 x 32   40 %
    GulimChe                                  Modern      Regular                       16 x 32   40 %
    GulimChe                                  Modern      Regular                        16 x 32   40 %
    GulimChe                                  Modern      Regular                   16 x 32   40 %
    GulimChe                                  Modern      Regular                        16 x 32   40 %
    GulimChe                                  Modern      Regular                         16 x 32   40 %
    GulimChe                                  Modern      Regular           16 x 32   40 %
    Gungsuh                                   Roman       Regular                      16 x 32   40 %
    Gungsuh                                   Roman       Regular                       16 x 32   40 %
    Gungsuh                                   Roman       Regular                        16 x 32   40 %
    Gungsuh                                   Roman       Regular                   16 x 32   40 %
    Gungsuh                                   Roman       Regular                        16 x 32   40 %
    Gungsuh                                   Roman       Regular                         16 x 32   40 %
    Gungsuh                                   Roman       Regular           16 x 32   40 %
    GungsuhChe                                Modern      Regular                      16 x 32   40 %
    GungsuhChe                                Modern      Regular                       16 x 32   40 %
    GungsuhChe                                Modern      Regular                        16 x 32   40 %
    GungsuhChe                                Modern      Regular                   16 x 32   40 %
    GungsuhChe                                Modern      Regular                        16 x 32   40 %
    GungsuhChe                                Modern      Regular                         16 x 32   40 %
    GungsuhChe                                Modern      Regular           16 x 32   40 %
    Impact                                    Swiss                             13 x 39   40 %
    Impact                                    Swiss                              13 x 39   40 %
    Impact                                    Swiss                               13 x 39   40 %
    Impact                                    Swiss                          13 x 39   40 %
    Impact                                    Swiss                               13 x 39   40 %
    Impact                                    Swiss                  13 x 39   40 %
    IrisUPC                                   Swiss       Regular                         9 x 40   40 %
    IrisUPC                                   Swiss       Regular                          9 x 40   40 %
    Iskoola Pota                              Swiss                               22 x 36   40 %
    JasmineUPC                                Roman       Regular                         9 x 34   40 %
    JasmineUPC                                Roman       Regular                          9 x 34   40 %
    KaiTi                                     Modern                              16 x 32   40 %
    KaiTi                                     Modern               (2312)        16 x 32   40 %
    Kalinga                                   Swiss       Regular                        19 x 48   40 %
    Kartika                                   Roman       Regular                        27 x 46   40 %
    Khmer UI                                  Swiss                               21 x 36   40 %
    KodchiangUPC                              Roman       Regular                         9 x 31   40 %
    KodchiangUPC                              Roman       Regular                          9 x 31   40 %
    Kokila                                    Swiss       Regular                        13 x 37   40 %
    Lao UI                                    Swiss                               18 x 43   40 %
    Latha                                     Swiss       Regular                        23 x 44   40 %
    Leelawadee                                Swiss                               17 x 38   40 %
    Leelawadee                                Swiss                                17 x 38   40 %
    Levenim MT                                Special     Regular                           16 x 42   40 %
    LilyUPC                                   Swiss                                9 x 30   40 %
    LilyUPC                                   Swiss                                 9 x 30   40 %
    Lucida Console                            Modern                             19 x 32   40 %
    Lucida Console                            Modern                              19 x 32   40 %
    Lucida Console                            Modern                         19 x 32   40 %
    Lucida Console                            Modern                              19 x 32   40 %
    Lucida Console                            Modern                 19 x 32   40 %
    Lucida Sans Unicode                       Swiss                             16 x 49   40 %
    Lucida Sans Unicode                       Swiss                              16 x 49   40 %
    Lucida Sans Unicode                       Swiss                               16 x 49   40 %
    Lucida Sans Unicode                       Swiss                                  16 x 49   40 %
    Lucida Sans Unicode                       Swiss                          16 x 49   40 %
    Lucida Sans Unicode                       Swiss                               16 x 49   40 %
    Lucida Sans Unicode                       Swiss                  16 x 49   40 %
    Malgun Gothic                             Swiss       Regular                        15 x 43   40 %
    Malgun Gothic                             Swiss       Regular                         15 x 43   40 %
    Mangal                                    Roman       Regular                        19 x 54   40 %
    Marlett                                   Special     Regular                      31 x 32   50 %
    Meiryo UI                                 Swiss                             17 x 41   40 %
    Meiryo UI                                 Swiss                              17 x 41   40 %
    Meiryo UI                                 Swiss                               17 x 41   40 %
    Meiryo UI                                 Swiss                          17 x 41   40 %
    Meiryo UI                                 Swiss                               17 x 41   40 %
    Meiryo UI                                 Swiss                  17 x 41   40 %
    Meiryo UI                                 Swiss                               17 x 41   40 %
    Meiryo                                    Swiss                             31 x 48   40 %
    Meiryo                                    Swiss                              31 x 48   40 %
    Meiryo                                    Swiss                               31 x 48   40 %
    Meiryo                                    Swiss                          31 x 48   40 %
    Meiryo                                    Swiss                               31 x 48   40 %
    Meiryo                                    Swiss                  31 x 48   40 %
    Meiryo                                    Swiss                               31 x 48   40 %
    Microsoft Himalaya                        Special                             13 x 32   40 %
    Microsoft JhengHei UI                     Swiss                              15 x 41   40 %
    Microsoft JhengHei UI                     Swiss                               15 x 41   40 %
    Microsoft JhengHei UI                     Swiss                (BIG5)        15 x 41   40 %
    Microsoft JhengHei                        Swiss                              15 x 43   40 %
    Microsoft JhengHei                        Swiss                               15 x 43   40 %
    Microsoft JhengHei                        Swiss                (BIG5)        15 x 43   40 %
    Microsoft New Tai Lue                     Swiss       Regular                        19 x 42   40 %
    Microsoft PhagsPa                         Swiss       Regular                        24 x 41   40 %
    Microsoft Sans Serif                      Swiss                               14 x 36   40 %
    Microsoft Sans Serif                      Swiss                             14 x 36   40 %
    Microsoft Sans Serif                      Swiss                            14 x 36   40 %
    Microsoft Sans Serif                      Swiss                              14 x 36   40 %
    Microsoft Sans Serif                      Swiss                               14 x 36   40 %
    Microsoft Sans Serif                      Swiss                                  14 x 36   40 %
    Microsoft Sans Serif                      Swiss                          14 x 36   40 %
    Microsoft Sans Serif                      Swiss                                14 x 36   40 %
    Microsoft Sans Serif                      Swiss                               14 x 36   40 %
    Microsoft Sans Serif                      Swiss                  14 x 36   40 %
    Microsoft Tai Le                          Swiss       Regular                        19 x 41   40 %
    Microsoft Uighur                          Special                             13 x 32   40 %
    Microsoft Uighur                          Special                             13 x 32   40 %
    Microsoft YaHei UI                        Swiss                              15 x 41   40 %
    Microsoft YaHei UI                        Swiss                               15 x 41   40 %
    Microsoft YaHei UI                        Swiss                          15 x 41   40 %
    Microsoft YaHei UI                        Swiss                (2312)        15 x 41   40 %
    Microsoft YaHei UI                        Swiss                               15 x 41   40 %
    Microsoft YaHei UI                        Swiss                  15 x 41   40 %
    Microsoft YaHei                           Swiss                              15 x 42   40 %
    Microsoft YaHei                           Swiss                               15 x 42   40 %
    Microsoft YaHei                           Swiss                          15 x 42   40 %
    Microsoft YaHei                           Swiss                (2312)        15 x 42   40 %
    Microsoft YaHei                           Swiss                               15 x 42   40 %
    Microsoft YaHei                           Swiss                  15 x 42   40 %
    Microsoft Yi Baiti                        Script                              21 x 32   40 %
    MingLiU_HKSCS                             Roman       Regular                        16 x 32   40 %
    MingLiU_HKSCS                             Roman       Regular         (BIG5)        16 x 32   40 %
    MingLiU_HKSCS-ExtB                        Roman       Regular                        16 x 32   40 %
    MingLiU_HKSCS-ExtB                        Roman       Regular         (BIG5)        16 x 32   40 %
    MingLiU                                   Modern      Regular                        16 x 32   40 %
    MingLiU                                   Modern      Regular         (BIG5)        16 x 32   40 %
    MingLiU-ExtB                              Roman       Regular                        16 x 32   40 %
    MingLiU-ExtB                              Roman       Regular         (BIG5)        16 x 32   40 %
    Miriam Fixed                              Modern      Regular                           19 x 32   40 %
    Miriam                                    Swiss       Regular                           13 x 32   40 %
    Modern                                    Modern                     OEM/DOS                 19 x 37   40 %
    Mongolian Baiti                           Script                              14 x 34   40 %
    MoolBoran                                 Swiss                               13 x 43   40 %
    MS Gothic                                 Modern      Regular                      16 x 32   40 %
    MS Gothic                                 Modern      Regular                       16 x 32   40 %
    MS Gothic                                 Modern      Regular                        16 x 32   40 %
    MS Gothic                                 Modern      Regular                   16 x 32   40 %
    MS Gothic                                 Modern      Regular                        16 x 32   40 %
    MS Gothic                                 Modern      Regular           16 x 32   40 %
    MS Gothic                                 Modern      Regular                        16 x 32   40 %
    MS Mincho                                 Modern      Regular                      16 x 32   40 %
    MS Mincho                                 Modern      Regular                       16 x 32   40 %
    MS Mincho                                 Modern      Regular                        16 x 32   40 %
    MS Mincho                                 Modern      Regular                   16 x 32   40 %
    MS Mincho                                 Modern      Regular                        16 x 32   40 %
    MS Mincho                                 Modern      Regular           16 x 32   40 %
    MS Mincho                                 Modern      Regular                        16 x 32   40 %
    MS PGothic                                Swiss       Regular                      13 x 32   40 %
    MS PGothic                                Swiss       Regular                       13 x 32   40 %
    MS PGothic                                Swiss       Regular                        13 x 32   40 %
    MS PGothic                                Swiss       Regular                   13 x 32   40 %
    MS PGothic                                Swiss       Regular                        13 x 32   40 %
    MS PGothic                                Swiss       Regular           13 x 32   40 %
    MS PGothic                                Swiss       Regular                        13 x 32   40 %
    MS PMincho                                Roman       Regular                      13 x 32   40 %
    MS PMincho                                Roman       Regular                       13 x 32   40 %
    MS PMincho                                Roman       Regular                        13 x 32   40 %
    MS PMincho                                Roman       Regular                   13 x 32   40 %
    MS PMincho                                Roman       Regular                        13 x 32   40 %
    MS PMincho                                Roman       Regular           13 x 32   40 %
    MS PMincho                                Roman       Regular                        13 x 32   40 %
    MS Reference Sans Serif                   Swiss                             16 x 39   40 %
    MS Reference Sans Serif                   Swiss                            16 x 39   40 %
    MS Reference Sans Serif                   Swiss                              16 x 39   40 %
    MS Reference Sans Serif                   Swiss                               16 x 39   40 %
    MS Reference Sans Serif                   Swiss                          16 x 39   40 %
    MS Reference Sans Serif                   Swiss                               16 x 39   40 %
    MS Reference Sans Serif                   Swiss                  16 x 39   40 %
    MS Reference Specialty                    Special                           23 x 39   40 %
    MS Sans Serif                             Swiss                                  5 x 13   40 %
    MS Serif                                  Roman                                  5 x 13   40 %
    MS UI Gothic                              Swiss       Regular                      13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                       13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                        13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                   13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                        13 x 32   40 %
    MS UI Gothic                              Swiss       Regular           13 x 32   40 %
    MS UI Gothic                              Swiss       Regular                        13 x 32   40 %
    MT Extra                                  Roman       Regular                      20 x 32   40 %
    MV Boli                                   Special                             18 x 52   40 %
    Narkisim                                  Swiss       Regular                           12 x 32   40 %
    Nirmala UI                                Swiss                               31 x 43   40 %
    NSimSun                                   Modern      Regular                        16 x 32   40 %
    NSimSun                                   Modern      Regular         (2312)        16 x 32   40 %
    Nyala                                     Special                           18 x 33   40 %
    Nyala                                     Special                             18 x 33   40 %
    Nyala                                     Special                             18 x 33   40 %
    Nyala                                     Special                18 x 33   40 %
    OpenSymbol                                Special     Regular                        23 x 32   40 %
    Palatino Linotype                         Roman                             14 x 43   40 %
    Palatino Linotype                         Roman                            14 x 43   40 %
    Palatino Linotype                         Roman                              14 x 43   40 %
    Palatino Linotype                         Roman                               14 x 43   40 %
    Palatino Linotype                         Roman                          14 x 43   40 %
    Palatino Linotype                         Roman                               14 x 43   40 %
    Palatino Linotype                         Roman                  14 x 43   40 %
    Plantagenet Cherokee                      Roman                               14 x 41   40 %
    PMingLiU                                  Roman       Regular                        16 x 32   40 %
    PMingLiU                                  Roman       Regular         (BIG5)        16 x 32   40 %
    PMingLiU-ExtB                             Roman       Regular                        16 x 32   40 %
    PMingLiU-ExtB                             Roman       Regular         (BIG5)        16 x 32   40 %
    Raavi                                     Swiss       Regular                        13 x 53   40 %
    Rod                                       Modern      Regular                           19 x 31   40 %
    Roman                                     Roman                      OEM/DOS                 22 x 37   40 %
    Sakkal Majalla                            Special                             16 x 45   40 %
    Sakkal Majalla                            Special                           16 x 45   40 %
    Sakkal Majalla                            Special                             16 x 45   40 %
    Sakkal Majalla                            Special                             16 x 45   40 %
    Sakkal Majalla                            Special                16 x 45   40 %
    Script                                    Script                     OEM/DOS                 16 x 36   40 %
    Segoe Print                               Special     Regular                      21 x 56   40 %
    Segoe Print                               Special     Regular                       21 x 56   40 %
    Segoe Print                               Special     Regular                        21 x 56   40 %
    Segoe Print                               Special     Regular                   21 x 56   40 %
    Segoe Print                               Special     Regular                        21 x 56   40 %
    Segoe Print                               Special     Regular           21 x 56   40 %
    Segoe Script                              Swiss                             22 x 51   40 %
    Segoe Script                              Swiss                              22 x 51   40 %
    Segoe Script                              Swiss                               22 x 51   40 %
    Segoe Script                              Swiss                          22 x 51   40 %
    Segoe Script                              Swiss                               22 x 51   40 %
    Segoe Script                              Swiss                  22 x 51   40 %
    Segoe UI Light                            Swiss       Regular                      17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                     17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                       17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                        17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                   17 x 43   30 %
    Segoe UI Light                            Swiss       Regular                        17 x 43   30 %
    Segoe UI Light                            Swiss       Regular           17 x 43   30 %
    Segoe UI Semibold                         Swiss       Regular                      18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                     18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                       18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                        18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                   18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular                        18 x 43   60 %
    Segoe UI Semibold                         Swiss       Regular           18 x 43   60 %
    Segoe UI Semilight                        Swiss       Regular                        17 x 43   35 %
    Segoe UI Semilight                        Swiss       Regular                      17 x 43   35 %
    Segoe UI Semilight                        Swiss       Regular                     17 x 43   35 %
    Segoe UI Semilight                        Swiss       Regular                       17 x 43   35 %
    Segoe UI Semilight                        Swiss       Regular                        17 x 43   35 %
    Segoe UI Semilight                        Swiss       Regular                           17 x 43   35 %
    Segoe UI Semilight                        Swiss       Regular                   17 x 43   35 %
    Segoe UI Semilight                        Swiss       Regular                        17 x 43   35 %
    Segoe UI Semilight                        Swiss       Regular           17 x 43   35 %
    Segoe UI Symbol                           Swiss                               23 x 43   40 %
    Segoe UI                                  Swiss                               17 x 43   40 %
    Segoe UI                                  Swiss                             17 x 43   40 %
    Segoe UI                                  Swiss                            17 x 43   40 %
    Segoe UI                                  Swiss                              17 x 43   40 %
    Segoe UI                                  Swiss                               17 x 43   40 %
    Segoe UI                                  Swiss                          17 x 43   40 %
    Segoe UI                                  Swiss                               17 x 43   40 %
    Segoe UI                                  Swiss                  17 x 43   40 %
    Shonar Bangla                             Swiss       Regular                        16 x 41   40 %
    Shruti                                    Swiss       Regular                        14 x 54   40 %
    SimHei                                    Modern                              16 x 32   40 %
    SimHei                                    Modern               (2312)        16 x 32   40 %
    Simplified Arabic Fixed                   Modern      Regular                        19 x 35   40 %
    Simplified Arabic Fixed                   Modern      Regular                        19 x 35   40 %
    Simplified Arabic                         Roman       Regular                        13 x 53   40 %
    Simplified Arabic                         Roman       Regular                        13 x 53   40 %
    SimSun                                    Special     Regular                        16 x 32   40 %
    SimSun                                    Special     Regular         (2312)        16 x 32   40 %
    SimSun-ExtB                               Modern                              16 x 32   40 %
    SimSun-ExtB                               Modern               (2312)        16 x 32   40 %
    Small Fonts                               Swiss                                   1 x 3   40 %
    Sylfaen                                   Roman                             13 x 42   40 %
    Sylfaen                                   Roman                              13 x 42   40 %
    Sylfaen                                   Roman                               13 x 42   40 %
    Sylfaen                                   Roman                          13 x 42   40 %
    Sylfaen                                   Roman                               13 x 42   40 %
    Sylfaen                                   Roman                  13 x 42   40 %
    Symbol                                    Roman                             19 x 39   40 %
    System                                    Swiss                                  7 x 16   70 %
    Tahoma                                    Swiss                               14 x 39   40 %
    Tahoma                                    Swiss                             14 x 39   40 %
    Tahoma                                    Swiss                            14 x 39   40 %
    Tahoma                                    Swiss                              14 x 39   40 %
    Tahoma                                    Swiss                               14 x 39   40 %
    Tahoma                                    Swiss                                  14 x 39   40 %
    Tahoma                                    Swiss                          14 x 39   40 %
    Tahoma                                    Swiss                                14 x 39   40 %
    Tahoma                                    Swiss                               14 x 39   40 %
    Tahoma                                    Swiss                  14 x 39   40 %
    Terminal                                  Modern                     OEM/DOS                  8 x 12   40 %
    Times New Roman                           Roman                               13 x 35   40 %
    Times New Roman                           Roman                             13 x 35   40 %
    Times New Roman                           Roman                            13 x 35   40 %
    Times New Roman                           Roman                              13 x 35   40 %
    Times New Roman                           Roman                               13 x 35   40 %
    Times New Roman                           Roman                                  13 x 35   40 %
    Times New Roman                           Roman                          13 x 35   40 %
    Times New Roman                           Roman                               13 x 35   40 %
    Times New Roman                           Roman                  13 x 35   40 %
    Traditional Arabic                        Roman       Regular                        15 x 48   40 %
    Traditional Arabic                        Roman       Regular                        15 x 48   40 %
    Trebuchet MS                              Swiss                             15 x 37   40 %
    Trebuchet MS                              Swiss                              15 x 37   40 %
    Trebuchet MS                              Swiss                               15 x 37   40 %
    Trebuchet MS                              Swiss                          15 x 37   40 %
    Trebuchet MS                              Swiss                               15 x 37   40 %
    Trebuchet MS                              Swiss                  15 x 37   40 %
    Tunga                                     Swiss       Regular                        18 x 53   40 %
    Utsaah                                    Swiss       Regular                        13 x 36   40 %
    Vani                                      Swiss       Regular                        23 x 54   40 %
    Verdana                                   Swiss                             16 x 39   40 %
    Verdana                                   Swiss                            16 x 39   40 %
    Verdana                                   Swiss                              16 x 39   40 %
    Verdana                                   Swiss                               16 x 39   40 %
    Verdana                                   Swiss                          16 x 39   40 %
    Verdana                                   Swiss                               16 x 39   40 %
    Verdana                                   Swiss                  16 x 39   40 %
    Vijaya                                    Swiss       Regular                        19 x 32   40 %
    Vrinda                                    Swiss       Regular                        20 x 44   40 %
    Webdings                                  Roman                             31 x 32   40 %
    Wingdings 2                               Roman       Regular                      27 x 34   40 %
    Wingdings 3                               Roman       Regular                      25 x 36   40 %
    Wingdings                                 Special     Regular                      28 x 36   40 %


--------[   ]------------------------------------------------------------------------------------------------

  [ AAC ACM Codec ]

      ACM:
                                        AAC ACM Codec
      Copyright-                                   2011 by fccHandler
                                  GNU General Public License
                                         Advanced Audio Codec for Windows ACM
                                          1.09

  [ AC-3 ACM Codec ]

      ACM:
                                        AC-3 ACM Codec
      Copyright-                                   2005-2012 by fccHandler
                                  GNU General Public License
                                         Dolby Digital AC-3 codec for Windows ACM
                                          2.02

  [ ffdshow Audio Decoder ]

      ACM:
                                        ffdshow Audio Decoder
      Copyright-                                  2003-2005 Milan Cutka
                                  GNU GPL
                                         audio decoding and processing
                                          4.00

  [ Fraunhofer IIS MPEG Layer-3 Codec (decode only) ]

      ACM:
                                        Fraunhofer IIS MPEG Layer-3 Codec (decode only)
      Copyright-                                  Copyright  1996-1999 Fraunhofer Institut Integrierte Schaltungen IIS
                                         decoder only version
                                          1.09

  [  ADPCM (Microsoft) ]

      ACM:
                                         ADPCM (Microsoft)
      Copyright-                                    , 1992-1996.
                                             Microsoft ADPCM.
                                          4.00

  [  CCITT G.711 A-Law  u-Law (Microsoft) ]

      ACM:
                                         CCITT G.711 A-Law  u-Law (Microsoft)
      Copyright-                                  ()  , 1993-1996.
                                             CCITT G.711 A-Law / u-Law.
                                          4.00

  [  GSM 6.10 (Microsoft) ]

      ACM:
                                         GSM 6.10 (Microsoft)
      Copyright-                                  ()  , 1993-1996.
                                                 ETSI-GSM (European Telecommunications Standards Institute-Groupe Special Mobile)  6.10.
                                          4.00

  [  IMA ADPCM (Microsoft) ]

      ACM:
                                         IMA ADPCM (Microsoft)
      Copyright-                                    , 1992-1996.
                                             IMA ADPCM.
                                          4.00

  [  PCM Microsoft ]

      ACM:
                                         PCM Microsoft
      Copyright-                                    , 1992-1996.
                                                PCM.
                                          5.00

  [   Indeo audio ]

      ACM:
                                          Indeo audio
      Copyright-                                   Intel Corporation, 1997
                                           Indeo audio
                                          2.05


--------[   ]------------------------------------------------------------------------------------------------

    C:\PROGRA~2\x264vfw\x264vfw.dll  38_2274bm_36885                     x264vfw - H.264/MPEG-4 AVC codec
    C:\Windows\system32\utv_vcm.dll                                      
    C:\Windows\SysWOW64\CamCodec.dll  1.5.0.0                             
    C:\Windows\SysWOW64\CFHD.dll  3.2.2.185                           
    C:\Windows\SysWOW64\GeoCodec.dll  8.4.0.0                             
    C:\Windows\SysWOW64\GeoCodecD.dll  8.4.0.0                             
    C:\Windows\SysWOW64\ir41_32.dll  R4.11.15.94                         
    C:\Windows\SysWOW64\ir50_32.dll  R.5.10.15.2.55                      
    C:\Windows\SysWOW64\mlc.dll                                      
    C:\Windows\SysWOW64\vmnc.dll  7.1.2 build-301548                  
    C:\Windows\SysWOW64\vp8vfw.dll  1.2.0.0                             
    CamCodec.dll               1.5.0.0                             CamStudio Lossless Codec
    CFHD.dll                   3.2.2.185                           CineForm HD CODEC
    ff_vfw.dll                 1.3.4530.0                          FFDShow Video Encoder
    GeoCodec.dll               8.4.0.0                             GeoVision MPEG4
    GeoCodecD.dll              8.4.0.0                             GeoVision MPEG4 Decoder
    iccvid.dll                 1.10.0.11                            Cinepak
    ir41_32.dll                R4.11.15.94                         Indeo Video v.4.1 codec
    ir50_32.dll                R.5.10.15.2.55                      Ligos Indeo XP v.5.2 codec
    iyuv_32.dll                6.1.7600.16385 (win7_rtm.090713-1255)  Intel Indeo(R) Video YUV 
    lagarith.dll               1.3.27                              Lagarith lossless codec [LAGS]
    mlc.dll                                                        MLC Lossless Codec [MLCY]
    msrle32.dll                6.1.7600.16385 (win7_rtm.090713-1255)  Microsoft RLE Compressor
    msvidc32.dll               6.1.7600.16385 (win7_rtm.090713-1255)    Microsoft Video 1
    msyuv.dll                  6.1.7601.17514 (win7sp1_rtm.101119-1850)  Microsoft UYVY Video Decompressor
    tsbyuv.dll                 6.1.7601.17514 (win7sp1_rtm.101119-1850)  Toshiba Video Codec
    vmnc.dll                   7.1.2 build-301548                  VMnc lossless codec [VMnc]
    vp8vfw.dll                 1.2.0.0                             VP8 Video Codec
    xvidvfw.dll                                                    Xvid MPEG-4 Video Codec


--------[ MCI ]---------------------------------------------------------------------------------------------------------

  [ AVIVideo ]

      MCI:
                                              AVIVideo
                                                       Windows
                                                 MCI Video  Windows
                                                     Digital Video Device
                                                 mciavi32.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                 
                                                  
                                        
      ''                             
                                      
                                         
                                         
                                            
                                          
                                          
                                

  [ CDAudio ]

      MCI:
                                              CDAudio
                                                 MCI   cdaudio
                                                 mcicda.dll
                                                  

  [ MPEGVideo ]

      MCI:
                                              MPEGVideo
                                                     DirectShow
                                                 MCI DirectShow
                                                     Digital Video Device
                                                 mciqtz32.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                 
                                                  
                                        
      ''                             
                                      
                                         
                                         
                                            
                                          
                                          
                                

  [ Sequencer ]

      MCI:
                                              Sequencer
                                                      MIDI
                                                 MCI   MIDI
                                                     Sequencer Device
                                                 mciseq.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                                  
                                        
                                          
                                          

  [ WaveAudio ]

      MCI:
                                              WaveAudio
                                                     Sound
                                                 MCI   
                                                     Waveform Audio Device
                                                 mciwave.dll
                                                  

      MCI:
                                     
                                  
                                      
                                         
                                                  
                                        
                                          
                                          


--------[ SAPI ]--------------------------------------------------------------------------------------------------------

     SAPI:
       SAPI4                                      -
       SAPI5                                      5.3.13120.0

     (SAPI5):
                                                     Microsoft Anna - English (United States)
                                                Microsoft Anna - English (United States)
                                               M1033DSK
                                              C:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\en-US\enu-dsk
                                                 
                                                     
                                                     ()
                                           Microsoft
                                                  2.0
       DLL                                          C:\Program Files (x86)\Common Files\SpeechEngines\Microsoft\TTS20\MSTTSEngine.dll  (x86)
      CLSID                                             {F51C7B23-6566-424C-94CF-2C4F83EE96FF}
      Frontend                                          {55DFB4F7-4175-4B3B-B247-D9B399ADB119}


--------[ IAM ]---------------------------------------------------------------------------------------------------------

  [ Microsoft Communities ]

      :
                                        Microsoft Communities
      ID                                   account{FDCEFD64-CBBE-4C5F-888B-FAACC01B657C}.oeaccount
                                         ( )
                                           Microsoft Windows Mail
                                                (IE  )
      NNTP-                                       msnews.microsoft.com

      :
        NNTP                                
        NNTP                     
        NNTP                        
         NNTP             
       NNTP                
       NNTP   HTML                         

  [ Active Directory ]

      :
                                        Active Directory
      ID                                   account{99481E7C-C205-445C-BD9A-74CB0DD8A45B}.oeaccount
                                        LDAP
                                           Microsoft Windows Mail
                                                (IE  )
      LDAP-                                       NULL:3268
        LDAP                             NULL
        LDAP                               NULL
        LDAP                               1 

      :
        LDAP                      
        LDAP                     
        LDAP                        
         LDAP                     

  [    VeriSign ]

      :
                                           VeriSign
      ID                                   account{BD84E639-A69B-4DD7-A772-B7C36FAFD4DF}.oeaccount
                                        LDAP
                                           Microsoft Windows Mail
                                                (IE  )
      LDAP-                                       directory.verisign.com
      LDAP URL                                          http://www.verisign.com
        LDAP                               NULL
        LDAP                               1 

      :
        LDAP                      
        LDAP                     
        LDAP                        
         LDAP                     


--------[  ]----------------------------------------------------------------------------------------------------

     :
                                        http://mail.ru/cnt/10445?gp=profitraf5
                                          http://go.microsoft.com/fwlink/?LinkId=54896
                                       C:\Windows\system32\blank.htm
                               

     :
                                            

    LAN-:
                                            


--------[  ]----------------------------------------------------------------------------------------------------

                  0.0.0.0          0.0.0.0      192.168.1.1  20   192.168.1.5 (Realtek PCIe GBE Family Controller)
                127.0.0.0        255.0.0.0        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
                127.0.0.1  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
          127.255.255.255  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
              192.168.1.0    255.255.255.0      192.168.1.5  276  192.168.1.5 (Realtek PCIe GBE Family Controller)
              192.168.1.5  255.255.255.255      192.168.1.5  276  192.168.1.5 (Realtek PCIe GBE Family Controller)
            192.168.1.255  255.255.255.255      192.168.1.5  276  192.168.1.5 (Realtek PCIe GBE Family Controller)
                224.0.0.0        240.0.0.0        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
                224.0.0.0        240.0.0.0      192.168.1.5  276  192.168.1.5 (Realtek PCIe GBE Family Controller)
          255.255.255.255  255.255.255.255        127.0.0.1  306  127.0.0.1 (Software Loopback Interface 1)
          255.255.255.255  255.255.255.255      192.168.1.5  276  192.168.1.5 (Realtek PCIe GBE Family Controller)


--------[ IE Cookie ]---------------------------------------------------------------------------------------------------

    2015-03-31 01:33:11  zaq@yandex.ru/
    2015-03-31 01:33:12  zaq@ledbin.ru/
    2015-03-31 01:33:12  zaq@mail.ru/
    2015-03-31 01:33:12  zaq@yadro.ru/
    2015-04-01 14:56:43  zaq@~~local~~/
    2015-04-01 14:56:43  zaq@~~local~~/C:/Users/zaq/AppData/Local/Skype/Apps/login/
    2015-04-05 12:15:17  zaq@doubleclick.net/
    2015-04-05 12:15:17  zaq@mathtag.com/
    2015-04-05 12:15:17  zaq@mookie1.com/
    2015-04-05 12:15:17  zaq@openx.net/
    2015-04-05 12:15:17  zaq@pixel.rubiconproject.com/
    2015-04-05 12:15:17  zaq@rubiconproject.com/
    2015-04-05 12:15:17  zaq@yahoo.com/
    2015-04-05 12:20:18  zaq@adadvisor.net/
    2015-04-05 12:20:19  zaq@adform.net/
    2015-04-05 12:20:19  zaq@adgrx.com/
    2015-04-05 12:20:19  zaq@adsrvr.org/
    2015-04-05 12:20:19  zaq@c1.adform.net/
    2015-04-05 12:20:19  zaq@eqads.com/
    2015-04-05 12:20:19  zaq@rlcdn.com/
    2015-04-05 12:20:19  zaq@w55c.net/
    2015-04-05 12:25:20  zaq@skimresources.com/
    2015-04-05 12:25:21  zaq@agkn.com/
    2015-04-05 12:25:21  zaq@bluekai.com/
    2015-04-05 12:25:21  zaq@burstnet.com/
    2015-04-05 12:25:22  zaq@adsymptotic.com/
    2015-04-05 12:25:23  zaq@ib.ap.ib-ibi.com/
    2015-04-05 12:30:22  zaq@sitescout.com/
    2015-04-05 12:30:23  zaq@everesttech.net/
    2015-04-05 12:53:32  zaq@contextweb.com/
    2015-04-05 22:22:01  zaq@bs.serving-sys.com/
    2015-04-05 22:22:01  zaq@serving-sys.com/
    2015-04-06 00:34:05  zaq@adriver.ru/
    2015-04-06 14:36:21  zaq@serving.plexop.net/
    2015-04-06 14:37:55  zaq@gwallet.com/
    2015-04-06 14:37:55  zaq@revsci.net/
    2015-04-06 14:37:55  zaq@rs.gwallet.com/
    2015-04-06 17:37:41  zaq@retargetads.ru/
    2015-04-06 19:50:53  zaq@c.bing.com/
    2015-04-06 21:02:05  zaq@c.msn.com/
    2015-04-06 21:02:09  zaq@skype.com/
    2015-04-06 21:02:22  zaq@adnxs.com/


--------[   ]--------------------------------------------------------------------------------------------

    2015-03-31 01:32:26  zaq@file:///C:/Users/zaq/Desktop/ledbin-patch.rar
    2015-03-31 01:33:12  zaq@http://ledbin.ru/update/index.html
    2015-03-31 01:35:49  zaq@file:///C:/Users/zaq/Documents/ledbin.ru-64bitindaass.txt
    2015-04-01 01:40:59  zaq@file:///C:/Users/zaq/Downloads/jAB2kN4FFlA%20(1).jpg
    2015-04-04 11:54:37  zaq@file:///C:/Users/zaq/Desktop/д/Укладка%20пациента%20с%20парализованными%20конечностями.docx
    2015-04-04 11:55:09  zaq@file:///C:/Users/zaq/Desktop/д/Медицинская%20помощь%20с%20ЧМТ.docx
    2015-04-04 11:58:30  zaq@file:///C:/Users/zaq/Desktop/д/Аллергический%20дерматит.docx
    2015-04-04 11:58:34  zaq@file:///C:/Users/zaq/Desktop/д/Высыпания.docx
    2015-04-04 11:58:41  zaq@file:///C:/Users/zaq/Desktop/д/Люмбальная%20пункция.docx
    2015-04-04 11:58:45  zaq@file:///C:/Users/zaq/Desktop/д/Токсикодермия.docx
    2015-04-04 12:25:40  zaq@file:///C:/Users/zaq/Documents/TaiGJBreak_1210.zip
    2015-04-04 12:47:04  zaq@file:///C:/Users/zaq/Documents/redsn0w_win_0.9.15b3.zip
    2015-04-04 12:57:50  zaq@file:///C:/Users/zaq/Documents/iPad2,2_8.1.2_12B440_Restore.ipsw
    2015-04-04 13:14:51  zaq@file:///C:/Users/zaq/Desktop/iPad2,2_8.1.2_12B440_Restore.ipsw
    2015-04-05 12:49:11  zaq@file:///C:/Users/zaq/Documents/CBcfg.rar
    2015-04-06 00:34:05  zaq@http://ad.adriver.ru/cgi-bin/erle.cgi?sid=1&bt=40&ad=510041&pid=1875177&bn=1875177&rnd=217153994&tail256=unknown
    2015-04-06 14:36:21  zaq@https://serving.plexop.net/pserving/9/1/9_5863.htm?rdclick=&rand=635601829594779697
    2015-04-06 16:14:41  zaq@https://apps.skype.com/incalladwidget/
    2015-04-06 16:56:05  zaq@file:///C:/Users/zaq/Documents/Документация.docx
    2015-04-06 16:57:15  zaq@file:///C:/Users/zaq/Documents/patch_pvplite.zip
    2015-04-06 17:05:51  zaq@https://apps.skype.com/chatadwidget/?containerType=LER
    2015-04-06 17:06:11  zaq@file:///C:/Users/zaq/Documents/Bandicam/bandicam%202015-04-06%2017-05-38-655.jpg
    2015-04-06 17:06:21  zaq@file:///C:/Users/zaq/AppData/Roaming/Skype/whitewarfare/media_messaging/media_cache/i2%5Ecimgpsh_orig.jpg
    2015-04-06 17:12:30  zaq@https://az361816.vo.msecnd.net/flextag/flextag.html?guid=d2cfae3a-4559-4ce5-b391-5d13df86f34c
    2015-04-06 17:12:31  zaq@https://apps.skype.com/chatadwidget/?containerType=NR
    2015-04-06 17:37:40  zaq@https://az361816.vo.msecnd.net/flextag/flextag.html?guid=1840523d-0144-44ec-89d2-f681ed2c8daf
    2015-04-06 19:33:42  zaq@file:///C:/Users/zaq/Desktop/Новая%20папка%20(4)/Windows6.1-KB980932-x64.msu
    2015-04-06 20:07:55  zaq@file:///C:/Users/zaq/Documents/kdfe.zip
    2015-04-06 20:50:13  zaq@file:///C:/Windows/Minidump/Minidump.rar
    2015-04-06 20:52:12  zaq@file:///C:/Users/zaq/Desktop/Новая%20папка%20(5)/Новая%20папка%20(5).rar
    2015-04-06 20:55:01  zaq@file:///C:/Users/zaq/Desktop/Новый%20текстовый%20документ%20(2).txt
    2015-04-06 21:01:14  zaq@https://apps.skype.com/adcontrol/prelogic.html
    2015-04-06 21:01:16  zaq@https://apps.skype.com/home/?uiversion=7.2.0.103&language=ru
    2015-04-06 21:01:48  zaq@https://m.hotmail.com/
    2015-04-06 21:01:49  zaq@https://s-static.ak.facebook.com/connect/xd_arbiter/6Dg4oLkBbYq.js?version=41
    2015-04-06 21:02:15  zaq@https://apps.skype.com/shared/adexpert/frame-hider.html
    2015-04-06 21:02:16  zaq@about:blank
    2015-04-06 21:02:16  zaq@https://static.skypeassets.com/adserver/AdLoader.html?version=1.66.1
    2015-04-06 21:02:21  zaq@https://az361816.vo.msecnd.net/flextag/flextag.html?guid=a486a9d6-cf19-4256-adb6-0028f1ee17ff
    2015-04-06 21:03:37  zaq@file:///C:/Users/zaq/Desktop/Документ%20Microsoft%20Word.docx
    2015-04-06 21:04:49  zaq@file:///C:/Users/zaq/Desktop/Новая%20папка%20(5).rar
    2015-04-06 21:08:40  zaq@file:///C:/Users/zaq/AppData/Local/Temp/rpt-1.txt


--------[  DirectX ]-----------------------------------------------------------------------------------------------

    amstream.dll                              6.06.7601.17514   Final Retail                         70656  21.11.2010 6:24:00
    bdaplgin.ax                               6.01.7600.16385   Final Retail                         74240  14.07.2009 4:14:10
    d2d1.dll                                  6.02.9200.16765   Final Retail  Russian                     3419136  06.05.2014 17:53:12
    d3d10.dll                                 6.02.9200.16492   Final Retail  English                     1080832  06.05.2014 17:31:54
    d3d10_1.dll                               6.02.9200.16492   Final Retail  English                      161792  06.05.2014 17:31:54
    d3d10_1core.dll                           6.02.9200.16492   Final Retail  English                      249856  06.05.2014 17:31:54
    d3d10core.dll                             6.02.9200.16492   Final Retail  English                      220160  06.05.2014 17:31:54
    d3d10level9.dll                           6.02.9200.16492   Final Retail  English                      604160  06.05.2014 17:31:54
    d3d10warp.dll                             6.02.9200.17033   Final Retail  English                     1987584  24.06.2014 5:59:50
    d3d11.dll                                 6.02.9200.16570   Final Retail  English                     1505280  06.05.2014 17:42:42
    d3d8.dll                                  6.01.7600.16385   Final Retail                    1036800  14.07.2009 4:15:08
    d3d8thk.dll                               6.01.7600.16385   Final Retail                      11264  14.07.2009 4:15:08
    d3d9.dll                                  6.01.7601.17514   Final Retail                    1828352  21.11.2010 6:24:23
    d3dim.dll                                 6.01.7600.16385   Final Retail                     386048  14.07.2009 4:15:08
    d3dim700.dll                              6.01.7600.16385   Final Retail                     817664  14.07.2009 4:15:08
    d3dramp.dll                               6.01.7600.16385   Final Retail                     593920  14.07.2009 4:15:08
    d3dxof.dll                                6.01.7600.16385   Final Retail                      53760  14.07.2009 4:15:08
    ddraw.dll                                 6.01.7600.16385   Final Retail                        531968  14.07.2009 4:15:10
    ddrawex.dll                               6.01.7600.16385   Final Retail                      30208  14.07.2009 4:15:10
    devenum.dll                               6.06.7600.16385   Final Retail                         66560  14.07.2009 4:15:10
    dinput.dll                                6.01.7600.16385   Final Retail                        136704  14.07.2009 4:15:11
    dinput8.dll                               6.01.7600.16385   Final Retail                        145408  14.07.2009 4:15:11
    dmband.dll                                6.01.7600.16385   Final Retail                      30720  14.07.2009 4:15:12
    dmcompos.dll                              6.01.7600.16385   Final Retail                      63488  14.07.2009 4:15:12
    dmime.dll                                 6.01.7600.16385   Final Retail                     179712  14.07.2009 4:15:12
    dmloader.dll                              6.01.7600.16385   Final Retail                      38400  14.07.2009 4:15:12
    dmscript.dll                              6.01.7600.16385   Final Retail                      86016  14.07.2009 4:15:12
    dmstyle.dll                               6.01.7600.16385   Final Retail                     105984  14.07.2009 4:15:12
    dmsynth.dll                               6.01.7600.16385   Final Retail                     105472  14.07.2009 4:15:12
    dmusic.dll                                6.01.7600.16385   Final Retail                        101376  14.07.2009 4:15:12
    dplaysvr.exe                              6.01.7600.16385   Final Retail                         29184  14.07.2009 4:14:18
    dplayx.dll                                6.01.7600.16385   Final Retail                     213504  14.07.2009 4:15:12
    dpmodemx.dll                              6.01.7600.16385   Final Retail                         23040  14.07.2009 4:15:12
    dpnaddr.dll                               6.01.7601.17514   Final Retail                       2560  21.11.2010 6:23:53
    dpnathlp.dll                              6.01.7600.16385   Final Retail  English                       57344  14.07.2009 4:15:14
    dpnet.dll                                 6.01.7601.17989   Final Retail                        376832  06.05.2014 17:37:51
    dpnhpast.dll                              6.01.7600.16385   Final Retail                       7168  14.07.2009 4:15:12
    dpnhupnp.dll                              6.01.7600.16385   Final Retail                       7168  14.07.2009 4:15:12
    dpnlobby.dll                              6.01.7600.16385   Final Retail                       2560  14.07.2009 4:04:52
    dpnsvr.exe                                6.01.7600.16385   Final Retail                         33280  14.07.2009 4:14:18
    dpwsockx.dll                              6.01.7600.16385   Final Retail                         44032  14.07.2009 4:15:12
    dsdmo.dll                                 6.01.7600.16385   Final Retail                     173568  14.07.2009 4:15:13
    dsound.dll                                6.01.7600.16385   Final Retail                        453632  14.07.2009 4:15:13
    dswave.dll                                6.01.7600.16385   Final Retail                      20992  14.07.2009 4:15:13
    dwrite.dll                                6.02.9200.16571   Final Retail  Russian                     1247744  06.05.2014 17:43:00
    dxdiagn.dll                               6.01.7601.17514   Final Retail                        210432  21.11.2010 6:24:22
    dxgi.dll                                  6.02.9200.16492   Final Retail  English                      293376  06.05.2014 17:31:54
    dxmasf.dll                                12.00.7601.18741  Final Retail                       4096  03.02.2015 6:12:32
    dxtmsft.dll                               11.00.9600.17690  Final Retail  English                      418304  21.02.2015 3:28:00
    dxtrans.dll                               11.00.9600.17690  Final Retail  English                      285696  21.02.2015 3:27:56
    dxva2.dll                                 6.01.7600.16385   Final Retail  English                       88064  14.07.2009 4:15:14
    encapi.dll                                6.01.7600.16385   Final Retail                      20992  14.07.2009 4:15:14
    gcdef.dll                                 6.01.7600.16385   Final Retail                        120832  14.07.2009 4:15:22
    iac25_32.ax                               2.00.0005.0053    Final Retail                        197632  14.07.2009 4:14:10
    ir41_32.ax                                4.51.0016.0003    Final Retail                        839680  14.07.2009 4:14:10
    ir41_qc.dll                               4.30.0062.0002    Final Retail                     120320  14.07.2009 4:15:34
    ir41_qcx.dll                              4.30.0062.0002    Final Retail                     120320  14.07.2009 4:15:34
    ir50_32.dll                               5.2562.0015.0055  Final Retail                        746496  14.07.2009 4:15:34
    ir50_qc.dll                               5.00.0063.0048    Final Retail                     200192  14.07.2009 4:15:34
    ir50_qcx.dll                              5.00.0063.0048    Final Retail                     200192  14.07.2009 4:15:34
    ivfsrc.ax                                 5.10.0002.0051    Final Retail                        146944  14.07.2009 4:14:10
    joy.cpl                                   6.01.7600.16385   Final Retail                        138240  14.07.2009 4:14:09
    ksproxy.ax                                6.01.7601.17514   Final Retail                        193536  21.11.2010 6:24:32
    kstvtune.ax                               6.01.7601.17514   Final Retail                         84480  21.11.2010 6:25:10
    ksuser.dll                                6.01.7600.16385   Final Retail                          4608  14.07.2009 4:15:35
    kswdmcap.ax                               6.01.7601.17514   Final Retail                        107008  21.11.2010 6:24:15
    ksxbar.ax                                 6.01.7601.17514   Final Retail                         48640  21.11.2010 6:25:10
    mciqtz32.dll                              6.06.7601.17514   Final Retail                         36352  21.11.2010 6:24:00
    mfc40.dll                                 4.01.0000.6151    Beta Retail                         954752  21.11.2010 6:24:00
    mfc42.dll                                 6.06.8064.0000    Beta Retail                        1137664  06.05.2014 17:22:31
    Microsoft.DirectX.AudioVideoPlayback.dll  5.04.0000.2904    Final Retail                      53248  29.03.2015 23:19:46
    Microsoft.DirectX.Diagnostics.dll         5.04.0000.2904    Final Retail                      12800  29.03.2015 23:19:46
    Microsoft.DirectX.Direct3D.dll            9.05.0132.0000    Final Retail                     473600  29.03.2015 23:19:46
    Microsoft.DirectX.Direct3DX.dll           5.04.0000.3900    Final Retail                    2676224  29.03.2015 23:19:43
    Microsoft.DirectX.Direct3DX.dll           9.04.0091.0000    Final Retail                    2846720  29.03.2015 23:19:43
    Microsoft.DirectX.Direct3DX.dll           9.05.0132.0000    Final Retail                     563712  29.03.2015 23:19:44
    Microsoft.DirectX.Direct3DX.dll           9.06.0168.0000    Final Retail                     567296  29.03.2015 23:19:44
    Microsoft.DirectX.Direct3DX.dll           9.07.0239.0000    Final Retail                     576000  29.03.2015 23:19:44
    Microsoft.DirectX.Direct3DX.dll           9.08.0299.0000    Final Retail                     577024  29.03.2015 23:19:44
    Microsoft.DirectX.Direct3DX.dll           9.09.0376.0000    Final Retail                     577536  29.03.2015 23:19:44
    Microsoft.DirectX.Direct3DX.dll           9.10.0455.0000    Final Retail                     577536  29.03.2015 23:19:45
    Microsoft.DirectX.Direct3DX.dll           9.11.0519.0000    Final Retail                     578560  29.03.2015 23:19:45
    Microsoft.DirectX.Direct3DX.dll           9.12.0589.0000    Final Retail                     578560  29.03.2015 23:19:46
    Microsoft.DirectX.DirectDraw.dll          5.04.0000.2904    Final Retail                     145920  29.03.2015 23:19:46
    Microsoft.DirectX.DirectInput.dll         5.04.0000.2904    Final Retail                     159232  29.03.2015 23:19:47
    Microsoft.DirectX.DirectPlay.dll          5.04.0000.2904    Final Retail                     364544  29.03.2015 23:19:48
    Microsoft.DirectX.DirectSound.dll         5.04.0000.2904    Final Retail                     178176  29.03.2015 23:19:48
    Microsoft.DirectX.dll                     5.04.0000.2904    Final Retail                     223232  29.03.2015 23:19:45
    mpeg2data.ax                              6.06.7601.17514   Final Retail                         72704  21.11.2010 6:25:10
    mpg2splt.ax                               6.06.7601.17528   Final Retail                     199680  06.05.2014 17:22:15
    msdmo.dll                                 6.06.7601.17514   Final Retail                      30720  21.11.2010 6:24:02
    msdvbnp.ax                                6.06.7601.17514   Final Retail                         59904  21.11.2010 6:25:10
    msvidctl.dll                              6.05.7601.17514   Final Retail                       2291712  21.11.2010 6:25:10
    msyuv.dll                                 6.01.7601.17514   Final Retail                      22528  21.11.2010 6:23:50
    pid.dll                                   6.01.7600.16385   Final Retail                      36352  14.07.2009 4:16:12
    psisdecd.dll                              6.06.7601.17669   Final Retail                        465408  06.05.2014 17:23:46
    psisrndr.ax                               6.06.7601.17669   Final Retail                         75776  06.05.2014 17:23:46
    qasf.dll                                  12.00.7601.17514  Final Retail                     206848  21.11.2010 6:24:01
    qcap.dll                                  6.06.7601.17514   Final Retail                        190976  21.11.2010 6:24:08
    qdv.dll                                   6.06.7601.17514   Final Retail                        283136  21.11.2010 6:24:09
    qdvd.dll                                  6.06.7601.18741   Final Retail                        519680  03.02.2015 6:12:29
    qedit.dll                                 6.06.7601.18501   Final Retail                        509440  06.06.2014 12:44:17
    qedwipes.dll                              6.06.7600.16385   Final Retail                     733184  14.07.2009 4:09:35
    quartz.dll                                6.06.7601.18741   Final Retail                       1329664  03.02.2015 6:12:29
    vbisurf.ax                                6.01.7601.17514   Final Retail                      33792  21.11.2010 6:25:10
    vfwwdm32.dll                              6.01.7601.17514   Final Retail                         56832  21.11.2010 6:24:09
    wsock32.dll                               6.01.7600.16385   Final Retail                         15360  14.07.2009 4:16:20


--------[  ]------------------------------------------------------------------------------------------------

    DrvUpdater                         Registry\User\Run        C:\Users\zaq\AppData\Roaming\DRPSu\DrvUpdater.exe /hide
    HDAudDeck                          Registry\Common\Run      C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
    iTunesHelper                       Registry\Common\Run      C:\Program Files\iTunes\iTunesHelper.exe 
    kype                               Registry\Common\Run      C:\Program Files (x86)\Skype\Phone\Skype.exe 
    NvBackend                          Registry\Common\Run      C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe 
    ShadowPlay                         Registry\Common\Run      C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
    Skype                              Registry\User\Run        C:\Program Files (x86)\Skype\Phone\Skype.exe /minimized /regrun
    Skype                              StartMenu\User           C:\Windows\Installer\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}\SkypeIcon.exe 
    V0330Mon.exe                       Registry\Common\Run      C:\Windows\V0330Mon.exe 


--------[  ]---------------------------------------------------------------------------------------------

  [ {4054F47F-4D79-4796-ACD4-EE21925E5886} ]

     :
                                               {4054F47F-4D79-4796-ACD4-EE21925E5886}
                                                  
                                           C:\Windows\system32\pcalua.exe
                                     -a "D:\SteamLibrary\steamapps\common\Left 4 Dead 2\bin\addoninstaller.exe" -d "D:\SteamLibrary\SteamApps\common\Left 4 Dead 2\left4dead2\addons" -c D:\SteamLibrary\SteamApps\common\Left 4 Dead 2\left4dead2\addons\silenthill.vpk
                                            
                                             
                                        zaq-\zaq
                                               
                                         24.08.2014 22:35:30
                                         

  [ {F3863290-6E26-4B8D-8E23-56C1061FD37D} ]

     :
                                               {F3863290-6E26-4B8D-8E23-56C1061FD37D}
                                                  
                                           C:\Windows\system32\pcalua.exe
                                     -a C:\Users\zaq\Desktop\winsdk_web.exe -d C:\Users\zaq\Desktop
                                            
                                             
                                        zaq-\zaq
                                               
                                         06.04.2015 20:07:28
                                         

  [ Adobe Acrobat Update Task ]

     :
                                               Adobe Acrobat Update Task
                                                  Queued
                                           C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
                                     
                                            
                                             This task keeps your Adobe Reader and Acrobat applications up to date with the latest enhancements and security fixes
                                        
                                               Adobe Systems Incorporated
                                         06.04.2015 21:11:04
                                         

     :
      At log on                                         At log on of any user - After triggered, repeat every 3 hours indefinitely

  [ Adobe Flash Player Updater ]

     :
                                               Adobe Flash Player Updater
                                                  
                                           C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
                                     
                                            
                                                  Adobe Flash Player        .      , Adobe Flash Player           .
                                        
                                               Adobe Systems Incorporated
                                         06.04.2015 20:32:00
                                         06.04.2015 21:32:00

     :
      Daily                                             At 3:32:00 every day - After triggered, repeat every 1 hour for a duration of 1 day

  [ GoogleUpdateTaskMachineCore ]

     :
                                               GoogleUpdateTaskMachineCore
                                                  
                                           C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
                                     /c
                                            
                                               ,    Google  .      ,   Google   .      ,     ,     .    ,    Google,   .
                                        
                                               
                                         06.04.2015 20:59:04
                                         07.04.2015 20:09:00

     :
      At log on                                         At log on of any user
      Daily                                             At 20:09:00 every day

  [ GoogleUpdateTaskMachineUA ]

     :
                                               GoogleUpdateTaskMachineUA
                                                  
                                           C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
                                     /ua /installsource scheduler
                                            
                                               ,    Google  .      ,   Google   .      ,     ,     .    ,    Google,   .
                                        
                                               
                                         06.04.2015 21:09:00
                                         06.04.2015 22:09:00

     :
      Daily                                             At 20:09:00 every day - After triggered, repeat every 1 hour for a duration of 1 day

  [ RunAsStdUser_GameCenterMailRu ]

     :
                                               RunAsStdUser_GameCenterMailRu
                                                  
                                           C:\Users\zaq\AppData\Local\Mail.Ru\GameCenter\GameCenter@Mail.Ru.exe
                                     -lowermode -clearcache /unique=5682976
                                            
                                             
                                        zaq-\zaq
                                               RunAsStdUser
                                         26.09.2014 21:53:38
                                         


--------[   ]-------------------------------------------------------------------------------------

    Torrent                                                                               3.4.2.35702    uTorrent                                      BitTorrent Inc.                           
    Torrent                                                                               3.4.2.35702    uTorrent                                      BitTorrent Inc.                           
    ABBYY FineReader 12 Professional                                                          12.1.426    {F12000FE-0001-0000-0000-074957833700}        ABBYY Production LLC            2015-02-26
    Adobe Flash Player 16 ActiveX                                                           16.0.0.305    Adobe Flash Player ActiveX                    Adobe Systems Incorporated                
    Adobe Flash Player 16 NPAPI                                                             16.0.0.305    Adobe Flash Player NPAPI                      Adobe Systems Incorporated                
    Adobe Reader XI (11.0.10) - Russian [ ()]                                     11.0.10    {AC76BA86-7AD7-1049-7B44-AB0000000001}        Adobe Systems Incorporated      2014-12-11
    Adobe Refresh Manager                                                                        1.8.0    {AC76BA86-0804-1033-1959-001802114130}        Adobe Systems Incorporated      2014-12-24
    AIDA64 Extreme v4.30                                                                          4.30    AIDA64 Extreme_is1                            FinalWire Ltd.                  2014-05-25
    AOMEI Backupper                                                                                       {A83692F5-3E9B-4E95-9E7E-B5DF5536C09D}_is1    AOMEI Technology Co., Ltd.      2014-08-11
    Apple Mobile Device Support                                                                8.1.1.3    {C4123106-B685-48E6-B9BD-E4F911841EB4}        Apple Inc.                      2015-04-04
    Apple Software Update [ ()]                                                 2.1.3.127    {789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}        Apple Inc.                      2014-06-03
    Asmedia ASM104x USB 3.0 Host Controller Driver                                            1.16.2.0    {E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}        Asmedia Technology              2014-08-10
    ATI Catalyst Install Manager                                                             3.0.765.0    {2A13EF26-4D68-B2D7-A486-DBBD2FDE366B}        ATI Technologies, Inc.          2014-08-10
    Bandicam                                                                                              Bandicam                                      Bandisoft                                 
    Bonjour [ ()]                                                                3.0.0.10    {6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}        Apple Inc.                      2014-06-03
    Counter-Strike: Global Offensive - SDK                                                                Steam App 745                                                                           
    Counter-Strike: Global Offensive                                                                      Steam App 730                                 Valve                                     
    Counter-Strike: Source                                                                                Steam App 240                                 Valve                                     
    Creative WebCam Vista/Live! Cam Chat (VF0330) Driver (1.12.01.00)                                     Creative VF0330                                                                         
    DayZ                                                                                                  Steam App 221100                              Bohemia Interactive                       
    Definition Update for Microsoft Office 2013 (KB2956172) 32-Bit Edition                                {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{1E980009-7F8F-426E-B716-1CE47405CA0C}  Microsoft                                 
    Definition Update for Microsoft Office 2013 (KB2956172) 32-Bit Edition                                {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{1E980009-7F8F-426E-B716-1CE47405CA0C}  Microsoft                                 
    Dota 2                                                                                                Steam App 570                                 Valve                                     
    DriverPack Solution Updater                                                                 0.0.25    DRPSu Updater                                 DriverPack Solution             2015-04-06
    DriverPack Solution Updater                                                                 0.0.25    DRPSu Updater                                 DriverPack Solution             2015-04-06
    Google Chrome                                                                        41.0.2272.118    Google Chrome                                 Google Inc.                     2014-05-19
    Google Update Helper                                                                     1.3.25.11    {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}        Google Inc.                     2014-11-14
    Google Update Helper                                                                      1.3.26.9    {60EC980A-BDA2-4CB6-A427-B07A5498B4CA}        Google Inc.                     2015-02-05
    How to Survive                                                                                        Steam App 250400                                                                        
    iTunes [ ()]                                                                 12.1.1.4    {D227565A-0033-40AD-89BA-653A205CDC11}        Apple Inc.                      2015-04-04
    Java 7 Update 65                                                                           7.0.650    {26A24AE4-039D-4CA4-87B4-2F83217055FF}        Oracle                          2014-05-26
    Java Auto Updater                                                                        2.1.65.20    {4A03706F-666A-4037-7777-5F2748764D10}        Oracle, Inc.                    2014-07-20
    Java SE Development Kit 7 Update 40 (64-bit)                                             1.7.0.400    {64A3A4F4-B792-11D6-A78A-00B0D0170400}        Oracle                          2014-06-18
    Java SE Development Kit 7 Update 40                                                      1.7.0.400    {32A3A4F4-B792-11D6-A78A-00B0D0170400}        Oracle                          2014-06-18
    Java(TM) 6 Update 45 (64-bit)                                                              6.0.450    {26A24AE4-039D-4CA4-87B4-2F86416045FF}        Oracle                          2014-06-18
    Java(TM) 6 Update 45                                                                       6.0.450    {26A24AE4-039D-4CA4-87B4-2F83216045FF}        Oracle                          2014-06-18
    Java(TM) SE Development Kit 6 Update 45 (64-bit)                                         1.6.0.450    {64A3A4F4-B792-11D6-A78A-00B0D0160450}        Oracle                          2014-06-18
    Java(TM) SE Development Kit 6 Update 45                                                  1.6.0.450    {32A3A4F4-B792-11D6-A78A-00B0D0160450}        Oracle                          2014-06-18
    Kaspersky Anti-Virus [ ()]                                                14.0.0.4651    {6F6873E3-5C92-4049-B511-231A138DD090}                  2014-05-26
    Kaspersky Anti-Virus                                                                   14.0.0.4651    InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}                      
    K-Lite Codec Pack 10.4.0 Full                                                               10.4.0    KLiteCodecPack_is1                                                            2014-05-19
    Lagarith Lossless Codec (1.3.27)                                                                      {F59AC46C-10C3-4023-882C-4212A92283B3}_is1                                    2014-08-11
    Left 4 Dead 2                                                                                         Steam App 550                                 Valve                                     
    Microsoft .NET Framework 4.5.2                                                           4.5.51209    {92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033  Microsoft Corporation                     
    Microsoft .NET Framework 4.5.2                                                           4.5.51209    {26784146-6E05-3FF9-9335-786C7C0FB5BE}        Microsoft Corporation           2015-03-06
    Microsoft ASP.NET MVC 4 Runtime                                                        4.0.40804.0    {3FE312D5-B862-40CE-8E4E-A6D8ABF62736}        Microsoft Corporation           2015-02-27
    Microsoft Excel 2013                                                                15.0.4569.1506    Office15.EXCEL                                Microsoft Corporation                     
    Microsoft Excel 2013                                                                15.0.4569.1506    {90150000-0016-0000-0000-0000000FF1CE}        Microsoft Corporation           2015-03-12
    Microsoft Excel MUI (Russian) 2013 [ ()]                               15.0.4569.1506    {90150000-0016-0419-0000-0000000FF1CE}        Microsoft Corporation           2015-03-12
    Microsoft Office 64-bit Components 2013                                             15.0.4569.1506    {90150000-002A-0000-1000-0000000FF1CE}        Microsoft Corporation           2015-03-12
    Microsoft Office Korrekturhilfen 2013 - Deutsch [ ()]               15.0.4569.1506    {90150000-001F-0407-0000-0000000FF1CE}        Microsoft Corporation           2015-03-12
    Microsoft Office OSM MUI (Russian) 2013 [ ()]                          15.0.4569.1506    {90150000-00E1-0419-0000-0000000FF1CE}        Microsoft Corporation           2014-12-22
    Microsoft Office OSM UX MUI (Russian) 2013 [ ()]                       15.0.4569.1506    {90150000-00E2-0419-0000-0000000FF1CE}        Microsoft Corporation           2014-12-22
    Microsoft Office Proofing (Russian) 2013 [ ()]                         15.0.4569.1506    {90150000-002C-0419-0000-0000000FF1CE}        Microsoft Corporation           2014-12-22
    Microsoft Office Proofing Tools 2013 - English                                      15.0.4569.1506    {90150000-001F-0409-0000-0000000FF1CE}        Microsoft Corporation           2015-03-12
    Microsoft Office Shared 64-bit MUI (Russian) 2013 [ ()]                15.0.4569.1506    {90150000-002A-0419-1000-0000000FF1CE}        Microsoft Corporation           2015-02-11
    Microsoft Office Shared MUI (Russian) 2013 [ ()]                       15.0.4569.1506    {90150000-006E-0419-0000-0000000FF1CE}        Microsoft Corporation           2015-03-12
    Microsoft Silverlight                                                                  5.1.30514.0    {89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}        Microsoft Corporation           2014-08-12
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148                      9.0.30729.4148    {4B6C7001-C7D6-3710-913E-5BC23FCE91E6}        Microsoft Corporation           2014-08-10
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161                      9.0.30729.6161    {5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}        Microsoft Corporation           2014-05-25
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17                             9.0.30729    {9A25302D-30C0-39D9-BD6F-21E6EC160475}        Microsoft Corporation           2015-01-05
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161                      9.0.30729.6161    {9BE518E6-ECC6-35A9-88E4-87755C07200F}        Microsoft Corporation           2014-05-25
    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219                             10.0.40219    {1D8E6291-B0D5-35EC-8441-6616F567A0F7}        Microsoft Corporation           2015-02-13
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219                             10.0.40219    {F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}        Microsoft Corporation           2015-02-13
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030                          11.0.61030.0    {ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}        Microsoft Corporation                     
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030                          11.0.61030.0    {33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}        Microsoft Corporation                     
    Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030                           11.0.61030    {37B8F9C7-03FB-3253-8781-2517C99D7C00}        Microsoft Corporation           2015-02-11
    Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030                              11.0.61030    {CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}        Microsoft Corporation           2015-02-11
    Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030                           11.0.61030    {B175520C-86A2-35A7-8619-86DC379688B9}        Microsoft Corporation           2015-02-11
    Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030                              11.0.61030    {BD95A8CD-1D9F-35AD-981A-3E7925026EBB}        Microsoft Corporation           2015-02-11
    Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - RUS [ ()]        10.0.50903    {9688CEFA-F3F5-35E6-B7F6-B1748178B09E}        Microsoft Corporation           2015-02-13
    Microsoft Visual Studio 2010 Tools for Office Runtime (x64)                             10.0.50903    Microsoft Visual Studio 2010 Tools for Office Runtime (x64)  Microsoft Corporation                     
    Microsoft Visual Studio 2010 Tools for Office Runtime (x64)                             10.0.50908    {9495AEB4-AB97-39DE-8C42-806EEF75ECA7}        Microsoft Corporation           2015-02-13
    Microsoft Word 2013                                                                 15.0.4569.1506    Office15.WORD                                 Microsoft Corporation                     
    Microsoft Word 2013                                                                 15.0.4569.1506    {90150000-001B-0000-0000-0000000FF1CE}        Microsoft Corporation           2015-03-12
    Microsoft Word MUI (Russian) 2013 [ ()]                                15.0.4569.1506    {90150000-001B-0419-0000-0000000FF1CE}        Microsoft Corporation           2015-03-12
    NVIDIA GeForce Experience 2.1.1 [ ()]                                           2.1.1    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience  NVIDIA Corporation              2014-08-11
    NVIDIA Install Application [ ()]                                      2.1002.157.1165    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer  NVIDIA Corporation              2014-08-11
    NVIDIA LED Visualizer 1.0 [ ()]                                                   1.0    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer  NVIDIA Corporation              2014-08-11
    NVIDIA Network Service [ ()]                                                      1.0    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service  NVIDIA Corporation              2014-08-11
    NVIDIA PhysX                                                                             9.13.1220    {80407BA7-7763-4395-AB98-5233F1B34E65}        NVIDIA Corporation              2014-08-11
    NVIDIA ShadowPlay 15.3.33 [ ()]                                               15.3.33    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay  NVIDIA Corporation              2014-08-11
    NVIDIA Stereoscopic 3D Driver                                                         7.17.12.6514    NVIDIAStereo                                  NVIDIA Corporation                        
    NVIDIA Update Core [ ()]                                                      15.3.33    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core  NVIDIA Corporation              2014-08-11
    NVIDIA Virtual Audio 1.2.23 [ ()]                                              1.2.23    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver  NVIDIA Corporation              2014-08-11
    NVIDIA   340.52 [ ()]                                        340.52    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver  NVIDIA Corporation              2014-08-11
    NVIDIA  3D Vision 340.52 [ ()]                                          340.52    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision  NVIDIA Corporation              2014-08-11
    NVIDIA   3D Vision 340.50 [ ()]                              340.50    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB  NVIDIA Corporation              2014-08-11
    NVIDIA    PhysX 9.13.1220 [ ()]              9.13.1220    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX  NVIDIA Corporation              2014-08-11
    Open Broadcaster Software                                                                             Open Broadcaster Software                                                               
    OpenOffice 4.1.0 [ ()]                                                      4.10.9764    {79AFBDB8-E9FF-4EF7-B683-7F0502A9A00C}        Apache Software Foundation      2014-05-25
    RaidCall                                                                          7.3.6-1.2.12952.156    RaidCall                                      raidcall.com.ru                           
    Realtek Ethernet Controller Driver []                                         7.52.203.2012    {8833FFB6-5B0C-4764-81AA-06DFEED9A476}        Realtek                         2014-08-10
    Renesas Electronics USB 3.0 Host Controller Driver                                        2.0.32.0    InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}  Renesas Electronics Corporation  2014-05-19
    SAM CoDeC Pack                                                                                5.50    SAM CoDeC Pack                                www.SamLab.ws                             
    Security Update for Microsoft Office 2013 (KB2880502) 32-Bit Edition                                  {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{90E7A66B-723D-4790-824A-6E4EEC0C2CBA}  Microsoft                                 
    Security Update for Microsoft Office 2013 (KB2880502) 32-Bit Edition                                  {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{90E7A66B-723D-4790-824A-6E4EEC0C2CBA}  Microsoft                                 
    Security Update for Microsoft Office 2013 (KB2910941) 32-Bit Edition                                  {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{E0434175-7133-45D2-B53A-78700C2F8BC4}  Microsoft                                 
    Security Update for Microsoft Office 2013 (KB2910941) 32-Bit Edition                                  {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{E0434175-7133-45D2-B53A-78700C2F8BC4}  Microsoft                                 
    Security Update for Microsoft Office 2013 (KB2956151) 32-Bit Edition                                  {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{989850CA-F2D5-4034-B7B6-B9AE3A9868B0}  Microsoft                                 
    Security Update for Microsoft Office 2013 (KB2956151) 32-Bit Edition                                  {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{989850CA-F2D5-4034-B7B6-B9AE3A9868B0}  Microsoft                                 
    Security Update for Microsoft Office 2013 (KB2956151) 32-Bit Edition                                  {90150000-006E-0419-0000-0000000FF1CE}_Office15.EXCEL_{989850CA-F2D5-4034-B7B6-B9AE3A9868B0}  Microsoft                                 
    Security Update for Microsoft Office 2013 (KB2956151) 32-Bit Edition                                  {90150000-006E-0419-0000-0000000FF1CE}_Office15.WORD_{989850CA-F2D5-4034-B7B6-B9AE3A9868B0}  Microsoft                                 
    Security Update for Microsoft Word 2013 (KB2956163) 32-Bit Edition                                    {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{EE0F3C75-36D9-4285-B04F-22F033550FD4}  Microsoft                                 
    Security Update for Microsoft Word 2013 (KB2956163) 32-Bit Edition                                    {90150000-001B-0419-0000-0000000FF1CE}_Office15.WORD_{EE0F3C75-36D9-4285-B04F-22F033550FD4}  Microsoft                                 
    SHIELD Streaming [ ()]                                                        3.1.100    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv  NVIDIA Corporation              2014-08-11
    Sid Meier's Civilization V                                                                            Steam App 8930                                2K Games, Inc.                            
    Skype 7.2                                                                                 7.2.103    {24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}        Skype Technologies S.A.         2015-03-12
    Steam                                                                                                 Steam                                         Valve Corporation                         
    SteelSeries Engine                                                                   2.8.171.34768    SteelSeries Engine                            SteelSeries                               
    Update for Microsoft Excel 2013 (KB2956145) 32-Bit Edition                                            {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{4DD8EF4D-12C6-45AB-AB63-34A044F9AE5A}  Microsoft                                 
    Update for Microsoft Excel 2013 (KB2956145) 32-Bit Edition                                            {90150000-0016-0419-0000-0000000FF1CE}_Office15.EXCEL_{4DD8EF4D-12C6-45AB-AB63-34A044F9AE5A}  Microsoft                                 
    Update for Microsoft Excel 2013 (KB2956145) 32-Bit Edition                                            {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{4DD8EF4D-12C6-45AB-AB63-34A044F9AE5A}  Microsoft                                 
    Update for Microsoft Excel 2013 (KB2956145) 32-Bit Edition                                            {90150000-001B-0419-0000-0000000FF1CE}_Office15.WORD_{4DD8EF4D-12C6-45AB-AB63-34A044F9AE5A}  Microsoft                                 
    Update for Microsoft Excel 2013 (KB2956145) 32-Bit Edition                                            {90150000-006E-0419-0000-0000000FF1CE}_Office15.EXCEL_{4DD8EF4D-12C6-45AB-AB63-34A044F9AE5A}  Microsoft                                 
    Update for Microsoft Excel 2013 (KB2956145) 32-Bit Edition                                            {90150000-006E-0419-0000-0000000FF1CE}_Office15.WORD_{4DD8EF4D-12C6-45AB-AB63-34A044F9AE5A}  Microsoft                                 
    Update for Microsoft Lync 2013 (KB2956174) 32-Bit Edition                                             {90150000-002A-0000-1000-0000000FF1CE}_Office15.EXCEL_{E519165B-2C62-4A31-953B-AE33D9AD7A41}  Microsoft                                 
    Update for Microsoft Lync 2013 (KB2956174) 32-Bit Edition                                             {90150000-002A-0000-1000-0000000FF1CE}_Office15.WORD_{E519165B-2C62-4A31-953B-AE33D9AD7A41}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2760249) 32-Bit Edition                                           {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{8C07AD38-38EB-4332-BCB3-F55A77C927DF}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2760249) 32-Bit Edition                                           {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{8C07AD38-38EB-4332-BCB3-F55A77C927DF}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2760344) 32-Bit Edition                                           {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{A7610F07-E844-4444-8E1D-D5BC8AD0B4C5}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2760344) 32-Bit Edition                                           {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{A7610F07-E844-4444-8E1D-D5BC8AD0B4C5}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2760371) 32-Bit Edition                                           {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{FFF87DE6-6602-4F65-BD75-D481E0539DCD}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2760544) 32-Bit Edition                                           {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{45B7D395-EB9B-414F-9E46-5849B42326E2}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2760544) 32-Bit Edition                                           {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{45B7D395-EB9B-414F-9E46-5849B42326E2}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2768012) 32-Bit Edition                                           {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{66421820-D3CA-450A-898C-78D7E40108E6}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2768012) 32-Bit Edition                                           {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{66421820-D3CA-450A-898C-78D7E40108E6}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2837654) 32-Bit Edition                                           {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{6D771289-E5A7-442F-82B5-5EC4217AEF03}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2837654) 32-Bit Edition                                           {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{6D771289-E5A7-442F-82B5-5EC4217AEF03}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2863843) 32-Bit Edition                                           {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{AD7045B8-1D75-4B4C-8120-12F045D206C7}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2863843) 32-Bit Edition                                           {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{AD7045B8-1D75-4B4C-8120-12F045D206C7}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2863843) 32-Bit Edition                                           {90150000-002A-0000-1000-0000000FF1CE}_Office15.EXCEL_{AD7045B8-1D75-4B4C-8120-12F045D206C7}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2863843) 32-Bit Edition                                           {90150000-002A-0000-1000-0000000FF1CE}_Office15.WORD_{AD7045B8-1D75-4B4C-8120-12F045D206C7}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2880478) 32-Bit Edition                                           {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{7C5CEE0F-6823-4BB7-A28F-76FEC14EB6AC}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2880478) 32-Bit Edition                                           {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{7C5CEE0F-6823-4BB7-A28F-76FEC14EB6AC}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2880977) 32-Bit Edition                                           {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{0F78855B-2181-4FCE-82DD-ED649E985409}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2880977) 32-Bit Edition                                           {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{0F78855B-2181-4FCE-82DD-ED649E985409}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2881001) 32-Bit Edition                                           {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{31849233-AD8B-42D7-9AE1-74C79C8E8C03}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2881001) 32-Bit Edition                                           {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{31849233-AD8B-42D7-9AE1-74C79C8E8C03}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2881035) 32-Bit Edition                                           {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{01B80B63-C638-4004-9148-75B8C8518B1E}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2881035) 32-Bit Edition                                           {90150000-0016-0419-0000-0000000FF1CE}_Office15.EXCEL_{01B80B63-C638-4004-9148-75B8C8518B1E}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2883036) 32-Bit Edition                                           {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{B8E73381-09B1-4895-ACD0-34385B0F526D}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2883036) 32-Bit Edition                                           {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{B8E73381-09B1-4895-ACD0-34385B0F526D}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2899498) 32-Bit Edition                                           {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{E4046E6A-999E-45AE-8348-C76677AD0016}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2899498) 32-Bit Edition                                           {90150000-0016-0419-0000-0000000FF1CE}_Office15.EXCEL_{E4046E6A-999E-45AE-8348-C76677AD0016}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2899522) 32-Bit Edition                                           {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{87F6726E-6F99-42F0-8E11-55D798E57DD5}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2899522) 32-Bit Edition                                           {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{87F6726E-6F99-42F0-8E11-55D798E57DD5}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2920754) 32-Bit Edition                                           {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{6EEF6E8E-9854-4DCD-862F-422DF2F984F7}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2920754) 32-Bit Edition                                           {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{6EEF6E8E-9854-4DCD-862F-422DF2F984F7}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2920769) 32-Bit Edition                                           {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{D2A7B64F-1BE1-4381-A555-FE49708BF92F}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2920769) 32-Bit Edition                                           {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{D2A7B64F-1BE1-4381-A555-FE49708BF92F}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956148) 32-Bit Edition                                           {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{0E4A489C-EA47-4488-BA4C-97FD3935E67E}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956148) 32-Bit Edition                                           {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{0E4A489C-EA47-4488-BA4C-97FD3935E67E}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956154) 32-Bit Edition                                           {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{197DFD5A-3C03-4F97-B8DB-0105BAE87FCD}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956154) 32-Bit Edition                                           {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{197DFD5A-3C03-4F97-B8DB-0105BAE87FCD}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956160) 32-Bit Edition                                           {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{7C8F81FA-2938-4909-A4B1-A702200FC779}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956160) 32-Bit Edition                                           {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{7C8F81FA-2938-4909-A4B1-A702200FC779}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956160) 32-Bit Edition                                           {90150000-006E-0419-0000-0000000FF1CE}_Office15.EXCEL_{7C8F81FA-2938-4909-A4B1-A702200FC779}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956160) 32-Bit Edition                                           {90150000-006E-0419-0000-0000000FF1CE}_Office15.WORD_{7C8F81FA-2938-4909-A4B1-A702200FC779}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956167) 32-Bit Edition                                           {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{6AC44D64-BAB9-4FD2-9315-98D376BB9C50}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956167) 32-Bit Edition                                           {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{6AC44D64-BAB9-4FD2-9315-98D376BB9C50}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956167) 32-Bit Edition                                           {90150000-006E-0419-0000-0000000FF1CE}_Office15.EXCEL_{6AC44D64-BAB9-4FD2-9315-98D376BB9C50}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956167) 32-Bit Edition                                           {90150000-006E-0419-0000-0000000FF1CE}_Office15.WORD_{6AC44D64-BAB9-4FD2-9315-98D376BB9C50}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956168) 32-Bit Edition                                           {90150000-001F-0407-0000-0000000FF1CE}_Office15.EXCEL_{EF221E03-F572-4C02-8DB9-157670CD9C05}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956168) 32-Bit Edition                                           {90150000-001F-0407-0000-0000000FF1CE}_Office15.WORD_{EF221E03-F572-4C02-8DB9-157670CD9C05}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956168) 32-Bit Edition                                           {90150000-001F-0409-0000-0000000FF1CE}_Office15.EXCEL_{1469ECD9-2952-4987-AC28-4B05FB37EFF5}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956168) 32-Bit Edition                                           {90150000-001F-0409-0000-0000000FF1CE}_Office15.WORD_{1469ECD9-2952-4987-AC28-4B05FB37EFF5}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956168) 32-Bit Edition                                           {90150000-001F-0419-0000-0000000FF1CE}_Office15.EXCEL_{E374137E-DA3D-4F99-832C-815F0429E0BE}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956168) 32-Bit Edition                                           {90150000-001F-0419-0000-0000000FF1CE}_Office15.WORD_{E374137E-DA3D-4F99-832C-815F0429E0BE}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956168) 32-Bit Edition                                           {90150000-001F-0422-0000-0000000FF1CE}_Office15.EXCEL_{005DC056-3809-4068-9697-CD252D410A8F}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956168) 32-Bit Edition                                           {90150000-001F-0422-0000-0000000FF1CE}_Office15.WORD_{005DC056-3809-4068-9697-CD252D410A8F}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956169) 32-Bit Edition                                           {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{D8F0FA15-9658-4B00-A176-FB441EF3A6FA}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956169) 32-Bit Edition                                           {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{D8F0FA15-9658-4B00-A176-FB441EF3A6FA}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956171) 32-Bit Edition                                           {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{92802C1D-B9BB-4927-9CD8-8ED2407C3D25}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956177) 32-Bit Edition                                           {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{AB41EDC8-9CA9-4D1B-8E96-C53D2A2BFF8E}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956177) 32-Bit Edition                                           {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{AB41EDC8-9CA9-4D1B-8E96-C53D2A2BFF8E}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956177) 32-Bit Edition                                           {90150000-002A-0000-1000-0000000FF1CE}_Office15.EXCEL_{AB41EDC8-9CA9-4D1B-8E96-C53D2A2BFF8E}  Microsoft                                 
    Update for Microsoft Office 2013 (KB2956177) 32-Bit Edition                                           {90150000-002A-0000-1000-0000000FF1CE}_Office15.WORD_{AB41EDC8-9CA9-4D1B-8E96-C53D2A2BFF8E}  Microsoft                                 
    Update for Microsoft OneDrive for Business (KB2920746) 32-Bit Edition                                 {90150000-002A-0000-1000-0000000FF1CE}_Office15.EXCEL_{0B0B3A2B-0A31-4324-9E65-AD30B6CD3CE9}  Microsoft                                 
    Update for Microsoft OneDrive for Business (KB2920746) 32-Bit Edition                                 {90150000-002A-0000-1000-0000000FF1CE}_Office15.WORD_{0B0B3A2B-0A31-4324-9E65-AD30B6CD3CE9}  Microsoft                                 
    Update for Microsoft OneDrive for Business (KB2920746) 32-Bit Edition                                 {90150000-002A-0419-1000-0000000FF1CE}_Office15.EXCEL_{0B0B3A2B-0A31-4324-9E65-AD30B6CD3CE9}  Microsoft                                 
    Update for Microsoft OneDrive for Business (KB2920746) 32-Bit Edition                                 {90150000-002A-0419-1000-0000000FF1CE}_Office15.WORD_{0B0B3A2B-0A31-4324-9E65-AD30B6CD3CE9}  Microsoft                                 
    Update for Microsoft OneNote 2013 (KB2956165) 32-Bit Edition                                          {90150000-002A-0000-1000-0000000FF1CE}_Office15.EXCEL_{B0672B3E-5774-4B5D-B1FD-6FFC062B5BC1}  Microsoft                                 
    Update for Microsoft OneNote 2013 (KB2956165) 32-Bit Edition                                          {90150000-002A-0000-1000-0000000FF1CE}_Office15.WORD_{B0672B3E-5774-4B5D-B1FD-6FFC062B5BC1}  Microsoft                                 
    Update for Microsoft Outlook 2013 (KB2956170) 32-Bit Edition                                          {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{BAE53937-6E59-4062-BD07-822FB9A52A57}  Microsoft                                 
    Update for Microsoft Outlook 2013 (KB2956170) 32-Bit Edition                                          {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{BAE53937-6E59-4062-BD07-822FB9A52A57}  Microsoft                                 
    Update for Microsoft Project 2013 (KB2956187) 32-Bit Edition                                          {90150000-002A-0000-1000-0000000FF1CE}_Office15.EXCEL_{0A9544E9-EA2A-4D39-8504-A79EA6FC4AA4}  Microsoft                                 
    Update for Microsoft Project 2013 (KB2956187) 32-Bit Edition                                          {90150000-002A-0000-1000-0000000FF1CE}_Office15.WORD_{0A9544E9-EA2A-4D39-8504-A79EA6FC4AA4}  Microsoft                                 
    Update for Microsoft Visio Viewer 2013 (KB2817301) 32-Bit Edition                                     {90150000-0016-0000-0000-0000000FF1CE}_Office15.EXCEL_{25C61889-2E44-4BE1-9E96-9364BFDCF501}  Microsoft                                 
    Update for Microsoft Visio Viewer 2013 (KB2817301) 32-Bit Edition                                     {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{25C61889-2E44-4BE1-9E96-9364BFDCF501}  Microsoft                                 
    Update for Microsoft Visio Viewer 2013 (KB2817301) 32-Bit Edition                                     {90150000-006E-0419-0000-0000000FF1CE}_Office15.EXCEL_{25C61889-2E44-4BE1-9E96-9364BFDCF501}  Microsoft                                 
    Update for Microsoft Visio Viewer 2013 (KB2817301) 32-Bit Edition                                     {90150000-006E-0419-0000-0000000FF1CE}_Office15.WORD_{25C61889-2E44-4BE1-9E96-9364BFDCF501}  Microsoft                                 
    Update for Microsoft Word 2013 (KB2878319) 32-Bit Edition                                             {90150000-001B-0000-0000-0000000FF1CE}_Office15.WORD_{A7CD05CC-CA85-428C-91FD-74A908D126E1}  Microsoft                                 
    Ut Video Codec Suite                                                                        13.3.1    utvideo_is1                                   UMEZAWA Takeshi                 2014-08-11
    Ventrilo Client for Windows x64                                                            3.0.8.0    {EEB3F6BB-318D-4CE5-989F-8191FCBFB578}        Flagship Industries, Inc.       2014-11-19
    VIA                                                                1.39    InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}  VIA Technologies, Inc.          2014-08-10
    VKMusic 4                                                                                     4.62    VKMusic 4_is1                                                                 2015-02-06
    WinRAR 5.01 (64-)                                                                  5.01.0    WinRAR archiver                               win.rar GmbH                              
    WinUtilities Free Edition 11.16                                                              11.16    {FC274982-5AAD-4C20-848D-4424A5043010}_is1    YL Computing, Inc               2014-09-09
    WinUtilities Professional Edition 11.35                                                      11.35    {FC274982-5AAD-4C20-848D-4424A5043009}_is1    YL Computing, Inc               2015-03-21
    x264vfw - H.264/MPEG-4 AVC codec (remove only)                                                        x264vfw                                                                                 
    x264vfw - H.264/MPEG-4 AVC codec for x64 (remove only)                                                x264vfw64                                                                               
    Xvid MPEG-4 Video Codec                                                                               Xvid_is1                                                                      2014-08-11
    Xvid MPEG-4 Video Codec                                                                               Xvid_is1                                                                      2014-08-11
       Microsoft Office 2013    [ ()]    15.0.4569.1506    {90150000-001F-0422-0000-0000000FF1CE}        Microsoft Corporation           2015-03-12
     NVIDIA 15.3.33 [ ()]                                               15.3.33    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update  NVIDIA Corporation              2014-08-11
      NVIDIA 340.52 [ ()]                                          340.52    {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel  NVIDIA Corporation              2014-08-11
      Apple (32-) [ ()]                                         3.1.2    {447CDCE5-F555-429B-BFA6-642C3C6D684F}        Apple Inc.                      2015-04-04
      Apple (64-) [ ()]                                         3.1.2    {0DF7096B-715A-4233-8633-C7A16ED6D616}        Apple Inc.                      2015-04-04
       Microsoft Office 2013   [ ()]    15.0.4569.1506    {90150000-001F-0419-0000-0000000FF1CE}        Microsoft Corporation           2015-03-12
      Microsoft Visual Studio 2010 Tools    Office (x64) - RUS        10.0.50903    Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - RUS  Microsoft Corporation                     


--------[  ]----------------------------------------------------------------------------------------------------

    Microsoft Excel 2013                                                    VGPNG-Y7HQW-9RHP7-TKPV3-BG7GB
    Microsoft Internet Explorer 9.11.9600.17691                             FJGCP-4DFJD-GJY49-VJBQ7-HYRR2
    Microsoft Windows 7 Ultimate                                            FJGCP-4DFJD-GJY49-VJBQ7-HYRR2
    Microsoft Word 2013                                                     6Q7VD-NX8JD-WJ2VH-88V73-4GBJ7


--------[   ]-------------------------------------------------------------------------------------------------

    386               Virtual Device Driver                                            
    3G2               3G2 File                                                         video/3gpp2
    3GP               3GP File                                                         video/3gpp
    3GP2              3GP2 File                                                        video/3gpp2
    3GPP              3GPP File                                                        video/3gpp
    7Z                 WinRAR                                                     
    AAC               AAC Audio File                                                   audio/vnd.dlna.adts
    AC3               AC3 Audio File                                                   
    ACE                WinRAR                                                     
    ACL               AutoCorrect List File                                            
    ACROBATSECURITYSETTINGS  Adobe Acrobat Security Settings Document                         application/vnd.adobe.acrobat-security-settings
    ADI               AOMEI Backupper Backup File                                      
    ADT               ADTS Audio                                                       audio/vnd.dlna.adts
    ADTS              ADTS Audio                                                       audio/vnd.dlna.adts
    AIF               AIFF Audio File                                                  audio/aiff
    AIFC              AIFF Audio File                                                  audio/aiff
    AIFF              AIFF Audio File                                                  audio/aiff
    ALAC              ALAC Audio File                                                  
    AMR               AMR Audio File                                                   
    AMV               AMV Video File                                                   
    ANI               Animated Cursor                                                  
    AOB               AOB Audio File                                                   
    APE               Monkey's Audio File                                              
    API               API File                                                         
    APPLICATION       Application Manifest                                             application/x-ms-application
    APPREF-MS         Application Reference                                            
    ARJ                WinRAR                                                     
    ASA               ASA File                                                         
    ASF               ASF File                                                         video/x-ms-asf
    ASP               ASP File                                                         
    ASX               ASX Playlist File                                                video/x-ms-asf
    AU                AU Format Sound                                                  audio/basic
    AVI               AVI Video File                                                   video/avi
    AW                Answer Wizard File                                               
    BAT               Windows Batch File                                               
    BAU                 OpenOffice.org 1.1                                 
    BDMV              Blu-ray File                                                     
    BLG               Performance Monitor File                                         
    BMP               Bitmap Image                                                     image/bmp
    BZ                 WinRAR                                                     
    BZ2                WinRAR                                                     
    C2R               C2R File                                                         
    CAB                WinRAR                                                     
    CAF               CAF Audio File                                                   
    CAMP              WCS Viewing Condition Profile                                    
    CAT               Security Catalog                                                 application/vnd.ms-pki.seccat
    CDA               CD Audio File                                                    
    CDMP              WCS Device Profile                                               
    CDX               CDX File                                                         
    CER               Security Certificate                                             application/x-x509-ca-cert
    CHESSTITANSSAVE-MS  .ChessTitansSave-ms                                              
    CHK               Recovered File Fragments                                         
    CHM               Compiled HTML Help file                                          
    CMD               Windows Command Script                                           
    COM               MS-DOS Application                                               
    COMFYCAKESSAVE-MS  .ComfyCakesSave-ms                                               
    COMPOSITEFONT     Composite Font File                                              
    CONTACT           Contact File                                                     text/x-ms-contact
    CPL               Control Panel Item                                               
    CRD               Information Card                                                 
    CRDS              Information Card Store                                           
    CRL               Certificate Revocation List                                      application/pkix-crl
    CRT               Security Certificate                                             application/x-x509-ca-cert
    CRTX               Microsoft Office Chart                                    
    CSS               Cascading Style Sheet Document                                   text/css
    CSV                Microsoft Excel                                               
    CUR               Cursor                                                           
    DB                Data Base File                                                   
    DER               Security Certificate                                             application/x-x509-ca-cert
    DESKLINK          Desktop Shortcut                                                 
    DIAGCAB           Diagnostic Cabinet                                               
    DIAGCFG           Diagnostic Configuration                                         
    DIAGPKG           Diagnostic Document                                              
    DIB               Bitmap Image                                                     image/bmp
    DIC               Text Document                                                    
    DIVX              DIVX Video File                                                  
    DLL               Application Extension                                            application/x-msdownload
    DOC                Microsoft Word 972003                                  application/msword
    DOCHTML            Microsoft Word   HTML                           
    DOCM               Microsoft Word                       application/vnd.ms-word.document.macroEnabled.12
    DOCMHTML          DOCMHTML File                                                    
    DOCX               Microsoft Word                                          application/vnd.openxmlformats-officedocument.wordprocessingml.document
    DOCXML             Microsoft Word   XML                            
    DOT                Microsoft Word 972003                                    application/msword
    DOTHTML            Microsoft Word   HTML                             
    DOTM               Microsoft Word                         application/vnd.ms-word.template.macroEnabled.12
    DOTX               Microsoft Word                                            application/vnd.openxmlformats-officedocument.wordprocessingml.template
    DQY                 ODBC  Microsoft Excel                            
    DRV               Device Driver                                                    
    DSN               Microsoft OLE DB Provider for ODBC Drivers                       
    DTS               DTS Audio File                                                   
    DV                Digital Video File                                               
    DVR               Microsoft Recorded TV Show                                       
    DVR-MS            Microsoft Recorded TV Show                                       
    DWFX              XPS Document                                                     model/vnd.dwfx+xps
    EASMX             XPS Document                                                     model/vnd.easmx+xps
    EDRWX             XPS Document                                                     model/vnd.edrwx+xps
    ELM               Microsoft Office Themes File                                     
    EMF               EMF File                                                         
    EPRTX             XPS Document                                                     model/vnd.eprtx+xps
    EVO               EVO Video File                                                   
    EVT               EVT File                                                         
    EVTX              EVTX File                                                        
    EXC               Text Document                                                    
    EXE               Application                                                      application/x-msdownload
    F4V               Flash Video File                                                 
    FDF                 Adobe Acrobat                                      application/vnd.fdf
    FLAC              FLAC Audio File                                                  
    FLV               Flash Video File                                                 
    FON               Font file                                                        
    FREECELLSAVE-MS   .FreeCellSave-ms                                                 
    GADGET            Windows Gadget                                                   
    GCSX                 Microsoft Office SmartArt                  
    GIF               GIF Image                                                        image/gif
    GLOX                Microsoft Office SmartArt                          
    GMMP              WCS Gamut Mapping Profile                                        
    GQSX              -  Microsoft Office SmartArt                 
    GRA                Microsoft Graph                                        
    GROUP             Contact Group File                                               text/x-ms-group
    GRP               Microsoft Program Group                                          
    GZ                 WinRAR                                                     
    H1C               Windows Help Collection Definition File                          
    H1D               Windows Help Validator File                                      
    H1F               Windows Help Include File                                        
    H1H               Windows Help Merged Hierarchy                                    
    H1K               Windows Help Index File                                          
    H1Q               Windows Help Merged Query Index                                  
    H1S               Compiled Windows Help file                                       
    H1T               Windows Help Table of Contents File                              
    H1V               Windows Help Virtual Topic Definition File                       
    H1W               Windows Help Merged Keyword Index                                
    HDMOV             HDMOV Video File                                                 
    HEARTSSAVE-MS     .HeartsSave-ms                                                   
    HLP               Help File                                                        
    HTA               HTML Application                                                 application/hta
    HTM               HTML Document                                                    text/html
    HTML              HTML Document                                                    text/html
    HXA               Microsoft Help Attribute Definition File                         application/xml
    HXC               Microsoft Help Collection Definition File                        application/xml
    HXD               Microsoft Help Validator File                                    application/octet-stream
    HXE               Microsoft Help Samples Definition File                           application/xml
    HXF               Microsoft Help Include File                                      application/xml
    HXH               Microsoft Help Merged Hierarchy File                             application/octet-stream
    HXI               Microsoft Help Compiled Index File                               application/octet-stream
    HXK               Microsoft Help Index File                                        application/xml
    HXQ               Microsoft Help Merged Query Index File                           application/octet-stream
    HXR               Microsoft Help Merged Attribute Index File                       application/octet-stream
    HXS               Microsoft Help Compiled Storage File                             application/octet-stream
    HXT               Microsoft Help Table of Contents File                            application/xml
    HXV               Microsoft Help Virtual Topic Definition File                     application/xml
    HXW               Microsoft Help Attribute Definition File                         application/octet-stream
    ICC               ICC Profile                                                      
    ICL               Icon Library                                                     
    ICM               ICC Profile                                                      
    ICO               Icon                                                             image/x-icon
    IFO               DVD IFO File                                                     
    IMG               Disc Image File                                                  
    INF               Setup Information                                                
    INI               Configuration Settings                                           
    IPA                  Apple                                   application/x-itunes-ipa
    IPG                iPod Game                                                   application/x-itunes-ipg
    IPSW                   Apple        application/x-itunes-ipsw
    IQY                -  Microsoft Excel                             text/x-ms-iqy
    ISO                WinRAR                                                     
    ITDB                 iTunes                                          
    ITE               iTunes Extras                                                    application/x-itunes-ite
    ITL                   iTunes                              
    ITLP              ITLP File                                                        application/x-itunes-itlp
    ITLS                iTunes                                               application/x-itunes-itls
    ITMS              URL iTunes Music Store                                           application/x-itunes-itms
    ITPC                                                         application/x-itunes-itpc
    JAR               Executable Jar File                                              
    JFIF              JPEG Image                                                       image/jpeg
    JFR               Java Flight Recorder File                                        
    JNLP              JNLP File                                                        application/x-java-jnlp-file
    JNT               Journal Document                                                 
    JOB               Task Scheduler Task Object                                       
    JOD               Microsoft.Jet.OLEDB.4.0                                          
    JPE               JPEG Image                                                       image/jpeg
    JPEG              JPEG Image                                                       image/jpeg
    JPG               JPEG Image                                                       image/jpeg
    JPS               JPS File                                                         image/jps
    JS                JavaScript File                                                  
    JSE               JScript Encoded File                                             
    JTP               Journal Template                                                 
    JTX               XPS Document                                                     application/x-jtx+xps
    LABEL             Property List                                                    
    LEX               Dictionary File                                                  
    LHA                WinRAR                                                     
    LIBRARY-MS        Library Folder                                                   application/windows-library+xml
    LNK               Shortcut                                                         
    LOG               Text Document                                                    
    LZH                WinRAR                                                     
    M1V               MPEG Video File                                                  video/mpeg
    M2P               MPEG Video File                                                  
    M2T               MPEG-TS Video File                                               video/vnd.dlna.mpeg-tts
    M2TS              MPEG-TS Video File                                               video/vnd.dlna.mpeg-tts
    M2V               MPEG Video File                                                  video/mpeg
    M3U               M3U Playlist File                                                audio/mpegurl
    M4A               MPEG4 Audio File                                                 audio/m4a
    M4R                                                                         audio/x-m4r
    M4V               M4V Video File                                                   video/x-m4v
    MAHJONGTITANSSAVE-MS  .MahjongTitansSave-ms                                            
    MAPIMAIL          Mail Service                                                     
    MCL               MCL File                                                         
    MFP               Macromedia Flash Paper                                           application/x-shockwave-flash
    MHT               MHTML Document                                                   message/rfc822
    MHTML             MHTML Document                                                   message/rfc822
    MID               MIDI Sequence                                                    audio/mid
    MIDI              MIDI Sequence                                                    audio/mid
    MIG               Migration Store                                                  
    MINESWEEPERSAVE-MS  .MinesweeperSave-ms                                              
    MKA               Matroska Audio File                                              
    MKV               Matroska Video File                                              
    MLC               Language Pack File_                                              
    MLP               MLP Audio File                                                   
    MOD               Movie Clip                                                       video/mpeg
    MOV               QuickTime Video File                                             video/quicktime
    MP2               MP3 Format Sound                                                 audio/mpeg
    MP2V              MPEG Video File                                                  video/mpeg
    MP3               MP3 Audio File                                                   audio/mpeg
    MP4               MP4 Video File                                                   video/mp4
    MP4V              MP4V Video File                                                  video/mp4
    MPA               Movie Clip                                                       video/mpeg
    MPC               Musepack Audio File                                              
    MPCPL             MPC Playlist File                                                
    MPE               MPEG Video File                                                  video/mpeg
    MPEG              MPEG Video File                                                  video/mpeg
    MPG               MPEG Video File                                                  video/mpeg
    MPL               DVD Audio File                                                   
    MPLS              Blu-ray Playlist File                                            
    MPO               MPO File                                                         image/mpo
    MPV2              MPEG Video File                                                  video/mpeg
    MPV4              MPV4 Video File                                                  
    MSC               Microsoft Common Console Document                                
    MSDVD             MSDVD File                                                       
    MSI               Windows Installer Package                                        
    MSP               Windows Installer Patch                                          
    MSRCINCIDENT      Windows Remote Assistance Invitation                             
    MSSTYLES          Windows Visual Style File                                        
    MSU               Microsoft Update Standalone Package                              
    MTS               MPEG-TS Video File                                               video/vnd.dlna.mpeg-tts
    MXF               Material Exchange Format                                         
    MYDOCS            MyDocs Drop Target                                               
    NFO               MSInfo Configuration File                                        
    OCX               ActiveX control                                                  
    ODB                 OpenDocument                                         application/vnd.sun.xml.base
    ODC               Microsoft Office Data Connection                                 text/x-ms-odc
    ODCCUBEFILE       ODCCUBEFILE File                                                 
    ODCDATABASEFILE   ODCDATABASEFILE File                                             
    ODCNEWFILE        ODCNEWFILE File                                                  
    ODCTABLECOLLECTIONFILE  ODCTABLECOLLECTIONFILE File                                      
    ODCTABLEFILE      ODCTABLEFILE File                                                
    ODF                OpenDocument                                             application/vnd.oasis.opendocument.formula
    ODG                OpenDocument                                             application/vnd.oasis.opendocument.graphics
    ODM                 OpenDocument                                  application/vnd.oasis.opendocument.text-master
    ODP                OpenDocument                                         application/vnd.oasis.opendocument.presentation
    ODS                 OpenDocument                                 application/vnd.oasis.opendocument.spreadsheet
    ODT                 OpenDocument                                  application/vnd.oasis.opendocument.text
    OFR               OptimFrog Audio File                                             
    OFS               OptimFrog Audio File                                             
    OGA               Ogg Audio File                                                   
    OGG               Ogg Audio File                                                   
    OGM               Ogg Video File                                                   
    OGV               Ogg Video File                                                   
    OPC               Microsoft Clean-up Wizard File                                   
    OPUS              Opus Audio File                                                  
    OQY                 OLAP  Microsoft Excel                            
    OSDX              OpenSearch Description File                                      application/opensearchdescription+xml
    OTF               OpenType Font file                                               
    OTG                 OpenDocument                                      application/vnd.oasis.opendocument.graphics-template
    OTH                HTML-                                            application/vnd.oasis.opendocument.text-web
    OTP                 OpenDocument                                  application/vnd.oasis.opendocument.presentation-template
    OTS                  OpenDocument                          application/vnd.oasis.opendocument.spreadsheet-template
    OTT                  OpenDocument                         application/vnd.oasis.opendocument.text-template
    OXPS              Open XPS Document                                                
    OXT               OpenOffice Extension                                             application/vnd.openofficeorg.extension
    P10               Certificate Request                                              application/pkcs10
    P12               Personal Information Exchange                                    application/x-pkcs12
    P7B               PKCS #7 Certificates                                             application/x-pkcs7-certificates
    P7C               Digital ID File                                                  application/pkcs7-mime
    P7M               PKCS #7 MIME Message                                             application/pkcs7-mime
    P7R               Certificate Request Response                                     application/x-pkcs7-certreqresp
    P7S               PKCS #7 Signature                                                application/pkcs7-signature
    PARTIAL           Partial Download                                                 
    PBK               Dial-Up Phonebook                                                
    PCAST                                                        application/x-podcast
    PDF               Adobe Acrobat Document                                           application/pdf
    PDFXML            Adobe Acrobat PDFXML Document                                    application/vnd.adobe.pdfxml
    PDX                Acrobat Catalog                                           application/vnd.adobe.pdx
    PERFMONCFG        Performance Monitor Configuration                                
    PFD               WinUtilities Document Protector                                  
    PFM               Type 1 Font file                                                 
    PFX               Personal Information Exchange                                    application/x-pkcs12
    PIF               Shortcut to MS-DOS Program                                       
    PKO               Public Key Security Object                                       application/vnd.ms-pki.pko
    PLS               PLS Playlist File                                                audio/scpls
    PNF               Precompiled Setup Information                                    
    PNG               PNG Image                                                        image/png
    PNS               PNS File                                                         image/pns
    POT                Microsoft PowerPoint 97-2003                              
    POTM               Microsoft PowerPoint                                      
    POTX               Microsoft PowerPoint                                      
    PPS                Microsoft PowerPoint                                
    PPT                Microsoft PowerPoint 97-2003                         
    PPTM               Microsoft PowerPoint                                 
    PPTX               Microsoft PowerPoint                                 
    PRF               PICS Rules File                                                  application/pics-rules
    PRINTEREXPORT     Printer Migration File                                           
    PS1               PS1 File                                                         
    PS1XML            PS1XML File                                                      
    PSC1              PSC1 File                                                        application/PowerShell
    PSD1              PSD1 File                                                        
    PSM1              PSM1 File                                                        
    PURBLEPAIRSSAVE-MS  .PurblePairsSave-ms                                              
    PURBLESHOPSAVE-MS  .PurbleShopSave-ms                                               
    QDS               Directory Query                                                  
    R00                WinRAR                                                     
    R01                WinRAR                                                     
    R02                WinRAR                                                     
    R03                WinRAR                                                     
    R04                WinRAR                                                     
    R05                WinRAR                                                     
    R06                WinRAR                                                     
    R07                WinRAR                                                     
    R08                WinRAR                                                     
    R09                WinRAR                                                     
    R10                WinRAR                                                     
    R11                WinRAR                                                     
    R12                WinRAR                                                     
    R13                WinRAR                                                     
    R14                WinRAR                                                     
    R15                WinRAR                                                     
    R16                WinRAR                                                     
    R17                WinRAR                                                     
    R18                WinRAR                                                     
    R19                WinRAR                                                     
    R20                WinRAR                                                     
    R21                WinRAR                                                     
    R22                WinRAR                                                     
    R23                WinRAR                                                     
    R24                WinRAR                                                     
    R25                WinRAR                                                     
    R26                WinRAR                                                     
    R27                WinRAR                                                     
    R28                WinRAR                                                     
    R29                WinRAR                                                     
    RA                RealMedia Audio File                                             
    RAM               RealMedia File                                                   
    RAR                WinRAR                                                     
    RAT               Rating System File                                               application/rat-file
    RDP               Remote Desktop Connection                                        
    REC               MPEG-TS Video File                                               
    REG               Registration Entries                                             
    RELS              XML Document                                                     
    RESMONCFG         Resource Monitor Configuration                                   
    REV                RAR                                         
    RLE               RLE File                                                         
    RLL               Application Extension                                            
    RM                RealMedia Video File                                             
    RMI               MIDI Sequence                                                    audio/mid
    RMVB              RealMedia Video File                                             
    RQY                 OLE DB  Microsoft Excel                          text/x-ms-rqy
    RTF                RTF                                                       application/msword
    SCF               Windows Explorer Command                                         
    SCP               Text Document                                                    
    SCR               Screen saver                                                     
    SCT               Windows Script Component                                         text/scriptlet
    SDG                 OpenOffice.org 1.1                                 
    SDV                 OpenOffice.org 1.1                                 
    SEARCHCONNECTOR-MS  Search Connector Folder                                          application/windows-search-connector+xml
    SEARCH-MS         Saved Search                                                     
    SECSTORE          SECSTORE File                                                    
    SFCACHE           ReadyBoost Cache File                                            
    SHTML             SHTML File                                                       text/html
    SKYPE             Skype Content                                                    application/x-skype
    SLK                  Microsoft Excel SLK                        application/vnd.ms-excel
    SLUPKG-MS         XrML Digital License Package                                     application/x-ms-license
    SND               AU Format Sound                                                  audio/basic
    SOB                 OpenOffice.org 1.1                                 
    SOC                 OpenOffice.org 1.1                                 
    SOD                 OpenOffice.org 1.1                                 
    SOE                 OpenOffice.org 1.1                                 
    SOG                 OpenOffice.org 1.1                                 
    SOH                 OpenOffice.org 1.1                                 
    SOLITAIRESAVE-MS  .SolitaireSave-ms                                                
    SPC               PKCS #7 Certificates                                             application/x-pkcs7-certificates
    SPIDERSOLITAIRESAVE-MS  .SpiderSolitaireSave-ms                                          
    SPL               Shockwave Flash Object                                           application/futuresplash
    SPX               Speex Audio File                                                 
    SST               Microsoft Serialized Certificate Store                           application/vnd.ms-pki.certstore
    STC                  OpenOffice.org XML 1.0                application/vnd.sun.xml.calc.template
    STD                 OpenOffice.org XML 1.0                            application/vnd.sun.xml.draw.template
    STI                 OpenOffice.org XML 1.0                        application/vnd.sun.xml.impress.template
    STL               Certificate Trust List                                           application/vnd.ms-pki.stl
    STW                  OpenOffice.org XML 1.0               application/vnd.sun.xml.writer.template
    SVG               SVG Document                                                     image/svg+xml
    SWF               Shockwave Flash Object                                           application/x-shockwave-flash
    SXC                 OpenOffice.org XML 1.0                       application/vnd.sun.xml.calc
    SXD                OpenOffice.org XML 1.0                                   application/vnd.sun.xml.draw
    SXG                 OpenOffice.org XML 1.0                        application/vnd.sun.xml.writer.global
    SXI                OpenOffice.org XML 1.0                               application/vnd.sun.xml.impress
    SXM                OpenOffice.org XML 1.0                                   application/vnd.sun.xml.math
    SXW                 OpenOffice.org XML 1.0                        application/vnd.sun.xml.writer
    SYS               System file                                                      
    TAK               TAK Audio File                                                   
    TAR                WinRAR                                                     
    TAZ                WinRAR                                                     
    TBZ                WinRAR                                                     
    TBZ2               WinRAR                                                     
    TGZ                WinRAR                                                     
    THEME             Windows Theme File                                               
    THEMEPACK         Windows Theme Pack                                               
    THM                 OpenOffice.org 1.1                                 
    TIF               TIF File                                                         image/tiff
    TIFF              TIFF File                                                        image/tiff
    TP                MPEG-TS Video File                                               
    TPS               MPEG-TS Video File                                               
    TRP               MPEG-TS Video File                                               
    TS                MPEG-TS Video File                                               video/vnd.dlna.mpeg-tts
    TTA               True Audio File                                                  
    TTC               TrueType Collection Font file                                    
    TTF               TrueType Font file                                               
    TTS               MPEG-2 TS Video                                                  video/vnd.dlna.mpeg-tts
    TXT               Text Document                                                    text/plain
    TXZ                WinRAR                                                     
    UDL               Microsoft Data Link                                              
    URL               URL File                                                         
    UU                 WinRAR                                                     
    UUE                WinRAR                                                     
    UXDC              UXDC File                                                        
    VBE               VBScript Encoded File                                            
    VBS               VBScript Script File                                             
    VCF               vCard File                                                       text/x-vcard
    VOB               DVD VOB File                                                     
    VPK               Source Game Add-on                                               
    VSTO              VSTO Deployment Manifest                                         application/x-ms-vsto
    VXD               Virtual Device Driver                                            
    WAB               Address Book File                                                
    WAV               WAV Audio File                                                   audio/wav
    WAX               Windows Media Audio shortcut                                     audio/x-ms-wax
    WBCAT             Windows Backup Catalog File                                      
    WBK                  Microsoft Word                          application/msword
    WCX               Workspace Configuration File                                     
    WDP               Windows Media Photo                                              image/vnd.ms-photo
    WEBM              WEBM Video File                                                  
    WEBPNP            Web Point And Print File                                         
    WEBSITE           Pinned Site Shortcut                                             application/x-mswebsite
    WIZ                Microsoft Word                                            application/msword
    WLL               WLL File                                                         
    WM                Windows Media Audio/Video file                                   video/x-ms-wm
    WMA               WMA Audio File                                                   audio/x-ms-wma
    WMD               Windows Media Player Download Package                            application/x-ms-wmd
    WMDB              Windows Media Library                                            
    WMF               WMF File                                                         
    WMS               Windows Media Player Skin File                                   
    WMV               Windows Media Video File                                         video/x-ms-wmv
    WMX               Windows Media Audio/Video playlist                               video/x-ms-wmx
    WMZ               Windows Media Player Skin Package                                application/x-ms-wmz
    WPL               Windows Media playlist                                           application/vnd.ms-wpl
    WSC               Windows Script Component                                         text/scriptlet
    WSF               Windows Script File                                              
    WSH               Windows Script Host Settings File                                
    WTV               Windows Recorded TV Show                                         
    WTX               Text Document                                                    
    WV                WavPack Audio File                                               
    WVX               Windows Media Audio/Video playlist                               video/x-ms-wvx
    XAML              Windows Markup File                                              application/xaml+xml
    XBA                 OpenOffice.org 1.1                                 
    XBAP              XAML Browser Application                                         application/x-ms-xbap
    XCS                 OpenOffice.org 1.1                                 
    XCU                 OpenOffice.org 1.1                                 
    XDL                 OpenOffice.org 1.1                                 
    XDP                  XML  Adobe Acrobat                         application/vnd.adobe.xdp+xml
    XEVGENXML         XEVGENXML File                                                   
    XFDF                Adobe Acrobat                                      application/vnd.adobe.xfdf
    XHT               XHTML Document                                                   application/xhtml+xml
    XHTML             XHTML Document                                                   application/xhtml+xml
    XLA                Microsoft Excel                                       application/vnd.ms-excel
    XLAM               Microsoft Excel                                       application/vnd.ms-excel.addin.macroEnabled.12
    XLD                 Microsoft Excel 5.0                                application/vnd.ms-excel
    XLK                  Microsoft Excel                             application/vnd.ms-excel
    XLL                Microsoft Excel XLL                                   application/vnd.ms-excel
    XLM                Microsoft Excel 4.0                                       application/vnd.ms-excel
    XLS                Microsoft Excel 97-2003                                     application/vnd.ms-excel
    XLSB                Microsoft Excel                                    application/vnd.ms-excel.sheet.binary.macroEnabled.12
    XLSHTML            Microsoft Excel   HTML                          
    XLSM               Microsoft Excel                          application/vnd.ms-excel.sheet.macroEnabled.12
    XLSMHTML          XLSMHTML File                                                    
    XLSX               Microsoft Excel                                             application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
    XLT                Microsoft Excel                                           application/vnd.ms-excel
    XLTHTML            Microsoft Excel   HTML                            
    XLTM               Microsoft Excel                        application/vnd.ms-excel.template.macroEnabled.12
    XLTX               Microsoft Excel                                           application/vnd.openxmlformats-officedocument.spreadsheetml.template
    XLW                 Microsoft Excel                                  application/vnd.ms-excel
    XLXML              Microsoft Excel   XML                               
    XML               XML Document                                                     text/xml
    XPS               XPS Document                                                     application/vnd.ms-xpsdocument
    XRM-MS            XrML Digital License                                             text/xml
    XSL               XSL Stylesheet                                                   text/xml
    XXE                WinRAR                                                     
    XZ                 WinRAR                                                     
    Z                  WinRAR                                                     
    ZFSENDTOTARGET    Compressed (zipped) Folder SendTo Target                         
    ZIP                ZIP - WinRAR                                               


--------[    ]--------------------------------------------------------------------------------------

  [ Windows Media Center ]

     :
                                                     Windows Media Center
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               MediaCenter.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Currency.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                     .
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               PicturePuzzle.Gadget\ru-RU\gadget.xml

  [   - ]

     :
                                                       -
                                                   ,     .
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               RSSFeeds.Gadget\ru-RU\gadget.xml

  [   ]

     :
                                                      
                                                      (RAM).
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               CPU.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                  .
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Calendar.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                      .
                                                  1.1.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Weather.Gadget\ru-RU\gadget.xml

  [   ]

     :
                                                      
                                                     .
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               SlideShow.Gadget\ru-RU\gadget.xml

  [  ]

     :
                                                     
                                                          .
                                                  1.0.0.0
                                                   Microsoft Corporation
      Copyright                                          2009
      URL                                               http://go.microsoft.com/fwlink/?LinkId=124093
                                                   ProgramFiles
      XML                                               Clock.Gadget\ru-RU\gadget.xml


--------[  Windows ]----------------------------------------------------------------------------------------

      :
                                              Microsoft Windows 7 Ultimate
                                       Service Pack 1
      Winlogon Shell                                    explorer.exe
          (UAC)  
                                   

       (DEP, NX, EDB):
                                        
                                        
       ( )                       
       ( )                        


--------[  Windows ]------------------------------------------------------------------------------------------

    (Automatic Update)                                                                Download:Automatic, Install:Scheduled  Every Day 3:00
    Definition Update for Windows Defender - KB915597 (Definition 1.195.1574.0)                   03.04.2015
    Microsoft .NET Framework 4.5.2  64- (x64)  Windows 7 (KB2901983)              06.03.2015
    Security Update for Microsoft ASP.NET MVC 4.0 (KB2993928)                                     27.02.2015
    Update for Internet Explorer 11 for Windows 7 for x64-based Systems (KB3025390)               18.12.2014
          Internet Explorer 11  Windows 7      x64 (KB2987107)              16.10.2014
          Internet Explorer 11  Windows 7      x64 (KB2987107)              16.10.2014
          Internet Explorer 11  Windows 7      x64 (KB3003057)              13.11.2014
          Internet Explorer 11  Windows 7      x64 (KB3008923)              11.12.2014
          Internet Explorer 11  Windows 7      x64 (KB3021952)              11.02.2015
          Internet Explorer 11  Windows 7      x64 (KB3032359)              12.03.2015
      Microsoft Excel 2013 (KB2956145) 32-                            12.03.2015
      Microsoft Lync 2013 (KB2910927) 32-                             23.12.2014
      Microsoft Lync 2013 (KB2920744) 32-                             11.02.2015
      Microsoft Lync 2013 (KB2956174) 32-                             12.03.2015
      Microsoft Office 2013 (KB2760249) 32-                           23.12.2014
      Microsoft Office 2013 (KB2760344) 32-                           23.12.2014
      Microsoft Office 2013 (KB2760371) 32-                           23.12.2014
      Microsoft Office 2013 (KB2760544) 32-                           23.12.2014
      Microsoft Office 2013 (KB2768012) 32-                           23.12.2014
      Microsoft Office 2013 (KB2827223) 32-                           11.02.2015
      Microsoft Office 2013 (KB2837654) 32-                           23.12.2014
      Microsoft Office 2013 (KB2863843) 32-                           23.12.2014
      Microsoft Office 2013 (KB2880478) 32-                           23.12.2014
      Microsoft Office 2013 (KB2880977) 32-                           11.02.2015
      Microsoft Office 2013 (KB2881001) 32-                           23.12.2014
      Microsoft Office 2013 (KB2881008) 32-                           23.12.2014
      Microsoft Office 2013 (KB2881035) 32-                           23.12.2014
      Microsoft Office 2013 (KB2883036) 32-                           23.12.2014
      Microsoft Office 2013 (KB2883049) 32-                           23.12.2014
      Microsoft Office 2013 (KB2889846) 32-                           11.02.2015
      Microsoft Office 2013 (KB2889858) 32-                           23.12.2014
      Microsoft Office 2013 (KB2889938) 32-                           23.12.2014
      Microsoft Office 2013 (KB2899498) 32-                           23.12.2014
      Microsoft Office 2013 (KB2899501) 32-                           23.12.2014
      Microsoft Office 2013 (KB2899505) 32-                           23.12.2014
      Microsoft Office 2013 (KB2899522) 32-                           23.12.2014
      Microsoft Office 2013 (KB2910921) 32-                           11.02.2015
      Microsoft Office 2013 (KB2910922) 32-                           23.12.2014
      Microsoft Office 2013 (KB2910931) 32-                           23.12.2014
      Microsoft Office 2013 (KB2920734) 32-                           23.12.2014
      Microsoft Office 2013 (KB2920735) 32-                           11.02.2015
      Microsoft Office 2013 (KB2920740) 32-                           11.02.2015
      Microsoft Office 2013 (KB2920742) 32-                           11.02.2015
      Microsoft Office 2013 (KB2920745) 32-                           11.02.2015
      Microsoft Office 2013 (KB2920754) 32-                           12.03.2015
      Microsoft Office 2013 (KB2920769) 32-                           11.02.2015
      Microsoft Office 2013 (KB2920798) 32-                           13.02.2015
      Microsoft Office 2013 (KB2956102) 32-                           11.02.2015
      Microsoft Office 2013 (KB2956148) 32-                           12.03.2015
      Microsoft Office 2013 (KB2956154) 32-                           12.03.2015
      Microsoft Office 2013 (KB2956160) 32-                           12.03.2015
      Microsoft Office 2013 (KB2956167) 32-                           12.03.2015
      Microsoft Office 2013 (KB2956168) 32-                           12.03.2015
      Microsoft Office 2013 (KB2956169) 32-                           12.03.2015
      Microsoft Office 2013 (KB2956171) 32-                           12.03.2015
      Microsoft Office 2013 (KB2956177) 32-                           12.03.2015
      Microsoft OneDrive for Business (KB2910935) 32-                 23.12.2014
      Microsoft OneDrive for Business (KB2920746) 32-                 11.02.2015
      Microsoft OneNote 2013 (KB2899502) 32-                          23.12.2014
      Microsoft OneNote 2013 (KB2920739) 32-                          11.02.2015
      Microsoft OneNote 2013 (KB2956165) 32-                          12.03.2015
      Microsoft Outlook 2013 (KB2899504) 32-                          23.12.2014
      Microsoft Outlook 2013 (KB2956087) 32-                          11.02.2015
      Microsoft Outlook 2013 (KB2956170) 32-                          12.03.2015
      Microsoft Outlook 2013 (KB2986204) 32-                          23.12.2014
      Microsoft Project 2013 (KB2956091) 32-                          11.02.2015
      Microsoft Project 2013 (KB2956187) 32-                          12.03.2015
      Microsoft Visio Viewer 2013 (KB2817301) 32-                     23.12.2014
      Microsoft Word 2013 (KB2878319) 32-                             23.12.2014
      Microsoft Word 2013 (KB2956085) 32-                             13.02.2015
      Windows 7     64- (x64)  (KB2952664)              11.02.2015
      Windows 7     64- (x64)  (KB2952664)              11.12.2014
      Windows 7     64- (x64)  (KB2952664)              13.11.2014
      Windows 7     64- (x64)  (KB2952664)              25.03.2015
      Windows 7     64- (x64)  (KB2994023)              16.10.2014
      Windows 7     64- (x64)  (KB2994023)              16.10.2014
      Windows 7     64- (x64)  (KB2998527)              24.09.2014
      Windows 7     64- (x64)  (KB3000988)              16.10.2014
      Windows 7     64- (x64)  (KB3000988)              16.10.2014
      Windows 7     64- (x64)  (KB3001554)              02.10.2014
      Windows 7     64- (x64)  (KB3004394)              11.02.2015
      Windows 7     64- (x64)  (KB3004394)              11.12.2014
      Windows 7     64- (x64)  (KB3006121)              11.12.2014
      Windows 7     64- (x64)  (KB3006137)              25.02.2015
      Windows 7     64- (x64)  (KB3006625)              11.12.2014
      Windows 7     64- (x64)  (KB3008627)              13.11.2014
      Windows 7     64- (x64)  (KB3009736)              11.12.2014
      Windows 7     64- (x64)  (KB3013410)              11.12.2014
      Windows 7     64- (x64)  (KB3014406)              11.12.2014
      Windows 7     64- (x64)  (KB3020338)              11.02.2015
      Windows 7     64- (x64)  (KB3021917)              04.03.2015
      Windows 7     64- (x64)  (KB3035583)              04.04.2015
      Windows 7      x64 (KB3024777)                       13.12.2014
        Microsoft Visual C++ 2012    4 (KB3032622)              11.02.2015
        Internet Explorer 11   Windows 7     64- (x64)  (KB3034196)              13.02.2015
        Microsoft Excel 2013 (KB2910929) 32-               23.12.2014
        Microsoft Excel 2013 (KB2920753) 32-               11.02.2015
        Microsoft Office 2013 (KB2726958) 32-               23.12.2014
        Microsoft Office 2013 (KB2878316) 32-               23.12.2014
        Microsoft Office 2013 (KB2880502) 32-               23.12.2014
        Microsoft Office 2013 (KB2910941) 32-               11.02.2015
        Microsoft Office 2013 (KB2956151) 32-               12.03.2015
        Microsoft Word 2013 (KB2910916) 32-               23.12.2014
        Microsoft Word 2013 (KB2956163) 32-               12.03.2015
        Windows 7     64- (x64)  (KB2949927)              16.10.2014
        Windows 7     64- (x64)  (KB2949927)              16.10.2014
        Windows 7     64- (x64)  (KB2977292)              16.10.2014
        Windows 7     64- (x64)  (KB2977292)              16.10.2014
        Windows 7     64- (x64)  (KB2984972)              16.10.2014
        Windows 7     64- (x64)  (KB2984972)              16.10.2014
        Windows 7     64- (x64)  (KB2984976)              16.10.2014
        Windows 7     64- (x64)  (KB2984976)              16.10.2014
        Windows 7     64- (x64)  (KB2984981)              16.10.2014
        Windows 7     64- (x64)  (KB2984981)              16.10.2014
        Windows 7     64- (x64)  (KB2991963)              13.11.2014
        Windows 7     64- (x64)  (KB2992611)              13.11.2014
        Windows 7     64- (x64)  (KB2993958)              13.11.2014
        Windows 7     64- (x64)  (KB3000061)              16.10.2014
        Windows 7     64- (x64)  (KB3000061)              16.10.2014
        Windows 7     64- (x64)  (KB3000869)              16.10.2014
        Windows 7     64- (x64)  (KB3000869)              16.10.2014
        Windows 7     64- (x64)  (KB3002885)              13.11.2014
        Windows 7     64- (x64)  (KB3003743)              13.11.2014
        Windows 7     64- (x64)  (KB3004361)              11.02.2015
        Windows 7     64- (x64)  (KB3004375)              11.02.2015
        Windows 7     64- (x64)  (KB3005607)              13.11.2014
        Windows 7     64- (x64)  (KB3006226)              13.11.2014
        Windows 7     64- (x64)  (KB3010788)              13.11.2014
        Windows 7     64- (x64)  (KB3011780)              20.11.2014
        Windows 7     64- (x64)  (KB3013126)              11.12.2014
        Windows 7     64- (x64)  (KB3013455)              11.02.2015
        Windows 7     64- (x64)  (KB3019215)              15.01.2015
        Windows 7     64- (x64)  (KB3020388)              15.01.2015
        Windows 7     64- (x64)  (KB3021674)              15.01.2015
        Windows 7     64- (x64)  (KB3022777)              15.01.2015
        Windows 7     64- (x64)  (KB3023266)              15.01.2015
        Windows 7     64- (x64)  (KB3023562)              11.02.2015
        Windows 7     64- (x64)  (KB3029944)              11.02.2015
        Windows 7     64- (x64)  (KB3030377)              12.03.2015
        Windows 7     64- (x64)  (KB3031432)              11.02.2015
        Windows 7     64- (x64)  (KB3032323)              12.03.2015
        Windows 7     64- (x64)  (KB3033889)              12.03.2015
        Windows 7     64- (x64)  (KB3033929)              12.03.2015
        Windows 7     64- (x64)  (KB3034344)              12.03.2015
        Windows 7     64- (x64)  (KB3035126)              12.03.2015
        Windows 7     64- (x64)  (KB3035131)              12.03.2015
        Windows 7     64- (x64)  (KB3035132)              12.03.2015
        Windows 7     64- (x64)  (KB3036493)              12.03.2015
        Windows 7     64- (x64)  (KB3039066)              12.03.2015
        Windows 7     64- (x64)  (KB3046049)              12.03.2015
       Microsoft Office 2013 (KB2760587) 32-               23.12.2014
       Microsoft Office 2013 (KB2910926) 32-               23.12.2014
       Microsoft Office 2013 (KB2920752) 32-               13.02.2015
       Microsoft Office 2013 (KB2956172) 32-               12.03.2015
        Microsoft .NET Framework 4.5, 4.5.1  4.5.2  Windows 7, Vista, Server 2008, Server 2008 R2 (64- ) (KB2972107)              18.10.2014
        Microsoft .NET Framework 4.5, 4.5.1  4.5.2  Windows 7, Vista, Server 2008, Server 2008 R2 (64- ) (KB2978128)              13.11.2014
        Microsoft .NET Framework 4.5, 4.5.1  4.5.2  Windows 7, Vista, Server 2008, Server 2008 R2 (64- ) (KB2979578)              18.10.2014
        Microsoft .NET Framework 3.5.1  Windows 7  Windows Server 2008 R2    1 (SP1)  64-  (KB2968294)              16.10.2014
        Microsoft .NET Framework 3.5.1  Windows 7  Windows Server 2008 R2    1 (SP1)  64-  (KB2968294)              16.10.2014
        Microsoft .NET Framework 3.5.1  Windows 7  Windows Server 2008 R2    1 (SP1)  64-  (KB2972100)              16.10.2014
        Microsoft .NET Framework 3.5.1  Windows 7  Windows Server 2008 R2    1 (SP1)  64-  (KB2972100)              16.10.2014
        Microsoft .NET Framework 3.5.1  Windows 7  Windows Server 2008 R2    1 (SP1)  64-  (KB2978120)              13.11.2014
        Microsoft .NET Framework 3.5.1  Windows 7  Windows Server 2008 R2    1 (SP1)  64-  (KB2979570)              16.10.2014
        Microsoft .NET Framework 3.5.1  Windows 7  Windows Server 2008 R2    1 (SP1)  64-  (KB2979570)              16.10.2014
         Microsoft Visual Studio 2010  Office (KB3001652)              13.02.2015
          x64:  2014 . (KB890830)              11.12.2014
          x64:  2015 . (KB890830)              12.03.2015
          x64:  2014 . (KB890830)              13.11.2014
          x64:  2014 . (KB890830)              23.10.2014
          x64:  2014 . (KB890830)              23.10.2014
          x64:  2014 . (KB890830)              24.10.2014
          x64:  2014 . (KB890830)              23.10.2014
          x64:  2015 . (KB890830)              11.02.2015
          x64:  2015 . (KB890830)              15.01.2015


--------[  ]---------------------------------------------------------------------------------------------------

    Kaspersky Anti-Virus                               14.0.0.4764                                06.04.2015         ?


--------[  ]--------------------------------------------------------------------------------------------------

     Windows                              6.1.7600.16385  


--------[   ]--------------------------------------------------------------------------------------------

    Microsoft Windows Defender                6.1.7600.16385(win7_rtm.090713-1255)


--------[   ]--------------------------------------------------------------------------------------

     :
                                    RTZ 2 ()
                            (UTC+03:00) , , - (RTZ 2)
                               
                                    

    :
       (.)                                      
       (.)                                      Russian
       (ISO 639)                                    ru

    /:
       (.)                                    
       (.)                                    Russia
       (ISO 3166)                                 RU
                                               7

     :
        (.)                          
        (.)                          Russian Ruble
         (.)                   .
         (ISO 4217)                RUB
                                      123456789,00.
                         -123456789,00.

    :
                                           H:mm:ss
                                       dd.MM.yyyy
                                        d MMMM yyyy '.'
                                       123456789,00
                          -123456789,00
                                            first; second; third
                                               0123456789

     :
                                       / 
                                           / 
                                              / 
                                           / 
                                            / 
                                            / 
                                        / 

    :
                                             / 
                                            / 
                                              / 
                                             / 
                                                / 
                                               / 
                                               / 
                                            / 
                                           / 
                                            / 
                                             / 
                                            / 

    :
                                            Gregorian (localized)
                                 A4
                                        

    :
      LCID 0419h ()                              ()


--------[  ]---------------------------------------------------------------------------------------------------

    ALLUSERSPROFILE           C:\ProgramData
    APPDATA                   C:\Users\zaq\AppData\Roaming
    CommonProgramFiles(x86)   C:\Program Files (x86)\Common Files
    CommonProgramFiles        C:\Program Files (x86)\Common Files
    CommonProgramW6432        C:\Program Files\Common Files
    COMPUTERNAME              ZAQ-
    ComSpec                   C:\Windows\system32\cmd.exe
    FP_NO_HOST_CHECK          NO
    HOMEDRIVE                 C:
    HOMEPATH                  \Users\zaq
    LOCALAPPDATA              C:\Users\zaq\AppData\Local
    LOGONSERVER               \\ZAQ-
    NUMBER_OF_PROCESSORS      6
    OS                        Windows_NT
    Path                      C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Skype\Phone\
    PATHEXT                   .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    PROCESSOR_ARCHITECTURE    x86
    PROCESSOR_ARCHITEW6432    AMD64
    PROCESSOR_IDENTIFIER      AMD64 Family 16 Model 10 Stepping 0, AuthenticAMD
    PROCESSOR_LEVEL           16
    PROCESSOR_REVISION        0a00
    ProgramData               C:\ProgramData
    ProgramFiles(x86)         C:\Program Files (x86)
    ProgramFiles              C:\Program Files (x86)
    ProgramW6432              C:\Program Files
    PSModulePath              C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
    PUBLIC                    C:\Users\Public
    SystemDrive               C:
    SystemRoot                C:\Windows
    TEMP                      C:\Users\zaq\AppData\Local\Temp
    TMP                       C:\Users\zaq\AppData\Local\Temp
    USERDOMAIN                zaq-
    USERNAME                  zaq
    USERPROFILE               C:\Users\zaq
    windir                    C:\Windows
    windows_tracing_flags     3


--------[   ]-------------------------------------------------------------------------------------------

    Flash Player                                Flash Player
    Java                                      Java Control Panel


--------[  ]-----------------------------------------------------------------------------------------------------

    C:        27          3      ?  ?
    E:            0         0      ?  ?


--------[   ]---------------------------------------------------------------------------------------------

  [ system.ini ]

    ; for 16-bit app support
    [386Enh]
    woafont=dosapp.fon
    EGA80WOA.FON=EGA80WOA.FON
    EGA40WOA.FON=EGA40WOA.FON
    CGA80WOA.FON=CGA80WOA.FON
    CGA40WOA.FON=CGA40WOA.FON
    
    [drivers]
    wave=mmdrv.dll
    timer=timer.drv
    
    [mci]

  [ win.ini ]

    ; for 16-bit app support
    [fonts]
    [extensions]
    [mci extensions]
    [files]
    [Mail]
    MAPI=1
    [MCI Extensions.BAK]
    3g2=MPEGVideo
    3gp=MPEGVideo
    3gp2=MPEGVideo
    3gpp=MPEGVideo
    aac=MPEGVideo
    adt=MPEGVideo
    adts=MPEGVideo
    m2t=MPEGVideo
    m2ts=MPEGVideo
    m2v=MPEGVideo
    m4a=MPEGVideo
    m4v=MPEGVideo
    mod=MPEGVideo
    mov=MPEGVideo
    mp4=MPEGVideo
    mp4v=MPEGVideo
    mts=MPEGVideo
    ts=MPEGVideo
    tts=MPEGVideo
    [XVRNT_B]
    cnfgprm=prdct=XVRNT_B&vrsn=3.0.0.1&hrdId=2c64d51200000000000014dae9ed2cd4&instlDate=16215

  [ hosts ]

    
    162.253.154.95 albert.apple.com 

  [ lmhosts.sam ]

    
    
    
    


--------[   ]---------------------------------------------------------------------------------------------

    Administrative Tools         C:\Users\zaq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    AppData                      C:\Users\zaq\AppData\Roaming
    Cache                        C:\Users\zaq\AppData\Local\Microsoft\Windows\Temporary Internet Files
    CD Burning                   C:\Users\zaq\AppData\Local\Microsoft\Windows\Burn\Burn
    Common Administrative Tools  C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    Common AppData               C:\ProgramData
    Common Desktop               C:\Users\Public\Desktop
    Common Documents             C:\Users\Public\Documents
    Common Favorites             C:\Users\zaq\Favorites
    Common Files (x86)           C:\Program Files (x86)\Common Files
    Common Files                 C:\Program Files (x86)\Common Files
    Common Music                 C:\Users\Public\Music
    Common Pictures              C:\Users\Public\Pictures
    Common Programs              C:\ProgramData\Microsoft\Windows\Start Menu\Programs
    Common Start Menu            C:\ProgramData\Microsoft\Windows\Start Menu
    Common Startup               C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
    Common Templates             C:\ProgramData\Microsoft\Windows\Templates
    Common Video                 C:\Users\Public\Videos
    Cookies                      C:\Users\zaq\AppData\Roaming\Microsoft\Windows\Cookies
    Desktop                      C:\Users\zaq\Desktop
    Device                       C:\Windows\inf
    Favorites                    C:\Users\zaq\Favorites
    Fonts                        C:\Windows\Fonts
    History                      C:\Users\zaq\AppData\Local\Microsoft\Windows\History
    Local AppData                C:\Users\zaq\AppData\Local
    My Documents                 C:\Users\zaq\Documents
    My Music                     C:\Users\zaq\Music
    My Pictures                  C:\Users\zaq\Pictures
    My Video                     C:\Users\zaq\Videos
    NetHood                      C:\Users\zaq\AppData\Roaming\Microsoft\Windows\Network Shortcuts
    PrintHood                    C:\Users\zaq\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
    Profile                      C:\Users\zaq
    Program Files (x86)          C:\Program Files (x86)
    Program Files                C:\Program Files (x86)
    Programs                     C:\Users\zaq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
    Recent                       C:\Users\zaq\AppData\Roaming\Microsoft\Windows\Recent
    Resources                    C:\Windows\resources
    SendTo                       C:\Users\zaq\AppData\Roaming\Microsoft\Windows\SendTo
    Start Menu                   C:\Users\zaq\AppData\Roaming\Microsoft\Windows\Start Menu
    Startup                      C:\Users\zaq\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
    System (x86)                 C:\Windows\SysWOW64
    System                       C:\Windows\system32
    Temp                         C:\Users\zaq\AppData\Local\Temp\
    Templates                    C:\Users\zaq\AppData\Roaming\Microsoft\Windows\Templates
    Windows                      C:\Windows


--------[   ]-------------------------------------------------------------------------------------------

                       2015-03-31 05:42:54                           Microsoft-Windows-User Profiles Service  1530: 
               3          2015-03-31 21:38:40                                  Windows Search Service          3036:     <csc://{S-1-5-21-2991384331-2220537945-3595610673-1000}/> .  :  "",  "SystemIndex"  :  URL-       .       , ,         .  (HRESULT : 0x80040d0d) (0x80040d0d)   
                 101        2015-04-01 00:30:44                                  Application Hang                1002: 
                       2015-04-01 04:09:01                           Microsoft-Windows-User Profiles Service  1530: 
                       2015-04-01 14:43:16                           Microsoft-Windows-User Profiles Service  1530: 
                         2015-04-02 21:24:12                                  NvStreamSvc                     
                         2015-04-02 21:24:12                                  NvStreamSvc                     
                         2015-04-02 21:24:12                                  NvStreamSvc                     
               3          2015-04-03 00:55:32                                  Windows Search Service          3036:     <csc://{S-1-5-21-2991384331-2220537945-3595610673-1000}/> .  :  "",  "SystemIndex"  :  URL-       .       , ,         .  (HRESULT : 0x80040d0d) (0x80040d0d)   
                         2015-04-03 21:17:43                                  NvStreamSvc                     
                         2015-04-03 21:17:43                                  NvStreamSvc                     
                         2015-04-03 21:17:43                                  NvStreamSvc                     
                         2015-04-03 21:27:55                                  NvStreamSvc                     
                         2015-04-03 21:27:55                                  NvStreamSvc                     
                         2015-04-03 21:27:55                                  NvStreamSvc                     
                       2015-04-04 00:18:19                           Microsoft-Windows-User Profiles Service  1530: 
                       2015-04-04 13:09:18  zaq                             Microsoft-Windows-RestartManager  10010:     "C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe" (  1432) - 1.  
                       2015-04-04 13:09:18  zaq                             Microsoft-Windows-RestartManager  10010:     "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\distnoted.exe" (  5852) - 1.  
                       2015-04-04 13:54:04                           Microsoft-Windows-User Profiles Service  1530: 
                       2015-04-05 13:11:51                           Microsoft-Windows-User Profiles Service  1530: 
                       2015-04-05 21:02:06                           Microsoft-Windows-User Profiles Service  1530: 
      Audit Success   12288      2015-03-30 23:03:18                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-03-30 23:03:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2015-03-30 23:03:18                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xab48  
      Audit Success   12544      2015-03-30 23:03:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-30 23:03:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-30 23:03:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-30 23:03:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-03-30 23:03:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-03-30 23:03:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-30 23:03:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-30 23:03:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-30 23:03:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-03-30 23:03:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2015-03-30 23:03:22                                  Microsoft-Windows-Eventlog      1101: 
      Audit Success   12544      2015-03-30 23:03:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-30 23:03:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-30 23:03:24                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x29c    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-03-30 23:03:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x1e227   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x29c    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-30 23:03:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x1e271   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x29c    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-30 23:03:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x1e227    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2015-03-30 23:03:25                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-03-30 23:03:31                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-03-30 23:03:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x4357e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-30 23:03:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-30 23:03:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-30 23:04:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-30 23:04:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-30 23:05:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x274    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-30 23:05:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-03-31 01:29:28                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-03-31 01:29:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 01:29:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 01:29:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 01:29:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 01:29:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-03-31 01:29:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-03-31 01:29:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-03-31 01:29:28                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb007  
      Audit Success   101        2015-03-31 01:29:29                                  Microsoft-Windows-Eventlog      1101: 
      Audit Success   12292      2015-03-31 01:29:29                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2015-03-31 01:29:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 01:29:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 01:29:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 01:29:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-03-31 01:29:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-03-31 01:29:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2015-03-31 01:29:30                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-03-31 01:29:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2fc3f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 01:29:45                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-03-31 01:29:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x34771   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 01:29:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x34799   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a8    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 01:29:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x34771    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 01:30:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 01:30:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 01:30:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 01:30:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 01:31:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 01:31:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 04:45:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 04:45:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 04:55:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 04:55:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 04:55:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 04:55:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 04:56:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 04:56:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-03-31 05:42:54                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x34799      ,   .  ,  ,  .        .  
      Audit Success   12544      2015-03-31 05:42:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 05:42:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2015-03-31 05:42:57                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-03-31 17:20:17                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-03-31 17:20:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2015-03-31 17:20:17                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xabf9  
      Audit Success   12544      2015-03-31 17:20:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 17:20:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 17:20:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 17:20:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 17:20:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 17:20:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-03-31 17:20:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-03-31 17:20:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-03-31 17:20:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-03-31 17:20:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2015-03-31 17:20:19                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-03-31 17:20:19                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-03-31 17:20:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 17:20:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 17:20:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2e04d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 17:21:03                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-03-31 17:21:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x3e4a9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 17:21:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x3e4d9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 17:21:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x3e4a9    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 17:21:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 17:21:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 17:21:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 17:21:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 17:22:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 17:22:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 17:23:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 17:23:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 17:25:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 17:25:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 17:25:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 17:25:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-03-31 17:25:43                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP      :  0x3e7    :    : 0x126c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x204988  
      Audit Success   13568      2015-03-31 17:25:43                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP      :  0x3e7    :    : 0x126c    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x204988  
      Audit Success   12544      2015-03-31 20:04:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 20:04:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 20:09:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 20:09:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 21:04:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 21:04:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-03-31 21:29:59                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-03-31 21:29:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 21:29:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 21:29:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-03-31 21:29:59                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xae7f  
      Audit Success   12544      2015-03-31 21:30:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 21:30:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 21:30:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 21:30:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 21:30:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-03-31 21:30:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-03-31 21:30:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-03-31 21:30:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2015-03-31 21:30:01                                  Microsoft-Windows-Eventlog      1101: 
      Audit Success   12292      2015-03-31 21:30:01                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-03-31 21:30:01                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-03-31 21:30:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 21:30:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 21:30:03                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-03-31 21:30:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x2899f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 21:30:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x289c7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 21:30:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x2899f    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 21:30:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2a2fc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 21:30:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 21:30:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 21:32:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 21:32:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 21:34:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 21:34:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-03-31 21:37:57                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-03-31 21:37:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2015-03-31 21:37:57                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xae1e  
      Audit Success   12544      2015-03-31 21:37:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 21:37:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 21:37:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 21:37:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 21:37:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 21:37:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-03-31 21:37:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-03-31 21:37:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-03-31 21:37:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-03-31 21:37:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2015-03-31 21:37:59                                  Microsoft-Windows-Eventlog      1101: 
      Audit Success   12292      2015-03-31 21:37:59                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-03-31 21:37:59                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-03-31 21:37:59                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 21:37:59                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 21:38:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2bc5a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 21:38:03                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-03-31 21:38:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x2c931   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-03-31 21:38:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x2c9b3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2e0    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 21:38:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x2c931    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 21:38:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 21:38:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 21:39:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 21:39:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 21:40:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 21:40:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 22:16:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 22:16:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 23:40:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 23:40:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-03-31 23:43:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-03-31 23:43:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-01 00:30:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x27c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 00:30:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-04-01 00:54:46                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-01 00:54:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 00:54:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 00:54:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-04-01 00:54:46                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb05b  
      Audit Success   101        2015-04-01 00:54:47                                  Microsoft-Windows-Eventlog      1101: 
      Audit Success   12544      2015-04-01 00:54:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 00:54:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 00:54:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 00:54:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 00:54:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 00:54:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-01 00:54:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-01 00:54:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-01 00:54:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-01 00:54:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2015-04-01 00:54:51                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2015-04-01 00:54:51                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2ac    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-01 00:54:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x20bdc   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2ac    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 00:54:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x20c04   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2ac    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 00:54:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x20bdc    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2015-04-01 00:54:57                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-04-01 00:55:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2ea9a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 00:55:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 00:55:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-01 00:57:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 00:57:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-01 00:59:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 00:59:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-04-01 04:09:01                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x20c04      ,   .  ,  ,  .        .  
      Audit Success   12544      2015-04-01 04:09:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 04:09:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2015-04-01 04:09:06                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-04-01 12:50:30                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-01 12:50:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2015-04-01 12:50:30                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xae5b  
      Audit Success   12544      2015-04-01 12:50:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 12:50:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 12:50:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 12:50:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 12:50:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 12:50:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-01 12:50:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-01 12:50:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-01 12:50:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-01 12:50:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2015-04-01 12:50:32                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-04-01 12:50:32                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-04-01 12:50:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 12:50:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-01 12:50:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2e922   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 12:52:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 12:52:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-01 12:52:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 12:52:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-01 12:52:55                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2b8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-01 12:52:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x504b8   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b8    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 12:52:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x504d7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b8    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 12:52:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x504b8    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-01 13:11:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 13:11:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-01 13:41:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 13:41:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-01 14:43:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 14:43:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-04-01 14:43:16                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x504d7      ,   .  ,  ,  .        .  
      Audit Success   12544      2015-04-01 14:43:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x288    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 14:43:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2015-04-01 14:43:21                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-04-01 14:56:10                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-01 14:56:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 14:56:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 14:56:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 14:56:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 14:56:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 14:56:10                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 14:56:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-01 14:56:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-01 14:56:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-01 14:56:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-01 14:56:10                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-04-01 14:56:10                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xae9b  
      Audit Success   12292      2015-04-01 14:56:11                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-04-01 14:56:11                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-04-01 14:56:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 14:56:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-01 14:56:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x295b0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 14:56:21                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2b0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-01 14:56:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x37900   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b0    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 14:56:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x37930   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b0    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 14:56:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x37900    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-01 14:56:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 14:56:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-01 14:58:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 14:58:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-01 15:11:23                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 15:11:23                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-04-01 15:11:24                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x37930      ,   .  ,  ,  .        .  
      Audit Success   12544      2015-04-01 15:11:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 15:11:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2015-04-01 15:11:28                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-04-01 23:04:30                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-01 23:04:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2015-04-01 23:04:30                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xae89  
      Audit Success   12544      2015-04-01 23:04:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 23:04:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 23:04:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 23:04:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 23:04:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 23:04:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-01 23:04:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-01 23:04:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-01 23:04:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-01 23:04:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2015-04-01 23:04:32                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-04-01 23:04:32                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-04-01 23:04:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 23:04:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-01 23:04:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2b113   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 23:05:12                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2b8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-01 23:05:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x37b73   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b8    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-01 23:05:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x37ba3   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b8    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 23:05:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x37b73    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-01 23:05:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 23:05:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-01 23:06:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-01 23:06:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-01 23:21:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12545      2015-04-01 23:21:03                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x37ba3      ,   .  ,  ,  .        .  
      Audit Success   12548      2015-04-01 23:21:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2015-04-01 23:21:05                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-04-02 18:43:11                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-02 18:43:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2015-04-02 18:43:11                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa95c  
      Audit Success   12544      2015-04-02 18:43:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-02 18:43:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-02 18:43:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-02 18:43:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-02 18:43:13                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-02 18:43:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-02 18:43:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-02 18:43:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-02 18:43:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-02 18:43:13                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-02 18:43:14                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-02 18:43:14                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2015-04-02 18:43:15                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-04-02 18:43:16                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-04-02 18:43:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28794   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-02 18:43:19                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-02 18:43:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x299d6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-02 18:43:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x29a0f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-02 18:43:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x299d6    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-02 18:43:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-02 18:43:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-02 18:45:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-02 18:45:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-02 18:46:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-02 18:46:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-02 20:23:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-02 20:23:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-04-02 21:24:07                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-02 21:24:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2015-04-02 21:24:07                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb242  
      Audit Success   12544      2015-04-02 21:24:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-02 21:24:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-02 21:24:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-02 21:24:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-02 21:24:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-02 21:24:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-02 21:24:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-02 21:24:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-02 21:24:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-02 21:24:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2015-04-02 21:24:09                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-04-02 21:24:09                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-04-02 21:24:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-02 21:24:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-02 21:24:11                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2ac    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-02 21:24:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x23000   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2ac    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-02 21:24:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x23028   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2ac    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-02 21:24:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x23000    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2015-04-02 21:24:19                                  Microsoft-Windows-Eventlog      1101: 
      Audit Success   12544      2015-04-02 21:24:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x27b63   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-02 21:24:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-02 21:24:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-02 21:26:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-02 21:26:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-04-02 22:03:58                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x23000      :    : 0x1834   :  C:\Windows\System32\dllhost.exe     :  2015-04-10T19:03:59.099385600Z   :  2015-04-02T19:03:58.000000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2015-04-02 22:03:58                                  Microsoft-Windows-Security-Auditing  4616:   .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x23000      :    : 0x1834   :  C:\Windows\System32\dllhost.exe     :  2015-04-02T19:03:58.000500100Z   :  2015-04-02T19:03:58.000000000Z          .    Windows,    ,    .           .  
      Audit Success   12288      2015-04-03 00:47:33                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-03 00:47:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2015-04-03 00:47:33                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb1fb  
      Audit Success   12544      2015-04-03 00:47:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 00:47:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 00:47:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 00:47:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 00:47:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 00:47:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-03 00:47:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-03 00:47:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-03 00:47:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-03 00:47:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2015-04-03 00:47:35                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-04-03 00:47:35                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-04-03 00:47:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 00:47:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-03 00:47:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2b271   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 00:47:37                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2ac    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-03 00:47:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x2b6df   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2ac    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 00:47:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x2b707   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2ac    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 00:47:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x2b6df    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2015-04-03 00:47:45                                  Microsoft-Windows-Eventlog      1101: 
      Audit Success   12544      2015-04-03 00:48:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 00:48:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-03 00:49:00                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 00:49:00                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-03 00:49:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 00:49:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-04-03 00:54:51                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-03 00:54:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 00:54:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 00:54:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 00:54:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 00:54:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 00:54:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 00:54:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-03 00:54:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-03 00:54:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-03 00:54:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-03 00:54:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-04-03 00:54:51                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb284  
      Audit Success   12292      2015-04-03 00:54:52                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-04-03 00:54:52                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-04-03 00:54:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 00:54:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-03 00:54:55                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2b0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-03 00:54:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x289c6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b0    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 00:54:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x289ee   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b0    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 00:54:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x289c6    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2015-04-03 00:55:02                                  Microsoft-Windows-Eventlog      1101: 
      Audit Success   12544      2015-04-03 00:55:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2f15c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 00:55:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 00:55:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-03 00:57:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 00:57:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-03 01:23:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 01:23:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-04-03 01:23:08                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x289ee      ,   .  ,  ,  .        .  
      Audit Success   12544      2015-04-03 01:23:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 01:23:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2015-04-03 01:23:11                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-04-03 16:24:39                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-03 16:24:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 16:24:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 16:24:39                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-04-03 16:24:39                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa963  
      Audit Success   12544      2015-04-03 16:24:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 16:24:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 16:24:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 16:24:41                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 16:24:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-03 16:24:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-03 16:24:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-03 16:24:41                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2015-04-03 16:24:43                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2015-04-03 16:24:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 16:24:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2015-04-03 16:24:45                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-04-03 16:24:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2b053   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 16:26:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 16:26:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-03 16:26:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 16:26:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-03 16:27:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 16:27:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-03 16:38:34                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-03 16:38:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x260946   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a0    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 16:38:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x26096e   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a0    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 16:38:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x260946    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-04-03 21:17:39                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-03 21:17:39                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2015-04-03 21:17:39                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xaeea  
      Audit Success   12292      2015-04-03 21:17:40                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2015-04-03 21:17:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 21:17:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 21:17:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 21:17:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 21:17:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 21:17:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 21:17:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-03 21:17:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-03 21:17:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-03 21:17:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-03 21:17:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-03 21:17:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2015-04-03 21:17:41                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-04-03 21:17:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2473a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 21:17:43                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-03 21:17:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x25044   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 21:17:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x2506f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 21:17:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x25044    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2015-04-03 21:17:45                                  Microsoft-Windows-Eventlog      1101: 
      Audit Success   12544      2015-04-03 21:18:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 21:18:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-03 21:19:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 21:19:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-03 21:20:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 21:20:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-04-03 21:27:51                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-03 21:27:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 21:27:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 21:27:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 21:27:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 21:27:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 21:27:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 21:27:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-03 21:27:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-03 21:27:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-03 21:27:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-03 21:27:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-04-03 21:27:51                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xae95  
      Audit Success   12292      2015-04-03 21:27:52                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-04-03 21:27:52                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-04-03 21:27:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 21:27:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-03 21:27:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x23f01   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 21:27:56                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-03 21:27:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x253fa   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-03 21:27:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x25422   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 21:27:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x253fa    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2015-04-03 21:27:57                                  Microsoft-Windows-Eventlog      1101: 
      Audit Success   12544      2015-04-03 21:28:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 21:28:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-03 21:29:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 21:29:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-03 21:30:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 21:30:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-03 21:49:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 21:49:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-03 22:29:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-03 22:29:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-04-04 00:18:19                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x25422      ,   .  ,  ,  .        .  
      Audit Success   12544      2015-04-04 00:18:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-04 00:18:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2015-04-04 00:18:22                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-04-04 11:53:03                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-04 11:53:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-04 11:53:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-04 11:53:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-04-04 11:53:03                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xab04  
      Audit Success   12544      2015-04-04 11:53:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-04 11:53:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-04 11:53:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-04 11:53:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-04 11:53:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-04 11:53:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-04 11:53:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-04 11:53:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2015-04-04 11:53:05                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-04-04 11:53:05                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-04-04 11:53:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-04 11:53:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-04 11:53:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2ec07   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-04 11:53:33                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2ac    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-04 11:53:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x3cb36   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2ac    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-04 11:53:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x3cb66   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2ac    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-04 11:53:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x3cb36    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-04 11:53:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-04 11:53:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-04 11:55:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-04 11:55:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-04 13:00:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-04 13:00:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-04 13:08:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-04 13:08:28                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-04 13:11:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-04 13:11:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-04 13:11:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-04 13:11:25                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-04 13:11:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-04 13:11:26                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-04-04 13:12:01                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP      :  0x3e7    :    : 0x14a4    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x5cfdac  
      Audit Success   13568      2015-04-04 13:12:01                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP      :  0x3e7    :    : 0x14a4    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x5cfdac  
      Audit Success   12544      2015-04-04 13:49:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-04 13:49:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-04-04 13:54:04                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x3cb66      ,   .  ,  ,  .        .  
      Audit Success   12544      2015-04-04 13:54:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-04 13:54:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-04 13:54:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-04 13:54:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-04-04 13:54:17                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\GWX\GWXUX.exe    : 0x418      :    : 0x1060    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2015-04-04 13:54:17                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\GWX\config.xml    : 0x560      :    : 0x1060    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2015-04-04 13:54:17                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\GWX\GWXUI.dll    : 0x43c      :    : 0x1060    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2015-04-04 13:54:17                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\GWX\GWX.exe    : 0x518      :    : 0x1060    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2015-04-04 13:54:17                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\GWX\config.cat    : 0x418      :    : 0x1060    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2015-04-04 13:54:17                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\GWX\GWXUXWorker.exe    : 0x560      :    : 0x1060    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2015-04-04 13:54:17                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\System32\GWX\GWXConfigManager.exe    : 0x43c      :    : 0x1060    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2015-04-04 13:54:17                                  Microsoft-Windows-Security-Auditing  4907:     .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7    :    : Security    : File    : C:\Windows\SysWOW64\GWX\GWX.exe    : 0x43c      :    : 0x1060    : C:\Windows\servicing\TrustedInstaller.exe     :     :      :  S:ARAI(AU;SAFA;DCLCRPCRSDWDWO;;;WD)  
      Audit Success   13568      2015-04-04 13:54:30                                  Microsoft-Windows-Security-Auditing  4904:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP      :  0x3e7    :    : 0x1274    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x945e69  
      Audit Success   13568      2015-04-04 13:54:30                                  Microsoft-Windows-Security-Auditing  4905:       .    Subject    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP      :  0x3e7    :    : 0x1274    : C:\Windows\System32\VSSVC.exe     :    : VSSAudit     : 0x945e69  
      Audit Success   103        2015-04-04 13:54:35                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-04-04 23:05:16                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-04 23:05:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2015-04-04 23:05:16                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa3a5  
      Audit Success   12544      2015-04-04 23:05:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-04 23:05:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-04 23:05:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-04 23:05:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-04 23:05:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-04 23:05:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-04 23:05:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-04 23:05:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2015-04-04 23:05:21                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-04-04 23:05:21                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-04-04 23:05:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-04 23:05:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-04 23:05:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-04 23:05:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-04 23:05:26                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2e3b4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-04 23:07:17                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-04 23:07:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x4ad09   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-04 23:07:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x4ad39   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-04 23:07:17                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x4ad09    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-04 23:07:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-04 23:07:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-04 23:07:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-04 23:07:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-04 23:07:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-04 23:07:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-04 23:09:08                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-04 23:09:08                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-04 23:53:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-04 23:53:32                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-04-05 11:05:32                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-05 11:05:32                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2015-04-05 11:05:32                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xaef7  
      Audit Success   12544      2015-04-05 11:05:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 11:05:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 11:05:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 11:05:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 11:05:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 11:05:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 11:05:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 11:05:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 11:05:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 11:05:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 11:05:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 11:05:33                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2015-04-05 11:05:34                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-04-05 11:05:34                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   101        2015-04-05 11:05:38                                  Microsoft-Windows-Eventlog      1101: 
      Audit Success   12544      2015-04-05 11:05:38                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-05 11:05:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x2272b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 11:05:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x22753   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 11:05:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x2272b    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-05 11:05:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2982b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 11:06:01                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 11:06:01                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-05 11:07:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 11:07:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-05 11:08:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 11:08:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-05 12:00:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 12:00:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-04-05 12:13:11                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-05 12:13:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 12:13:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 12:13:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 12:13:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 12:13:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 12:13:11                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 12:13:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 12:13:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 12:13:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 12:13:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 12:13:11                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-04-05 12:13:11                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xaedf  
      Audit Success   101        2015-04-05 12:13:12                                  Microsoft-Windows-Eventlog      1101: 
      Audit Success   12292      2015-04-05 12:13:12                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-04-05 12:13:12                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-04-05 12:13:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 12:13:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-05 12:13:15                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2bc    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-05 12:13:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x225cf   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2bc    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 12:13:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x2269a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2bc    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 12:13:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x225cf    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-05 12:13:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x27b70   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 12:14:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 12:14:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-05 12:15:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 12:15:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-04-05 13:11:51                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x2269a      ,   .  ,  ,  .        .  
      Audit Success   12544      2015-04-05 13:11:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 13:11:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2015-04-05 13:11:53                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-04-05 16:30:43                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-05 16:30:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 16:30:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 16:30:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 16:30:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 16:30:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 16:30:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 16:30:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 16:30:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 16:30:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 16:30:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 16:30:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-04-05 16:30:44                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xad62  
      Audit Success   12292      2015-04-05 16:30:45                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-04-05 16:30:45                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-04-05 16:30:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 16:30:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-05 16:30:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x29445   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 16:32:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 16:32:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-05 16:32:54                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 16:32:54                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-05 16:34:12                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-05 16:34:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x5351b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 16:34:12                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x5353a   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 16:34:12                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x5351b    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-04-05 19:12:47                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-05 19:12:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2015-04-05 19:12:47                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xb31d  
      Audit Success   12544      2015-04-05 19:12:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 19:12:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 19:12:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 19:12:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 19:12:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 19:12:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 19:12:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 19:12:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 19:12:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 19:12:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2015-04-05 19:12:49                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12544      2015-04-05 19:12:49                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 19:12:49                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-05 19:12:55                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-05 19:12:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x1f31c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 19:12:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x1f344   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2a4    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 19:12:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x1f31c    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2015-04-05 19:12:58                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   101        2015-04-05 19:13:00                                  Microsoft-Windows-Eventlog      1101: 
      Audit Success   12544      2015-04-05 19:13:17                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x3c212   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 19:13:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 19:13:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-05 19:13:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 19:13:19                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-05 19:15:22                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 19:15:22                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-05 21:02:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 21:02:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-04-05 21:02:06                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x1f344      ,   .  ,  ,  .        .  
      Audit Success   12544      2015-04-05 21:02:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x28c    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 21:02:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2015-04-05 21:02:10                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-04-05 22:17:15                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-05 22:17:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 22:17:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 22:17:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 22:17:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 22:17:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 22:17:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 22:17:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 22:17:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 22:17:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 22:17:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 22:17:15                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   13568      2015-04-05 22:17:15                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xabda  
      Audit Success   12292      2015-04-05 22:17:16                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-04-05 22:17:16                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-04-05 22:17:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 22:17:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-05 22:17:19                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2b5b0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 22:18:09                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2b0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-05 22:18:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x3bbd9   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b0    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 22:18:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x3bc09   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b0    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 22:18:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x3bbd9    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-05 22:18:21                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 22:18:21                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-05 22:19:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 22:19:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-04-05 23:35:33                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-05 23:35:33                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2015-04-05 23:35:33                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xad79  
      Audit Success   12544      2015-04-05 23:35:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 23:35:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 23:35:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 23:35:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 23:35:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 23:35:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 23:35:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 23:35:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 23:35:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-05 23:35:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2015-04-05 23:35:35                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-04-05 23:35:35                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-04-05 23:35:35                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 23:35:35                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-05 23:35:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2d99f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 23:35:47                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x320    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-05 23:35:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x32c82   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x320    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-05 23:35:47                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x32cb2   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x320    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 23:35:47                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x32c82    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-05 23:36:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 23:36:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-05 23:37:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-05 23:37:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 01:46:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 01:46:09                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-04-06 04:17:55                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x32cb2      ,   .  ,  ,  .        .  
      Audit Success   12544      2015-04-06 04:17:57                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 04:17:57                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2015-04-06 04:18:03                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-04-06 14:29:28                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-06 14:29:28                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2015-04-06 14:29:28                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xadf0  
      Audit Success   12544      2015-04-06 14:29:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-06 14:29:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-06 14:29:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-06 14:29:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-06 14:29:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 14:29:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-06 14:29:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-06 14:29:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-06 14:29:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-06 14:29:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2015-04-06 14:29:30                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-04-06 14:29:30                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-04-06 14:29:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 14:29:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 14:29:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x28a10   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-06 14:31:34                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 14:31:34                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 14:31:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 14:31:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 14:32:37                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 14:32:37                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 14:35:58                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2b8    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-06 14:35:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x163b9f   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b8    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-06 14:35:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x163bc4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b8    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 14:35:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x163b9f    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 15:13:55                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x284    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 15:13:55                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12288      2015-04-06 15:58:02                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-06 15:58:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2015-04-06 15:58:02                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xaf2e  
      Audit Success   12544      2015-04-06 15:58:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-06 15:58:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-06 15:58:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-06 15:58:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-06 15:58:03                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 15:58:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-06 15:58:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-06 15:58:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-06 15:58:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-06 15:58:03                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   101        2015-04-06 15:58:04                                  Microsoft-Windows-Eventlog      1101: 
      Audit Success   12292      2015-04-06 15:58:04                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-04-06 15:58:04                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-04-06 15:58:04                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 15:58:04                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 15:58:06                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2b0    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-06 15:58:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x218a6   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b0    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-06 15:58:06                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x218ce   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b0    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 15:58:06                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x218a6    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 15:58:09                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2e820   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-06 15:58:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 15:58:44                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 15:58:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 15:58:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 16:00:24                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 16:00:24                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 18:21:46                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 18:21:46                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 18:44:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 18:44:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 19:33:45                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 19:33:45                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 19:46:16                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 19:46:16                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-04-06 19:46:19                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x218ce      ,   .  ,  ,  .        .  
      Audit Success   12544      2015-04-06 19:46:20                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x280    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 19:46:20                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2015-04-06 19:46:23                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-04-06 19:47:25                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-06 19:47:25                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2015-04-06 19:47:26                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xab8d  
      Audit Success   12544      2015-04-06 19:47:27                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 19:47:27                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 19:47:29                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 19:47:29                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 19:47:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-06 19:47:30                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 19:47:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-06 19:47:30                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 19:47:31                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 19:47:31                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 19:47:36                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 19:47:36                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2015-04-06 19:47:38                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-04-06 19:47:40                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-04-06 19:47:42                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2ec    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-06 19:47:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x2190c   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2ec    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-06 19:47:42                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x219d0   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2ec    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 19:47:42                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x2190c    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 19:47:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x2f51d   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-06 19:48:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 19:48:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 19:50:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 19:50:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 20:03:56                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 20:03:56                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 20:30:07                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 20:30:07                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 20:55:43                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 20:55:43                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12545      2015-04-06 20:56:13                                  Microsoft-Windows-Security-Auditing  4647: ,  :    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x219d0      ,   .  ,  ,  .        .  
      Audit Success   12544      2015-04-06 20:56:18                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b4    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 20:56:18                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   103        2015-04-06 20:56:24                                  Microsoft-Windows-Eventlog      1100: 
      Audit Success   12288      2015-04-06 20:58:44                                  Microsoft-Windows-Security-Auditing  4608:   Windows.           LSASS.EXE    .  
      Audit Success   12544      2015-04-06 20:58:44                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   0     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x4    :        :     : -     : -    :  -       :    :  -     : -    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   13568      2015-04-06 20:58:45                                  Microsoft-Windows-Security-Auditing  4902:      .     : 0   : 0xa672  
      Audit Success   12544      2015-04-06 20:58:48                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 20:58:48                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 20:58:50                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 20:58:50                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-20     :  NETWORK SERVICE     :  NT AUTHORITY    :  0x3e4    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 20:58:51                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 20:58:51                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-19     :  LOCAL SERVICE     :  NT AUTHORITY    :  0x3e5    :  SeAssignPrimaryTokenPrivilege     SeAuditPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 20:58:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-06 20:58:52                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 20:58:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12548      2015-04-06 20:58:52                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 20:58:58                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 20:58:58                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12292      2015-04-06 20:59:00                                  Microsoft-Windows-Security-Auditing  5033:   Windows  .  
      Audit Success   12292      2015-04-06 20:59:02                                  Microsoft-Windows-Security-Auditing  5024:   Windows  .  
      Audit Success   12544      2015-04-06 20:59:02                                  Microsoft-Windows-Security-Auditing  4648:          .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}          :     :  zaq     :  zaq-   GUID :  {00000000-0000-0000-0000-000000000000}     :     : localhost    : localhost      :    :  0x2ec    :  C:\Windows\System32\winlogon.exe      :    : 127.0.0.1   :   0      ,        ,     .         , ,  ,    RUNAS.  
      Audit Success   12544      2015-04-06 20:59:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x20bc1   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2ec    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-06 20:59:02                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   2     :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x20c0b   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2ec    :  C:\Windows\System32\winlogon.exe      :     : ZAQ-     : 127.0.0.1    :  0       :    :  User32      : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 20:59:02                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-21-2991384331-2220537945-3595610673-1000     :  zaq     :  zaq-    :  0x20bc1    :  SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 20:59:15                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-0-0     :  -     :  -    :  0x0     :   3     :    :  S-1-5-7     :        :  NT AUTHORITY    :  0x30974   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x0    :  -      :     :      : -    :  -       :    :  NtLmSsp      : NTLM    : -     ( NTLM): NTLM V1    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12544      2015-04-06 20:59:38                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 20:59:38                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 21:00:40                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 21:00:40                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
      Audit Success   12544      2015-04-06 21:02:05                                  Microsoft-Windows-Security-Auditing  4624:      .    :    :  S-1-5-18     :  ZAQ-$     :  WORKGROUP    :  0x3e7     :   5     :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7   GUID :  {00000000-0000-0000-0000-000000000000}      :    :  0x2b8    :  C:\Windows\System32\services.exe      :     :      : -    :  -       :    :  Advapi       : Negotiate    : -     ( NTLM): -    :  0          .    ,    .     ""      ,  .   , ,  "",   ,   Winlogon.exe  Services.exe.      " "    .     2 ()  3 ().     " "    ,      ,     ,    .     ,    ,      .      ,         .                .   - GUID  -   ,        KDC.   -   " " ,         .   -  " "   ,    NTLM.   -  " "     .      "0",     .  
      Audit Success   12548      2015-04-06 21:02:05                                  Microsoft-Windows-Security-Auditing  4672:      .    :    :  S-1-5-18     :       :  NT AUTHORITY    :  0x3e7    :  SeAssignPrimaryTokenPrivilege     SeTcbPrivilege     SeSecurityPrivilege     SeTakeOwnershipPrivilege     SeLoadDriverPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeDebugPrivilege     SeAuditPrivilege     SeSystemEnvironmentPrivilege     SeImpersonatePrivilege  
                          2015-03-30 21:43:48  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  
                          2015-03-30 21:45:48  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  
                          2015-03-30 22:45:48  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  
                            2015-03-30 23:03:20                                  EventLog                        6008:      23:01:47  ?30.?03.?2015  .  
                            2015-03-30 23:03:56                                  Service Control Manager         7026: 
                            2015-03-31 01:29:29                                  EventLog                        6008:      1:28:13  ?31.?03.?2015  .  
                            2015-03-31 01:29:31                                  BugCheck                        
                            2015-03-31 01:29:38                                  Service Control Manager         7026: 
                          2015-03-31 01:29:38  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 3   : 9   : 4           .  
                            2015-03-31 17:20:21                                  Service Control Manager         7026: 
                          2015-03-31 18:54:07  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  
                          2015-03-31 18:57:07  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  
                          2015-03-31 21:15:07  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  
                            2015-03-31 21:30:00                                  EventLog                        6008:      21:28:52  ?31.?03.?2015  .  
                            2015-03-31 21:30:05                                  BugCheck                        
                            2015-03-31 21:30:06                                  Service Control Manager         7026: 
                            2015-03-31 21:37:58                                  EventLog                        6008:      21:36:49  ?31.?03.?2015  .  
                            2015-03-31 21:38:03                                  BugCheck                        
                            2015-03-31 21:38:03                                  Service Control Manager         7026: 
                          2015-04-01 00:09:49  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  
                            2015-04-01 00:54:47                                  EventLog                        6008:      0:52:48  ?01.?04.?2015  .  
                            2015-04-01 00:54:50                                  BugCheck                        
                            2015-04-01 00:55:01                                  Service Control Manager         7026: 
                            2015-04-01 00:59:57                                  Service Control Manager         7022: 
                          2015-04-01 03:58:37  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  
                          2015-04-01 04:06:37  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  
                            2015-04-01 12:50:35                                  Service Control Manager         7026: 
                          2015-04-01 14:22:21  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  
                            2015-04-01 14:56:12                                  Service Control Manager         7026: 
                            2015-04-01 23:04:33                                  Service Control Manager         7026: 
                            2015-04-02 18:43:19                                  Service Control Manager         7026: 
                            2015-04-02 21:24:08                                  EventLog                        6008:      21:22:20  ?02.?04.?2015  .  
                            2015-04-02 21:24:18                                  BugCheck                        
                            2015-04-02 21:24:23                                  Service Control Manager         7026: 
                          2015-04-02 21:24:23  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 3   : 9   : 4           .  
                          2015-04-02 22:39:55  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  
                            2015-04-03 00:47:34                                  EventLog                        6008:      0:45:54  ?03.?04.?2015  .  
                            2015-04-03 00:47:35                                  BugCheck                        
                            2015-04-03 00:47:35                                  BugCheck                        
                            2015-04-03 00:47:46                                  Service Control Manager         7026: 
                            2015-04-03 00:54:51                                  EventLog                        6008:      0:53:23  ?03.?04.?2015  .  
                            2015-04-03 00:54:54                                  BugCheck                        
                            2015-04-03 00:54:54                                  BugCheck                        
                            2015-04-03 00:55:06                                  Service Control Manager         7026: 
                            2015-04-03 16:24:49                                  Service Control Manager         7026: 
                          2015-04-03 20:45:33  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  
                          2015-04-03 21:06:32  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  
                            2015-04-03 21:17:40                                  EventLog                        6008:      21:15:48  ?03.?04.?2015  .  
                            2015-04-03 21:17:41                                  BugCheck                        
                            2015-04-03 21:17:41                                  BugCheck                        
                            2015-04-03 21:17:46                                  Service Control Manager         7026: 
                          2015-04-03 21:19:31  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  
                            2015-04-03 21:27:51                                  EventLog                        6008:      21:26:30  ?03.?04.?2015  .  
                            2015-04-03 21:27:52                                  BugCheck                        
                            2015-04-03 21:27:57                                  Service Control Manager         7026: 
                            2015-04-03 21:27:58  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   20:   .    : AMD Northbridge   : 3   : 7   : 0          .  
                            2015-04-04 11:53:09                                  Service Control Manager         7026: 
                  212        2015-04-04 12:18:34                           Microsoft-Windows-Kernel-PnP    219: 
                            2015-04-04 23:05:26                                  Service Control Manager         7026: 
                            2015-04-05 11:05:33                                  EventLog                        6008:      0:53:05  ?05.?04.?2015  .  
                            2015-04-05 11:05:33                                  BugCheck                        
                            2015-04-05 11:05:33                                  BugCheck                        
                            2015-04-05 11:05:42                                  Service Control Manager         7026: 
                            2015-04-05 12:13:11                                  EventLog                        6008:      12:11:38  ?05.?04.?2015  .  
                            2015-04-05 12:13:12                                  BugCheck                        
                            2015-04-05 12:13:18                                  Service Control Manager         7026: 
                          2015-04-05 12:29:02  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  
                            2015-04-05 16:30:50                                  Service Control Manager         7026: 
                            2015-04-05 19:12:48                                  EventLog                        6008:      19:10:33  ?05.?04.?2015  .  
                            2015-04-05 19:12:59                                  BugCheck                        
                            2015-04-05 19:13:17                                  Service Control Manager         7026: 
                          2015-04-05 19:44:33  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  
                            2015-04-05 22:17:19                                  Service Control Manager         7026: 
                            2015-04-05 23:35:34                                  EventLog                        6008:      23:33:20  ?05.?04.?2015  .  
                            2015-04-05 23:35:36                                  BugCheck                        
                            2015-04-05 23:35:36                                  BugCheck                        
                            2015-04-05 23:35:40                                  Service Control Manager         7026: 
                          2015-04-06 00:00:25  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  
                          2015-04-06 00:56:26  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  
                          2015-04-06 01:01:25  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  
                            2015-04-06 14:29:32                                  Service Control Manager         7026: 
                          2015-04-06 15:11:18  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  
                          2015-04-06 15:12:18  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  
                          2015-04-06 15:14:15                                  Display                         4101: 
                          2015-04-06 15:27:18  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  
                            2015-04-06 15:58:03                                  EventLog                        6008:      15:56:18  ?06.?04.?2015  .  
                            2015-04-06 15:58:08                                  BugCheck                        
                            2015-04-06 15:58:09                                  Service Control Manager         7026: 
                            2015-04-06 17:05:18                           Schannel                        36888: 
                            2015-04-06 17:05:18                           Schannel                        36888: 
                            2015-04-06 17:05:18                           Schannel                        36888: 
                            2015-04-06 19:47:53                                  Service Control Manager         7026: 
                            2015-04-06 20:59:16                                  Service Control Manager         7026: 
                          2015-04-06 21:04:31  LOCAL SERVICE                   Microsoft-Windows-WHEA-Logger   19:    .     :     : 1   : 9   : 4           .  


--------[   ]-------------------------------------------------------------------------------------------------------

      :
      Borland Database Engine                           -
      Borland InterBase Client                          -
      Easysoft ODBC-InterBase 6                         -
      Easysoft ODBC-InterBase 7                         -
      Firebird Client                                   -
      Jet Engine                                        4.00.9756.0
      MDAC                                              6.1.7601.17514 (win7sp1_rtm.101119-1850)
      ODBC                                              6.1.7601.17514 (win7sp1_rtm.101119-1850)
      MySQL Connector/ODBC                              -
      Oracle Client                                     -
      PsqlODBC                                          -
      Sybase ASE ODBC                                   -

     :
      Borland InterBase Server                          -
      Firebird Server                                   -
      Microsoft SQL Server                              -
      Microsoft SQL Server Compact Edition              -
      Microsoft SQL Server Express Edition              -
      MySQL Server                                      -
      Oracle Server                                     -
      PostgreSQL Server                                 -
      Sybase SQL Server                                 -


--------[  ODBC ]-----------------------------------------------------------------------------------------------

    Driver da Microsoft para arquivos texto (*.txt; *.csv)      odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.,*.asc,*.csv,*.tab,*.txt,*.csv
    Driver do Microsoft Access (*.mdb)                          odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.mdb
    Driver do Microsoft dBase (*.dbf)                           odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.dbf,*.ndx,*.mdx
    Driver do Microsoft Excel(*.xls)                            odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.xls
    Driver do Microsoft Paradox (*.db )                         odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.db
    Driver para o Microsoft Visual FoxPro                       vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft Access Driver (*.mdb)                             odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.mdb
    Microsoft Access Driver (*.mdb, *.accdb)                    aceodbc.dll         15.0.4695.1000        *.mdb,*.accdb
    Microsoft Access Text Driver (*.txt, *.csv)                 aceodbc.dll         15.0.4695.1000        *.txt, *.csv
    Microsoft Access-Treiber (*.mdb)                            odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.mdb
    Microsoft dBase Driver (*.dbf)                              odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.dbf,*.ndx,*.mdx
    Microsoft dBase VFP Driver (*.dbf)                          vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft dBase-Treiber (*.dbf)                             odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.dbf,*.ndx,*.mdx
    Microsoft Excel Driver (*.xls)                              odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.xls
    Microsoft Excel Driver (*.xls, *.xlsx, *.xlsm, *.xlsb)      aceodbc.dll         15.0.4695.1000        *.xls,*.xlsx, *.xlsb
    Microsoft Excel-Treiber (*.xls)                             odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.xls
    Microsoft FoxPro VFP Driver (*.dbf)                         vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft ODBC for Oracle                                   msorcl32.dll        6.1.7601.17514 (win7sp1_rtm.101119-1850)  
    Microsoft Paradox Driver (*.db )                            odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.db
    Microsoft Paradox-Treiber (*.db )                           odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.db
    Microsoft Text Driver (*.txt; *.csv)                        odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.,*.asc,*.csv,*.tab,*.txt,*.csv
    Microsoft Text-Treiber (*.txt; *.csv)                       odbcjt32.dll        6.1.7601.17632 (win7sp1_gdr.110614-1930)  *.,*.asc,*.csv,*.tab,*.txt,*.csv
    Microsoft Visual FoxPro Driver                              vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft Visual FoxPro-Treiber                             vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    SQL Server                                                  sqlsrv32.dll        6.1.7601.17514 (win7sp1_rtm.101119-1850)  
    SQL Server                                                  sqlsrv32.dll        6.1.7601.17514 (win7sp1_rtm.101119-1850)  


--------[   ODBC ]---------------------------------------------------------------------------------------

    Excel Files                   Microsoft Excel Driver (*.xls, *.xlsx, *.xlsm, *.xlsb)        
    MS Access Database            Microsoft Access Driver (*.mdb, *.accdb)                      


--------[ Debug - PCI ]-------------------------------------------------------------------------------------------------

    B00 D00 F00:  AMD RS780/RS880 Chipset - Host Bridge
                  
      Offset 000:  22 10 00 96  06 00 30 22  00 00 00 06  00 00 00 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 88 83 
      Offset 030:  00 00 00 00  C4 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  08 9C 00 C0  C1 00 00 00  26 00 00 00  42 20 05 00 
      Offset 050:  43 10 88 83  08 40 00 90  08 10 05 00  08 00 00 00 
      Offset 060:  3C 00 00 00  00 00 00 00  00 02 20 00  09 C0 86 85 
      Offset 070:  00 00 00 00  00 00 00 00  48 93 0F 00  01 00 00 20 
      Offset 080:  00 00 00 00  10 00 00 03  20 3A 00 00  31 20 00 00 
      Offset 090:  00 00 00 D0  7F 00 00 00  00 00 00 00  08 F8 7C D0 
      Offset 0A0:  26 00 74 00  00 00 00 80  00 00 00 00  79 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 80  08 54 80 01  20 10 11 11  D0 00 00 00 
      Offset 0D0:  60 0B 75 1E  02 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  FF FF FF FF  F0 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 80 80 00  08 00 00 E0  00 00 00 00 

    B00 D02 F00:  AMD RS780/RS880 Chipset - PCI Express Graphics Port 0
                  
      Offset 000:  22 10 03 96  07 01 10 00  00 00 04 06  10 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 01 01 00  D1 D1 00 00 
      Offset 020:  00 FA A0 FE  01 D0 F1 DF  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  12 01 1B 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 58 03 C8  00 00 00 00  10 A0 42 01  20 80 00 00 
      Offset 060:  10 08 00 00  02 0D 30 00  40 00 02 71  80 25 14 00 
      Offset 070:  00 00 48 01  00 00 01 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  42 00 01 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 B0 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  0D B8 00 00  43 10 88 83  08 00 03 A8  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  FF FF FF FF  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D07 F00:  AMD RS780/RS880 Chipset - PCI Express Port 3
                  
      Offset 000:  22 10 07 96  06 01 10 00  00 00 04 06  10 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 02 02 00  F1 01 00 00 
      Offset 020:  B0 FE B0 FE  F1 FF 01 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  13 01 07 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 58 03 C8  00 00 00 00  10 A0 42 01  20 80 00 00 
      Offset 060:  10 08 00 00  12 0C 30 04  40 00 12 70  80 0C 3C 00 
      Offset 070:  00 00 48 01  00 00 01 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  42 00 01 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 B0 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  0D B8 00 00  43 10 88 83  08 00 03 A8  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  FF FF FF FF  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D0A F00:  AMD RS780/RS880 Chipset - PCI Express Port 5
                  
      Offset 000:  22 10 09 96  07 01 10 00  00 00 04 06  10 00 01 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 03 03 00  E1 E1 00 00 
      Offset 020:  F0 FF 00 00  F1 F8 F1 F8  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  12 01 07 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 58 03 C8  00 00 00 00  10 A0 42 01  20 80 00 00 
      Offset 060:  10 08 00 00  12 0C 30 01  40 00 11 70  80 0C 54 00 
      Offset 070:  00 00 48 01  00 00 01 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  42 00 01 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  05 B0 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  0D B8 00 00  43 10 88 83  08 00 03 A8  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  FF FF FF FF  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D11 F00:  ATI SB750 - SATA Controller
                  
      Offset 000:  02 10 90 43  07 01 30 02  00 8F 01 01  10 40 00 00 
      Offset 010:  01 C0 00 00  01 B0 00 00  01 A0 00 00  01 90 00 00 
      Offset 020:  01 80 00 00  00 FC FF F9  00 00 00 00  43 10 89 83 
      Offset 030:  00 00 00 00  60 00 00 00  00 00 00 00  16 01 00 00 
      Offset 040:  10 00 00 00  01 00 10 00  C0 BF 00 00  00 00 00 00 
      Offset 050:  05 70 84 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  01 70 22 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  12 00 10 00  0F 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  06 00 00 2C  F6 A0 B4 01  F5 A0 B4 01 
      Offset 090:  F4 A0 B4 01  F6 A0 B4 01  F6 A0 B4 01  F7 A0 B4 01 
      Offset 0A0:  D8 A0 F8 A0  F7 A0 F7 A0  B8 A0 F7 A0  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 20 00 00 
      Offset 0E0:  80 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D12 F00:  ATI SB750 - OHCI USB Controller
                  
      Offset 000:  02 10 97 43  06 01 A0 02  00 10 03 0C  10 40 80 00 
      Offset 010:  00 E0 FF F9  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 89 83 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  10 01 00 00 
      Offset 040:  80 03 00 00  11 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  40 13 03 F6  00 00 00 00  FF FF FF FF  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  FF 00 00 80  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D12 F01:  ATI SB750 - OHCI USB Controller
                  
      Offset 000:  02 10 98 43  16 01 A0 02  00 10 03 0C  10 40 00 00 
      Offset 010:  00 D0 FF F9  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 89 83 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  10 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D12 F02:  ATI SB750 - EHCI USB 2.0 Controller
                  
      Offset 000:  02 10 96 43  06 01 B0 02  00 20 03 0C  10 40 00 00 
      Offset 010:  00 F8 FF F9  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 89 83 
      Offset 030:  00 00 00 00  C0 00 00 00  00 00 00 00  11 02 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  D8 01 9E 80  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  20 20 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  01 00 00 00  00 20 00 C0  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  01 E4 02 7E  00 00 40 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  0A 00 E0 20  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D13 F00:  ATI SB750 - OHCI USB Controller
                  
      Offset 000:  02 10 97 43  06 01 A0 02  00 10 03 0C  10 40 80 00 
      Offset 010:  00 C0 FF F9  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 89 83 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  12 01 00 00 
      Offset 040:  80 03 00 00  11 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  40 13 03 F6  00 00 00 00  FF FF FF FF  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  FF 00 00 80  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D13 F01:  ATI SB750 - OHCI USB Controller
                  
      Offset 000:  02 10 98 43  16 01 A0 02  00 10 03 0C  10 40 00 00 
      Offset 010:  00 B0 FF F9  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 89 83 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  12 01 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D13 F02:  ATI SB750 - EHCI USB 2.0 Controller
                  
      Offset 000:  02 10 96 43  06 01 B0 02  00 20 03 0C  10 40 00 00 
      Offset 010:  00 F4 FF F9  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 89 83 
      Offset 030:  00 00 00 00  C0 00 00 00  00 00 00 00  13 02 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  D8 01 9E 80  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  20 20 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  01 00 00 00  00 20 00 C0  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  01 E4 02 7E  00 00 40 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  0A 00 E0 20  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F00:  ATI SB750 - SMBus Controller
                  
      Offset 000:  02 10 85 43  03 04 30 D2  3C 00 05 0C  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 89 83 
      Offset 030:  00 00 00 00  B0 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  44 EB 00 FD  00 00 00 00  0F FF 00 00  00 00 00 C0 
      Offset 050:  F0 01 F0 0E  F0 0F F0 0F  21 0B F0 C3  00 00 00 00 
      Offset 060:  01 00 A4 20  9F FC 9E 03  FF 90 00 00  20 00 00 00 
      Offset 070:  00 00 00 00  08 00 C0 FE  FF 6E 00 00  00 00 F0 06 
      Offset 080:  F0 0A F0 7E  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  01 0B 00 00  F9 CE FF 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 FF FF  00 00 F0 09  00 FF 08 02  06 59 20 18 
      Offset 0B0:  08 00 02 A8  00 00 D0 FE  00 00 00 00  F0 0F 08 1A 
      Offset 0C0:  FF FF FF FF  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 01 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  20 99 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  D8 0C 00 00  00 00 44 00  00 00 00 00  02 00 30 00 

    B00 D14 F01:  ATI SB750 - IDE Controller
                  
      Offset 000:  02 10 9C 43  05 00 30 02  00 8A 01 01  00 00 00 00 
      Offset 010:  01 00 00 00  01 00 00 00  01 00 00 00  01 00 00 00 
      Offset 020:  01 FF 00 00  00 00 00 00  00 00 00 00  43 10 89 83 
      Offset 030:  00 00 00 00  70 00 00 00  00 00 00 00  00 01 00 00 
      Offset 040:  99 99 99 99  FF FF FF FF  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 40 26  10 2C 01 07  01 00 00 00  FF FF 0F 00 
      Offset 070:  05 00 02 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F02:  ATI SB750 - High Definition Audio Controller
                  
      Offset 000:  02 10 83 43  06 00 10 04  00 00 03 04  10 40 00 00 
      Offset 010:  04 40 FF F9  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 6C 83 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  10 01 00 00 
      Offset 040:  00 00 00 00  01 00 00 00  00 00 00 00  01 00 00 00 
      Offset 050:  01 00 42 C8  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  05 00 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F03:  ATI SB750 - PCI-LPC Bridge
                  
      Offset 000:  02 10 9D 43  0F 00 20 02  00 00 01 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 89 83 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  04 00 00 00  43 C0 03 FF  17 FF 40 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  30 02 00 00  0E 00 0F 00  A0 FF FF FF 
      Offset 070:  67 45 23 00  00 00 00 00  14 00 00 00  05 0A 00 00 
      Offset 080:  08 00 03 A8  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 08  01 00 00 00 
      Offset 0A0:  02 00 C1 FE  2F 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 E9  F2 FF 00 00 
      Offset 0C0:  00 00 00 00  00 00 08 00  F7 FF FF FD  00 00 00 78 
      Offset 0D0:  00 FF FF 00  00 00 00 FF  FF FF FF 00  00 00 00 0C 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F04:  ATI SB750 - PCI-PCI Bridge
                  
      Offset 000:  02 10 84 43  07 05 A0 02  00 01 04 06  00 40 81 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 04 04 40  F0 00 80 22 
      Offset 020:  F0 FF 00 00  F0 FF 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 07 00 
      Offset 040:  26 00 08 FF  00 00 00 00  0C 0F 3C D1  00 01 00 00 
      Offset 050:  01 00 00 00  08 00 03 A8  00 00 00 00  85 00 FF FF 
      Offset 060:  CA 0E 17 00  BA D8 10 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  01 00 02 06 
      Offset 0E0:  00 00 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F05:  ATI SB750 - OHCI USB Controller
                  
      Offset 000:  02 10 99 43  06 01 A0 02  00 10 03 0C  10 40 00 00 
      Offset 010:  00 A0 FF F9  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 89 83 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  12 03 00 00 
      Offset 040:  80 01 00 00  11 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  40 13 1F F6  00 00 00 00  FF FF FF FF  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  FF 00 00 80  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F00:  AMD K10 - HyperTransport Technology Configuration
                  
      Offset 000:  22 10 00 12  00 00 10 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  80 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  01 02 04 00  01 02 04 00  01 02 04 00  01 02 04 00 
      Offset 050:  01 02 04 00  01 02 04 00  01 02 04 00  01 02 04 00 
      Offset 060:  00 00 05 00  E0 00 00 00  20 A8 4F 00  10 FE 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  08 00 01 21  20 30 11 11  60 0B F5 FF  13 00 00 00 
      Offset 090:  CF 02 85 80  00 00 02 00  07 00 00 00  0E 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F01:  AMD K10 - Address Map
                  
      Offset 000:  22 10 01 12  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  03 00 00 00  00 00 AF 01  00 00 00 00  01 00 00 00 
      Offset 050:  00 00 00 00  02 00 00 00  00 00 00 00  03 00 00 00 
      Offset 060:  00 00 00 00  04 00 00 00  00 00 00 00  05 00 00 00 
      Offset 070:  00 00 00 00  06 00 00 00  00 00 00 00  07 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  03 0A 00 00  00 0B 00 00  03 00 D0 00  00 FF DF 00 
      Offset 0B0:  03 00 E0 00  80 FF EF 00  03 00 F0 00  00 DF FF 00 
      Offset 0C0:  13 10 00 00  00 F0 FF 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  03 00 00 1F  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  03 30 00 D0  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F02:  AMD K10 - DRAM Controller
                  
      Offset 000:  22 10 02 12  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  01 00 00 00  00 00 00 00  01 01 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  E0 3E F8 00  E0 3E F8 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  06 00 08 0E  50 04 22 18 
      Offset 080:  77 00 00 00  D4 0A 24 00  45 96 57 00  55 79 B2 01 
      Offset 090:  00 00 01 00  0D 09 58 5F  07 E0 0F 8D  3D 01 00 00 
      Offset 0A0:  00 02 00 00  00 00 00 00  40 00 00 00  00 00 00 00 
      Offset 0B0:  3E 7F F6 CE  EA 00 00 00  4D 88 80 0B  1B 15 98 83 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  62 82 35 29  70 92 D0 0D  2D 54 4B 86  EF 0D BC 08 
      Offset 0E0:  8A 43 49 F8  80 0E C6 FD  43 A3 1A 86  4A 8D 77 CB 
      Offset 0F0:  00 00 00 80  00 00 00 00  E4 4D A2 7B  D0 55 01 00 
      Offset 100:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 110:  C5 35 01 00  00 B0 00 00  24 A4 40 04  60 0F E0 2C 
      Offset 120:  F6 40 46 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 130:  3F 07 00 11  34 74 8F 03  66 10 08 28  30 00 F5 7D 
      Offset 140:  01 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 150:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 160:  E0 3F 78 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 170:  00 00 00 00  00 00 00 00  06 00 C8 0D  50 00 02 18 
      Offset 180:  07 00 00 00  D4 00 24 00  45 96 57 00  55 79 32 00 
      Offset 190:  00 00 01 00  0D 09 48 5F  07 E0 0F 8D  3D 01 00 00 
      Offset 1A0:  00 02 00 00  00 00 00 00  40 00 00 00  00 00 00 00 
      Offset 1B0:  01 91 C3 3F  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1F0:  00 00 00 80  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F03:  AMD K10 - Miscellaneous Control
                  
      Offset 000:  22 10 03 12  00 00 10 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  F0 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  FF FF FF 3F  5C 00 B0 4A  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  00 00 00 00  00 10 12 10  00 00 00 00 
      Offset 060:  00 00 00 00  05 62 3F 4A  C0 00 00 10  51 80 01 60 
      Offset 070:  51 11 32 60  01 01 98 00  14 0C 20 00  11 08 07 00 
      Offset 080:  81 E6 00 E6  E6 41 E6 01  08 00 00 00  00 40 58 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 08 12 A0  EF 0F 0C 39  00 00 00 28  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  26 0F 81 C8  14 13 00 03  1A 64 67 00 
      Offset 0E0:  00 00 00 00  30 14 C0 1D  19 DF 07 02  00 00 00 00 
      Offset 0F0:  0F 00 10 00  00 00 00 00  00 00 00 00  A0 0F 10 00 

    B00 D18 F04:  AMD K10 - Link Control
                  
      Offset 000:  22 10 04 12  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 010:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 030:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 040:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  00 00 00 00  FF FF 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 080:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 100:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 110:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 120:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 130:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 140:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 150:  00 00 00 00  00 00 00 00  00 00 00 00  07 00 00 00 
      Offset 160:  A0 0F 10 00  00 00 00 00  00 00 00 00  00 06 00 00 
      Offset 170:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 180:  0A 53 00 E0  00 40 00 00  00 00 00 00  00 00 00 00 
      Offset 190:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1A0:  01 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1C0:  00 00 00 80  10 01 00 00  00 00 00 00  00 00 00 00 
      Offset 1D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 1E0:  15 0C 3C 03  40 34 66 0A  09 1C EA 02  01 24 AA 02 
      Offset 1F0:  11 14 3E 03  1E 0F 00 00  00 00 00 00  00 00 00 00 

    B01 D00 F00:  nVIDIA GeForce 9800 GTX+ Video Adapter
                  
      Offset 000:  DE 10 13 06  07 01 10 00  A2 00 00 03  10 00 00 00 
      Offset 010:  00 00 00 FD  0C 00 00 D0  00 00 00 00  04 00 00 FA 
      Offset 020:  00 00 00 00  01 DC 00 00  00 00 00 00  7D 10 B8 2A 
      Offset 030:  00 00 00 00  60 00 00 00  00 00 00 00  12 01 00 00 
      Offset 040:  7D 10 B8 2A  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  01 00 00 00  01 00 00 00  CE D6 23 00  00 00 00 00 
      Offset 060:  01 68 03 00  08 00 00 00  05 78 80 00  00 00 00 00 
      Offset 070:  00 00 00 00  00 00 00 00  10 00 02 00  E0 84 2C 01 
      Offset 080:  10 29 00 00  02 2D 00 00  48 00 02 11  00 00 00 00 
      Offset 090:  00 00 00 00  00 00 00 00  00 00 00 00  10 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  01 00 00 00  00 00 00 00 
      Offset 0B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B02 D00 F00:  ASMedia ASM1142 USB 3.0 xHCI Controller
                  
      Offset 000:  21 1B 42 11  06 05 10 00  00 30 03 0C  10 00 00 00 
      Offset 010:  04 00 BF FE  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 020:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 BF 85 
      Offset 030:  00 00 00 00  50 00 00 00  00 00 00 00  00 01 00 00 
      Offset 040:  00 00 00 00  60 61 11 02  00 00 00 00  00 00 00 00 
      Offset 050:  05 68 86 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  30 20 00 00  00 00 00 00  11 78 07 80  00 20 00 00 
      Offset 070:  80 20 00 00  00 00 00 00  01 80 43 80  08 00 00 00 
      Offset 080:  10 00 12 00  02 82 64 00  10 28 01 00  12 FC 03 01 
      Offset 090:  40 00 12 10  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  02 00 01 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  96 05 03 11  00 00 00 02  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  BF 85 00 00  00 00 00 00 

    B03 D00 F00:  Realtek RTL8168/8111 PCI-E Gigabit Ethernet Adapter
                  
      Offset 000:  EC 10 68 81  07 05 10 00  09 00 00 02  10 00 00 00 
      Offset 010:  01 E8 00 00  00 00 00 00  0C F0 FF F8  00 00 00 00 
      Offset 020:  0C 80 FF F8  00 00 00 00  00 00 00 00  43 10 05 85 
      Offset 030:  00 00 00 00  40 00 00 00  00 00 00 00  00 01 00 00 
      Offset 040:  01 50 C3 FF  08 01 00 00  00 00 00 00  00 00 00 00 
      Offset 050:  05 70 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 060:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 070:  10 B0 02 02  C0 8C 64 00  10 50 10 00  11 7C 07 00 
      Offset 080:  40 00 11 10  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 090:  00 00 00 00  1F 00 00 00  10 00 00 00  00 00 00 00 
      Offset 0A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0B0:  11 D0 03 80  04 00 00 00  04 08 00 00  00 00 00 00 
      Offset 0C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0D0:  03 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 0F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    PCI-1002-9600:  ATI ClkConfig
                  
      Offset 00:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 10:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 20:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 30:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 40:  01 00 04 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 50:  00 00 00 00  00 00 00 00  00 00 00 00  42 00 00 00 
      Offset 60:  00 00 00 00  00 00 00 00  9F 10 03 00  80 00 00 00 
      Offset 70:  01 00 00 02  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 80:  00 00 00 00  00 00 00 00  00 00 00 00  3F 5F C4 80 
      Offset 90:  FF 03 00 00  1F FF FE 6A  40 00 00 00  00 00 00 00 
      Offset A0:  60 60 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset B0:  00 00 00 00  00 00 00 00  00 00 00 00  FF FF 10 00 
      Offset C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset D0:  00 00 00 00  6C 7B 00 00  9D 00 00 00  00 00 00 00 
      Offset E0:  01 00 4D 07  0C 01 00 00  00 00 00 EC  03 00 00 00 
      Offset F0:  00 00 00 00  00 00 00 00  30 CF 00 00  00 00 00 00 

    PCI-1002-9600:  ATI RS690/RD780/RD790/RS740/RS780/RX790/RS880 NBMCIND
                  
      Offset 00:  00AC0056 88148200 00030200 00000000 
      Offset 04:  08881018 0000BBBB 00000002 00000000 
      Offset 08:  10000A00 00000008 50505411 00100000 
      Offset 0C:  0F000000 00054064 0AAAA000 00000000 
      Offset 10:  00FF0000 00000000 00000000 00000000 
      Offset 14:  00000000 08CC8888 000E2403 D1E01094 
      Offset 18:  01FFFF0F 00000000 00000000 00000000 
      Offset 1C:  00000000 0000FFFF 0000FFFF 0000FFFF 
      Offset 20:  0000FFFF 0000FFFF 0000FFFF 11111111 
      Offset 24:  00000010 00000010 00000000 00000000 
      Offset 28:  00000000 12280000 00070440 0710FFF0 
      Offset 2C:  00010908 00000000 00000000 00000000 
      Offset 30:  00000001 02000001 04000000 04000000 
      Offset 34:  04000000 04000000 04000000 04000000 
      Offset 38:  00F83FE0 1FF83FE0 1FF83FE0 1FF83FE0 
      Offset 3C:  000000BB 00000001 02000001 04000000 
      Offset 40:  04000000 04000000 04000000 04000000 
      Offset 44:  04000000 00F83FE0 1FF83FE0 1FF83FE0 
      Offset 48:  1FF83FE0 000000BB 00020007 00000000 
      Offset 4C:  00000000 00000000 00000000 00000000 
      Offset 50:  00000000 00000000 00000000 00000000 
      Offset 54:  00000000 00000000 00000000 00000000 
      Offset 58:  00000000 00000000 00000000 00000000 
      Offset 5C:  00000400 00000000 00000000 00000000 
      Offset 60:  00000000 00000000 00000000 00000000 
      Offset 64:  00000000 00000000 00000000 00000000 
      Offset 68:  00000000 00000000 00000000 00000000 
      Offset 6C:  00000000 00000000 00000000 00000000 
      Offset 70:  00000000 00000000 00000000 00000000 
      Offset 74:  00000000 00000000 00000000 00000000 
      Offset 78:  00000000 00000000 00000000 00000000 
      Offset 7C:  00000000 00000000 00000000 00000000 
      Offset 80:  00000000 00000000 00000000 00000000 
      Offset 84:  00000000 00000000 00000000 00000000 
      Offset 88:  00000000 00000000 00000000 00000000 
      Offset 8C:  00000000 00000000 00000000 00000000 
      Offset 90:  00000000 00000000 00000000 00000000 
      Offset 94:  00000000 00000000 00000000 00000000 
      Offset 98:  00000000 00000000 00000000 00000000 
      Offset 9C:  00000000 00000000 00000000 00000000 
      Offset A0:  00F00000 01F10000 74F20000 4AF30000 
      Offset A4:  22224851 00000000 00000000 00000000 
      Offset A8:  68488834 10282018 23212421 21482286 
      Offset AC:  00000000 00000000 00000000 00040000 
      Offset B0:  48800000 33330223 00000202 00000000 
      Offset B4:  05000A00 0CBDDDDC 00000033 00000044 
      Offset B8:  BBBBBBBB BBBBBBBB 55555555 BBBBBBBB 
      Offset BC:  BBBBBBBB 00000000 00000000 00000000 
      Offset C0:  00000000 00000000 00000000 80006B00 
      Offset C4:  04355554 00000000 00000000 00000001 
      Offset C8:  23F00000 01F10000 00F20000 05F30000 
      Offset CC:  68488834 10282018 33212421 21482286 
      Offset D0:  00000202 00000000 00000033 00000044 
      Offset D4:  00000000 00000000 00000000 00000000 
      Offset D8:  00A000A0 00A000A0 00000000 00000000 
      Offset DC:  00000000 00000000 00000000 00000000 
      Offset E0:  00380038 00380038 00000000 00000000 
      Offset E4:  00000000 00000000 00000000 00000000 
      Offset E8:  00380038 00380038 00000000 00000000 
      Offset EC:  00000000 00000000 00000000 00000000 
      Offset F0:  00000000 00000000 00000000 00000000 
      Offset F4:  00000000 00000000 00000000 00000000 
      Offset F8:  00000000 00000000 00000000 00000000 
      Offset FC:  00000000 00000000 00000000 00000000 
      Offset 100:  00AC0056 88148200 00030200 00000000 
      Offset 104:  08881018 0000BBBB 00000002 00000000 
      Offset 108:  10000A00 00000008 50505411 00100000 
      Offset 10C:  0F000000 00054064 0AAAA000 00000000 
      Offset 110:  00FF0000 00000000 00000000 00000000 
      Offset 114:  00000000 08CC8888 000E2403 D1E01094 
      Offset 118:  01FFFF0F 00000000 00000000 00000000 
      Offset 11C:  00000000 0000FFFF 0000FFFF 0000FFFF 
      Offset 120:  0000FFFF 0000FFFF 0000FFFF 11111111 
      Offset 124:  00000010 00000010 00000000 00000000 
      Offset 128:  00000000 12280000 00070440 0710FFF0 
      Offset 12C:  00010908 00000000 00000000 00000000 
      Offset 130:  00000001 02000001 04000000 04000000 
      Offset 134:  04000000 04000000 04000000 04000000 
      Offset 138:  00F83FE0 1FF83FE0 1FF83FE0 1FF83FE0 
      Offset 13C:  000000BB 00000001 02000001 04000000 
      Offset 140:  04000000 04000000 04000000 04000000 
      Offset 144:  04000000 00F83FE0 1FF83FE0 1FF83FE0 
      Offset 148:  1FF83FE0 000000BB 00020007 00000000 
      Offset 14C:  00000000 00000000 00000000 00000000 
      Offset 150:  00000000 00000000 00000000 00000000 
      Offset 154:  00000000 00000000 00000000 00000000 
      Offset 158:  00000000 00000000 00000000 00000000 
      Offset 15C:  00000400 00000000 00000000 00000000 
      Offset 160:  00000000 00000000 00000000 00000000 
      Offset 164:  00000000 00000000 00000000 00000000 
      Offset 168:  00000000 00000000 00000000 00000000 
      Offset 16C:  00000000 00000000 00000000 00000000 
      Offset 170:  00000000 00000000 00000000 00000000 
      Offset 174:  00000000 00000000 00000000 00000000 
      Offset 178:  00000000 00000000 00000000 00000000 
      Offset 17C:  00000000 00000000 00000000 00000000 
      Offset 180:  00000000 00000000 00000000 00000000 
      Offset 184:  00000000 00000000 00000000 00000000 
      Offset 188:  00000000 00000000 00000000 00000000 
      Offset 18C:  00000000 00000000 00000000 00000000 
      Offset 190:  00000000 00000000 00000000 00000000 
      Offset 194:  00000000 00000000 00000000 00000000 
      Offset 198:  00000000 00000000 00000000 00000000 
      Offset 19C:  00000000 00000000 00000000 00000000 
      Offset 1A0:  00F00000 01F10000 74F20000 4AF30000 
      Offset 1A4:  22224851 00000000 00000000 00000000 
      Offset 1A8:  68488834 10282018 23212421 21482286 
      Offset 1AC:  00000000 00000000 00000000 00040000 
      Offset 1B0:  48800000 33330223 00000202 00000000 
      Offset 1B4:  05000A00 0CBDDDDC 00000033 00000044 
      Offset 1B8:  BBBBBBBB BBBBBBBB 55555555 BBBBBBBB 
      Offset 1BC:  BBBBBBBB 00000000 00000000 00000000 
      Offset 1C0:  00000000 00000000 00000000 80006B00 
      Offset 1C4:  04355554 00000000 00000000 00000001 
      Offset 1C8:  23F00000 01F10000 00F20000 05F30000 
      Offset 1CC:  68488834 10282018 33212421 21482286 
      Offset 1D0:  00000202 00000000 00000033 00000044 
      Offset 1D4:  00000000 00000000 00000000 00000000 
      Offset 1D8:  00A000A0 00A000A0 00000000 00000000 
      Offset 1DC:  00000000 00000000 00000000 00000000 
      Offset 1E0:  00380038 00380038 00000000 00000000 
      Offset 1E4:  00000000 00000000 00000000 00000000 
      Offset 1E8:  00380038 00380038 00000000 00000000 
      Offset 1EC:  00000000 00000000 00000000 00000000 
      Offset 1F0:  00000000 00000000 00000000 00000000 
      Offset 1F4:  00000000 00000000 00000000 00000000 
      Offset 1F8:  00000000 00000000 00000000 00000000 
      Offset 1FC:  00000000 00000000 00000000 00000000 


--------[ Debug - Video BIOS ]------------------------------------------------------------------------------------------

    C000:0000  U.i.K7400.L.w.VIDEO ......:...IBM VGA Compatible......n.11/04/08
    C000:0040  .................45.}..*.#............".........PMIDl.o.......
    C000:0080  .....3b.M...|.......;.......................-.....s...@.@...1...
    C000:00C0  ....Q......`....".......................HWEAWinFast PX9800 GTX+.
    C000:0100  ..X+ VGA BIOS................................................Ver
    C000:0140  sion 62.92.68.00.07 ...Copyright (C) 1996-2008 NVIDIA Corp......
    C000:0180  ..vB....G92 Board - 03910050...............Chip Rev   ..........
    C000:01C0  ................................................PCIR............
    C000:0200  i.......HYB$..BIT......E2.....B.....C.....D.....A.....I.....L...
    C000:0240  ..M.....N.....P.....S.....T.....U.....V.....c.....x...#.d...'.i.
    C000:0280  (.)...Q. .....`..........h.b.]................\\............j..M
    C000:02C0  ..b.....`.v.|...`...v.L...4....(.....y.......................B.
    C000:0300  .....P=..W.( ..4.#..#.....................h.b....@-.:...10/20/08
    C000:0340  ..........x.................Z.S.................9. .........Z.S.
    C000:0380  ........,.....9.1.....X.5...x.......G.....L.......Q...Z....... .
    C000:03C0  ........|.........a.......f.t.t.t.......t.n.....q.t...t.m.6...x.


--------[ Debug - Unknown ]---------------------------------------------------------------------------------------------

    HDD             WDC WD5000LMVW-11CKRS0
    Monitor ID      PHLC0CE:   PnP [NoDB]
    Monitor Model   PHL 203V5
    SSD             WDC WD5000LMVW-11CKRS0


------------------------------------------------------------------------------------------------------------------------

The names of actual companies and products mentioned herein may be the trademarks of their respective owners.
